Kb5129194 Windows 11 26h1 Security Update
This out-of-band update for Windows 11, version 26H1 (KB5129194) includes the latest fixes and improvements. Visit the Windows release health dashboard for the latest status on this release.
This out-of-band update includes the following improvements:
[Security] This update includes protections documented in CVE-2026-62721 , which refers to a Windows User-Mode Power Service (UMPS) Elevation of Privilege vulnerability.
[Security] This update includes protections documented in CVE-2026-62721 , which refers to a Windows User-Mode Power Service (UMPS) Elevation of Privilege vulnerability.
[Security] This update includes protections documented in CVE-2026-85921 , which refers to a Windows Secure Kernel Mode Elevation of Privilege vulnerability.
[Security] This update includes protections documented in CVE-2026-85921 , which refers to a Windows Secure Kernel Mode Elevation of Privilege vulnerability.
[Remote Desktop Services (known issue)] Fixed: This update addresses an issue affecting Remote Desktop Services (RDS) after installing the September 2026 Windows security update ( KB5124012 ). In affected environments, RDS might become unstable, causing RDP connection and sign-in failures or servers to become unresponsive during Remote Desktop configuration. Related tools, including Microsoft Management Console (MMC), RDS Licensing Diagnoser, File Explorer, and the Windows Update page, might also stop responding.
[Remote Desktop Services (known issue)] Fixed: This update addresses an issue affecting Remote Desktop Services (RDS) after installing the September 2026 Windows security update ( KB5124012 ). In affected environments, RDS might become unstable, causing RDP connection and sign-in failures or servers to become unresponsive during Remote Desktop configuration. Related tools, including Microsoft Management Console (MMC), RDS Licensing Diagnoser, File Explorer, and the Windows Update page, might also stop responding.
[Hyper-V (known issue)] Fixed: Some applications that use HCS-managed virtual machines experienced issues when sharing host folder with Linux VMs using Plan9. Folders shared from the Windows host using Plan9 did not appear or could not be accessed in the guest environment.
[Hyper-V (known issue)] Fixed: Some applications that use HCS-managed virtual machines experienced issues when sharing host folder with Linux VMs using Plan9. Folders shared from the Windows host using Plan9 did not appear or could not be accessed in the guest environment.
[8-channel or 3D audio modes] Fixed: Some USB Audio Class 1.0 devices functioning as expected in standard stereo configurations failed when using multichannel audio features, including 8-channel or 3D audio modes. (Note: There are other audio symptoms not resolved in this OOB update. See the “Known issues in this update” section for more information.)
[8-channel or 3D audio modes] Fixed: Some USB Audio Class 1.0 devices functioning as expected in standard stereo configurations failed when using multichannel audio features, including 8-channel or 3D audio modes. (Note: There are other audio symptoms not resolved in this OOB update. See the “Known issues in this update” section for more information.)
If you've already installed updates, your device will download and install only the new updates included in this package.
This release updates the following AI components to version 1.2608.951.0: Image , Content Extraction, Semantic Analysis, and Settings Model.
Known issues in this update
After installing the September 8, 2026, Windows security update, some USB Audio Class 1.0 devices might fail to start or produce audio. Affected devices might experience one or more of the following symptoms:
The device displays an error in Device Manager: "This device cannot start (Code 10).”
Volume controls are unresponsive or remain at zero.
Sound settings are unresponsive or unavailable.
This issue is limited to USB Audio Class 1.0 devices.
Microsoft is working on a resolution and will update this documentation when more information is available.
How to get this update
Before you install this update
Microsoft combines the latest servicing stack update (SSU) for your operating system with the latest cumulative update (LCU). For general information SSUs, see Servicing stack updates .
If you deploy dynamic updates such as this update to an existing Windows image, ensure the boot.stl file is included as part of the installation media. Failure to include the file might prevent devices from successfully starting from the installation media and can result in error code 0xc0430001 .
The boot.stl file is used during Secure Boot validation and must match the Windows version and architecture of the image you are updating.
To ensure the boot.stl file is included as part of the installation media, do one of the following:
Use the Update WinPE script to update an existing Windows image. (Recommended)
Manually copy the boot.stl file from the device Windows\Boot\EFI folder to the corresponding folder on your installation media before deploying the update.
For information how to apply Dynamic Update packages to existing Windows images, see Update Windows installation media with Dynamic Update .
To install this out-of-band update, use one of the following Windows and Microsoft release channels.
Microsoft Update Catalog
Windows Server Update Services
Note The Microsoft Update Catalog may include one or more required checkpoint cumulative updates and the target cumulative update. Install the checkpoint cumulative updates in order before installing the target cumulative update.
Download all MSU files for update KB5129194 from the Microsoft Update Catalog and place them in the same folder (for example, C:/Packages). Ensure no other files are present in the folder.
This update consists of the following update file(s).
Method 1: Install each MSU file individually, in order
Double-click each file in the following order to install that update (if there is more than one .msu file listed):
windows11.0-kb5129194-arm64.msu
Note If a required checkpoint cumulative update is already present, a message will indicate that the update is already installed. For guidance on using the Windows Update Standalone Installer (Wusa.exe), see Description of the Windows Update Standalone Installer in Windows .
Method 2: Install all MSU files together
Use Deployment Image Servicing and Management (DISM.exe) to install the target cumulative update. DISM automatically scans the folder specified in the PackagePath folder and installs any required checkpoint cumulative updates.
Updating a Windows PC
To apply this update on a running Windows PC, run the following command from an elevated Command Prompt window:
DISM /Online /Add-Package /PackagePath:c:\packages\windows11.0-kb5129194-arm64.msu
Or, run the following command from an elevated PowerShell window:
`Add-WindowsPackage -Online -PackagePath "c:\packages\windows11.0-kb5129194-arm64.msu"'
Updating Windows installation media
To apply this update to Windows installation media, see Update Windows installation media with Dynamic Update .
To add this update to a mounted image, run the following command from an elevated Command Prompt window:
DISM /Image:mountdir /Add-Package /PackagePath:windows11.0-kb5129194-arm64.msu
Or, run the following command from an elevated PowerShell window:
Add-WindowsPackage -Path "c:\\offline" -PackagePath "windows11.0-kb5129194-arm64.msu" -PreventPending
Classification : Security Updates
For a list of the files provided in this update, download the file information for out-of-band update KB5129194 .
For a list of the files provided in the servicing stack update, download the file information for the SSU (KB5125104) - version 28000.2950 .
Windows monthly updates explained
Description of the standard terminology used for Microsoft software updates
Windows release health
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
