Skip to content
anavem.com logoanavem.com logo
MitigatedMicrosoft Windows 11High severityNewsCVE-2026-62721Windows 11

Windows 11 KB5129195 Emergency Update Fixes RDS, Plan9, and Some USB Audio Failures

The emergency cumulative update fixes three September Patch Tuesday regressions and adds CVE-2026-62721 protection, but administrators still have a known issue to watch.

On this page

Key takeaways

  • KB5129195 is cumulative and can be installed directly on Windows 11 24H2 and 25H2.
  • It fixes RDS instability and Plan9 host folder shares used by HCS-managed Linux environments.
  • USB audio support is only partially restored; Code 10 and no-output cases can remain.
  • The update adds CVE-2026-62721 protection, while some Credential Guard systems may still hit domain trust failures.

What to do now

High urgency
  1. Deploy KB5129195 to affected Windows 11 24H2 and 25H2 devices, prioritizing RDS endpoints and Plan9-dependent systems.
  2. Confirm that devices report build 26100.9457 or 26200.9457 after installation.
  3. Retest Remote Desktop connectivity, management tools, Linux guest shares and representative USB audio hardware.
  4. Monitor Microsoft’s release-health entry for the unresolved audio symptoms and the Credential Guard domain trust issue.

Microsoft has shipped KB5129195 as an emergency out-of-band update for Windows 11 24H2 and 25H2 after the September security rollout destabilized Remote Desktop Services, broke Plan9 folder sharing in some Linux virtual machines and disrupted USB Audio Class 1.0 devices. The cumulative package raises Windows 11 to builds 26100.9457 and 26200.9457 and can be installed without first taking the faulty September rollup.

For IT teams, KB5129195 removes the choice between restoring Remote Desktop and keeping September security protections. It does not close every support case, however: some USB audio failures remain open, and Microsoft lists a separate domain trust issue for certain Credential Guard configurations.

KB5129195 restores RDS stability and Plan9 shares on Windows 11 24H2 and 25H2, partially fixes USB audio, and adds a new security protection.

Deploy KB5129195 on affected Windows 11 24H2 and 25H2 devices, prioritize RDS and Plan9-dependent systems, retest USB audio, and watch the known Credential Guard trust issue.

Affected & context

Event summary

Microsoft released KB5129195 on September 14, 2026, an out-of-band cumulative security update for Windows 11 24H2 and 25H2. It moves devices to builds 26100.9457 and 26200.9457, fixes Remote Desktop Services instability, restores HCS Plan9 host folder sharing, partially repairs USB Audio Class 1.0 failures, and adds protection for CVE-2026-62721.

Why it matters

RDS regressions disrupted connections and administrative tools, while the Plan9 bug broke shared folders used by WSL and Claude Cowork. Because KB5129195 is cumulative, administrators can deploy it directly instead of rolling back September security fixes.

Who is affected

Windows 11 version 24H2 and 25H2 systems, especially Remote Desktop endpoints, HCS-managed Linux environments that depend on Plan9 shares, and PCs using USB Audio Class 1.0 hardware.

Vendors
Microsoft
Products
Windows 11 version 24H2Windows 11 version 25H2
Organizations
Organizations operating Windows 11 24H2 or 25H2 fleets
Geography
global
Industry
Information technology
CVEs
CVE-2026-62721

Quick facts

Release date
September 14, 2026
Windows 11 24H2 build
26100.9457
Windows 11 25H2 build
26200.9457
Update type
Out-of-band cumulative security update
Primary fixes
RDS stability and Plan9 host folder sharing
Partial fix
USB Audio Class 1.0 8-channel and 3D modes
Security and known issue
CVE-2026-62721 protection; some Credential Guard trust failures remain

What KB5129195 changes on Windows 11

Microsoft released KB5129195 on September 14, 2026, outside the normal Patch Tuesday schedule. The package targets Windows 11 version 24H2 and 25H2 and advances the operating systems to builds 26100.9457 and 26200.9457 respectively.

This is a cumulative security update, not a narrow hotfix. It includes the protections from the September 8 rollout, so a device can install KB5129195 directly even if administrators paused or removed the earlier package while troubleshooting.

