Skip to main content

Morning Overview

Microsoft issued an out-of-band fix for the September Windows 11 update that broke Remote Desktop

Microsoft released an out-of-band update on September 14, 2026, to repair Remote Desktop failures introduced by its own September security update for Windows 11. The regular update, KB5124008, arrived on September 8. Six days later, KB5129195 shipped outside the normal monthly schedule to stop Remote Desktop Services from becoming unstable and to fix several other faults the first update had caused.

The sequence began with an unusual warning. Days before the September update misbehaved, Microsoft had urged Windows users to install updates promptly, citing the speed of AI-assisted attacks. The patch that followed broke connections for enterprise administrators.

What KB5124008 broke on September 8

KB5124008 is the September 2026 cumulative update for Windows 11 versions 24H2 and 25H2, raising builds to 26100.9445 and 26200.9445. Its Microsoft support page lists the release date and builds. Within days, administrators reported that Remote Desktop Services, the server component behind RDP sessions, was dropping connections and rejecting sign-ins, and that users were stuck on configuration dialogs.

The failures did not stop at Remote Desktop. Windows Latest documented Explorer.exe crashing or failing to start after login, producing black screens on virtual desktop setups that use Citrix, FSLogix, Horizon or ProfileUnity, along with unconfirmed reports of File History backups failing to detect external drives and driver problems on some AMD Radeon graphics cards. Microsoft did not confirm the File History and AMD reports.

One of the confirmed faults reached beyond Windows itself. Microsoft acknowledged that apps relying on Hyper-V’s host-managed Linux virtual machines with Plan9 shared folders broke because the update changed how file sharing is implemented, and Anthropic confirmed that the September 8 update had stopped the workspace in its Claude desktop app from reaching local files. That Plan9 fault is the one the September 14 patch later addressed, which shows how a single monthly update can ripple into unrelated software.

Microsoft’s admission, and its limits

Microsoft did not pretend to understand everything at first. As Windows Latest relayed, the company said that “the September Windows updates were extensive and need more data to understand and root cause.” That is a narrower statement than a full acknowledgment of every reported fault, and the distinction affects how much of the early coverage can be treated as confirmed.

What Microsoft did confirm was documented on its Windows 11 25H2 release health page. The Remote Desktop Services instability is listed as originating in KB5124008, dated September 8, and as resolved by KB5129195 on September 14. The same page lists a domain trust relationship loss tied to the update’s Machine Identity Isolation feature as mitigated, not resolved, with a workaround that disables the feature and repairs the secure channel using the PowerShell command Test-ComputerSecureChannel.

Repairs in out-of-band update KB5129195

The fix arrived as KB5129195, which raised builds to 26100.9457 and 26200.9457. Microsoft’s notes say it resolves an issue where “RDS might become unstable, causing RDP connection and sign-in failures,” and that related tools such as the Microsoft Management Console and File Explorer could also become unresponsive before the repair.

The update fixed more than Remote Desktop. It addressed a Hyper-V problem in which applications using host-managed virtual machines failed when sharing a host folder with Linux virtual machines through Plan9, and a USB Audio Class 1.0 bug that broke 8-channel and 3D audio modes. It also carries protections for CVE-2026-62721, a Windows User-Mode Power Service elevation-of-privilege flaw, so skipping it leaves a security gap open as well.

Problems that outlasted the fix

Administrators who could not wait for the patch had few clean options. Windows Latest listed restarting Explorer, creating a new user profile, or removing KB5124008 outright, and it noted that removal is not recommended because the update also carries security patches. Microsoft’s release health page describes a related black screen and Explorer crash pattern on Azure Virtual Desktop hosts using FSLogix, traced to an earlier update, KB5120998 from August 27, with a Known Issue Rollback available through Group Policy.

Not everything went away. Notebookcheck reported that some USB audio devices still failed or threw Code 10 errors, that AMD graphics driver crashes persisted, that File History failures from the original update remained, and that some secure domain sign-in failures continued after installation. Microsoft’s release health page separately classes the USB audio issue as mitigated, with KB5129195 only partly resolving it.

According to Notebookcheck, KB5129195 is rolling out automatically through Windows Update, with manual downloads available from the Microsoft Update Catalog and management tools such as Intune. For Remote Desktop administrators the practical result is a closed issue on Microsoft’s own tracker. For everyone else the open question is whether the AMD, File History and domain sign-in reports, none of which Microsoft has marked resolved, get a fix before the next monthly update.

This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.


More from Morning Overview