Laptop with Windows 11, surrounded by glowing cybersecurity, cloud, update, and protection icons.
Windows 11 users should treat the September 2026 security release as a reason to open Windows Update, install every applicable cumulative update offered there, and restart only if Windows requires it. The immediate security concern is real: September’s release addresses two Windows elevation-of-privilege vulnerabilities reported as actively exploited. But the practical response is more precise than a blanket instruction for every user to reboot immediately.

For PCs on Windows 11 versions 24H2, 25H2, or 26H1, the September 14 out-of-band (OOB) cumulative updates are now the latest relevant client updates identified for those versions. They add security protections and correct regressions reported after the September 8 release. Readers on other Windows 11 versions or editions should follow Windows Update for the package applicable to their installed version rather than assuming a named KB applies to every PC.

What to install now​

Open Settings > Windows Update, select Check for updates, and install every applicable cumulative update Windows offers. If Windows asks for a restart, save work and restart. Once the PC returns, check Windows Update again to confirm there is no failed installation, pending restart, or additional offered update.

For the Windows 11 versions covered by the September 14 OOB release:

  • KB5129195 applies to Windows 11 versions 24H2 and 25H2.
  • KB5129194 applies to Windows 11 version 26H1.

These are cumulative OOB updates, meaning they include the relevant earlier fixes as well as additional changes. Microsoft says they install automatically through Windows Update. For ordinary home users, Windows Update is therefore the appropriate route; there is no general need to hunt for a standalone package or manually install one from a catalog.

There can be exceptions in administrator-managed environments. An IT team may use a controlled deployment process, testing ring, or another approved servicing method. Employees should not attempt to bypass those controls. Administrators should verify that the applicable update deployed successfully and that any required restart actually completed.

The September 8 packages remain useful context, but are not the complete current list for the affected feature versions. KB5124008 was the September 8 cumulative update for 24H2 and 25H2, while KB5124012 was the September 8 package for 26H1. The September 14 OOB releases followed them for those version families.

Why the September 14 OOB updates matter​

The OOB updates address two known functional regressions associated with the September servicing sequence: issues affecting Remote Desktop Services and Hyper-V/Plan9 shared folders. That makes them more than a routine reissue of the monthly security package. They are intended to restore affected functionality while also delivering additional security protections.

This does not mean every Windows 11 machine had either problem. Remote Desktop Services is particularly relevant to remote workers, help desks, administrators, and businesses with remote-access workflows. Hyper-V and Plan9 shared-folder behavior is more likely to matter to developers, IT professionals, and users of virtualized workloads. Still, because the packages are cumulative and arrive through the normal update path, routine patching remains the sensible default for eligible devices.

There is also an important, narrowly scoped audio caveat. The OOB updates resolve the reported multichannel symptom—described as 8-channel or 3D audio—for affected USB Audio Class 1.0 devices. They do not resolve every reported issue affecting that device class. Microsoft’s current release-note information continues to identify unresolved symptoms including a device failing to start with Code 10, no audio output, an unresponsive volume control, or unresponsive sound settings.

That limitation should not deter routine patching. It does not describe a general Windows 11 audio failure, nor does it apply broadly to every USB headset, speaker, or audio driver. It is a remaining issue limited to USB Audio Class 1.0 hardware with the listed symptoms. Users affected by those specific problems should recognize that the OOB update may correct the multichannel behavior without curing the other audio failures.

The vulnerability total is not one simple number​

Large September vulnerability totals need careful labeling. Several figures have circulated, and they describe different counting methods rather than one universally applicable total for every Windows 11 PC.

One analysis counts 964 customer-actionable CVEs, including 104 rated Critical. Its method starts with 974 CVEs in Microsoft’s full September security release and excludes 10 issues involving cloud services or fixes Microsoft applies itself. That makes 964 a useful customer-patching measure, but not an unqualified count of every item in the release.

Other assessments use different scopes. One Patch Tuesday-focused count identifies 966 flaws and 105 Critical vulnerabilities. Another reports 972 Microsoft CVEs, increasing to 997 when external and Chromium CVEs are included. The 974 figure represents another broader release-wide approach.

Those differences do not prove that one count is wrong. They reflect decisions about whether to include cloud services, vendor-remediated issues, external CVEs, Chromium items, and updates outside a narrow Patch Tuesday window. None should be presented as a single, unqualified Microsoft total or as the number of Windows 11 vulnerabilities facing every home user.

The release also extends beyond the Windows operating system. Reporting attributes 723 flaws to Windows and 222 to Office, while also identifying affected areas such as SQL, developer tools, SharePoint, Azure, Skype for Business, and Exchange Server. A broad September figure is therefore not a Windows 11-only deployment list.

For a PC owner, the conclusion is simpler than the counting debate: the servicing scope is substantial, and pending applicable security updates should not be left uninstalled. But the raw CVE number alone cannot determine a particular device’s exposure.

Two exploited elevation-of-privilege flaws raise the priority​

Two September vulnerabilities are reported as actively exploited: CVE-2026-81963 in the Windows Update Stack and CVE-2026-85880 in Windows ALPC, the Advanced Local Procedure Call mechanism.

Both are elevation-of-privilege vulnerabilities. In practical terms, the reported risk is that an attacker who already has a way to execute code or operate on a device could potentially use either weakness to obtain SYSTEM privileges. SYSTEM is one of Windows’ most powerful privilege levels. A successful escalation could make an initial compromise more damaging by helping an attacker interfere with security controls, access protected areas, establish persistence, or move further through an organization.

The nature of these flaws also sets a meaningful limit on the immediate threat model. They are reported as local paths to SYSTEM privileges, not standalone remote-access vulnerabilities. The available information does not establish that an unauthenticated attacker can simply connect to any unpatched Windows 11 PC from the internet and take control through either flaw alone.

Nor do the available reports establish how widespread exploitation is, which threat actors are responsible, which configurations were targeted, or exactly how the attacks work. Those uncertainties should prevent alarmism, not invite delay. Active exploitation makes prompt patching especially important where a criminal might first obtain access through phishing, a malicious download, stolen credentials, malware, or a separate vulnerability.

Restart when Windows requires it​

Restarting matters because some security improvements replace components that cannot be updated while Windows is running. Microsoft specifically notes that hotpatch-enrolled devices need a restart when such components change.

A restart notification should therefore not be ignored. If Windows says a restart is required, leaving the device in that state may leave the update incomplete even when Windows Update indicates that it has downloaded or begun installing.

However, “restart now” is not a complete instruction for all users. A device may already be current and have completed its required restart. Another may not yet have been offered an update. A third may have an installation error that a reboot alone will not solve. Managed PCs can also follow an organization’s deployment and restart schedule.

The right order is check, install, then restart if Windows requires it. Rebooting does not install a missing cumulative update, and an update can remain incomplete until the requested restart occurs.

A practical checklist for home users​

  1. Open Settings > Windows Update.
  2. Select Check for updates and allow all applicable cumulative updates to install.
  3. Install the September 14 OOB cumulative update if Windows offers it for the PC’s installed version.
  4. Save work and restart if Windows requires a restart.
  5. Return to Windows Update after sign-in and check for failed installations, pending restarts, or additional offered updates.

If an installation fails, note the exact error code or message. Check available storage, power, and network reliability where relevant. Another update check after a restart can be reasonable, but repeated restarts alone are unlikely to resolve a persistent installation failure. Contact an administrator for a work-managed device, or use normal Windows Update support and troubleshooting channels for a personal PC.

The same discipline applies to supported Microsoft applications. September’s release includes more than Windows, but users should install only updates applicable to the products they actually use and should rely on their normal servicing channels.

A support-lifecycle reminder for 24H2 users​

Windows 11 version 24H2 Home and Pro editions are scheduled to reach end of updates on October 13, 2026. Enterprise and Education editions remain supported until October 12, 2027. This is an upgrade-planning issue, not evidence of a special immediate exploit risk for 24H2 users.

Still, Home and Pro users on 24H2 should not treat this month’s patch as a long-term answer by itself. Once the support date arrives, planning a supported upgrade path becomes necessary to continue receiving regular security updates.

The bottom line​

September’s Windows 11 updates warrant prompt installation because the broader release includes two actively exploited local privilege-escalation vulnerabilities, and the September 14 OOB updates add security protections while repairing reported Remote Desktop Services and Hyper-V/Plan9 shared-folder regressions.

The action is not to panic-reboot indiscriminately. Open Windows Update, install every applicable cumulative update offered for the installed Windows 11 version—including the September 14 OOB update where offered—and restart if Windows requires it. Keep the eye-catching figures in context: 964, 966, 972, 974, and 997 are all products of different counting scopes, not one unqualified total for Microsoft or Windows 11. The practical risk-reduction step remains straightforward: do not leave applicable cumulative updates or required restarts pending.