Microsoft distributes the update through Windows Update, Windows Update for Business, WSUS and the Microsoft Update Catalog. Consumer devices using default Windows Update settings can receive it automatically, while managed fleets can stage deployment through their normal servicing rings.

  • KB5129195 raises Windows 11 24H2 to build 26100.9457 and 25H2 to build 26200.9457.

Builds: 26100.9457 for Windows 11 24H2 and 26200.9457 for Windows 11 25H2.

Remote Desktop and Plan9 fixes carry the biggest operational value

The Remote Desktop regression was the most disruptive change. After the September update, RDS connections could drop after several minutes, sign-ins could fail and affected hosts could stop responding. Microsoft also documented hangs in tools such as MMC, the RDS Licensing Diagnoser, File Explorer and the Windows Update settings page.

KB5129195 contains Microsoft’s fix for that instability on Windows 11 24H2 and 25H2. Organizations that removed the September update to restore access can install this cumulative package to regain the security fixes and the RDS repair in one step.

The update also restores Plan9 host folder sharing for applications that create Linux virtual machines through the Host Compute System. Microsoft specifically names Windows Subsystem for Linux and Claude Cowork as affected scenarios. Conventional Hyper-V virtual machines that do not depend on Plan9 shares were outside the scope of this regression.

  • The update fixes RDS instability and restores Plan9 host shares used by WSL and Claude Cowork.

Deployment priority: RDS hosts and Plan9-dependent HCS or WSL environments.

Advertisement

USB audio is only partly fixed

The September regression affects USB Audio Class 1.0 devices. Reported symptoms include a Code 10 error in Device Manager, no audio output, unresponsive volume controls and sound settings that fail to react.

KB5129195 fixes the failure on devices using 8-channel and 3D audio modes, but Microsoft does not describe the audio work as complete. Systems that still show Code 10, silent output or frozen controls remain under investigation, so administrators should test the exact hardware model rather than treating installation success as proof that audio is restored.

The package also adds protection for CVE-2026-62721, a Windows User-Mode Power Service elevation-of-privilege vulnerability. That security content gives organizations a reason to deploy the update even on systems that never encountered the RDS, Plan9 or audio regressions.

  • USB Audio Class 1.0 support is restored for 8-channel and 3D modes, while some failures remain open.

USB audio caveat: 8-channel and 3D modes are fixed, but some Code 10 and no-output cases remain.

A known domain trust issue remains

Microsoft lists a separate known issue for some domain-joined devices that use Credential Guard with Machine Identity Isolation enforcement. Affected systems can lose the secure trust relationship with their domain, creating authentication and management problems after the update.

The documented workaround is intended for administrators: temporarily disable the relevant enforcement, restore the machine’s secure channel, and follow Microsoft’s release-health guidance before re-enabling protections. Because that process changes a security control, it should be tested and approved through normal change management rather than applied broadly.

A sensible rollout starts with RDS session hosts and systems that depend on Plan9 shares, followed by a representative sample of USB audio hardware and domain-joined endpoints. Verify the new build, Remote Desktop connectivity, shared folders, audio output and the domain secure channel before expanding deployment.

  • Some domain-joined devices using Credential Guard with Machine Identity Isolation can lose domain trust.

Known issue: some Credential Guard deployments can still lose the domain secure channel.

Timeline

  1. Microsoft releases KB5129195 out of band

    The cumulative Windows 11 24H2 and 25H2 update ships with RDS and Plan9 fixes, a partial USB audio repair, and CVE-2026-62721 protection.

    Source: Microsoft Support KB5129195

    Confidence: High

Impact

KB5129195 resolves the main Windows 11 regressions introduced by the September security update, restoring RDS reliability and Plan9 shares while only partially repairing USB audio.

Business impact

Organizations can restore Remote Desktop access and shared-folder workflows without uninstalling September security protections, reducing downtime on managed endpoints and administrative systems.

Technical impact

The update stabilizes RDS components, restores HCS Plan9 host shares and repairs 8-channel and 3D modes on USB Audio Class 1.0 devices. Some Code 10 and no-output audio failures remain open.

Security impact

KB5129195 carries forward September security fixes and adds protection for CVE-2026-62721, a Windows User-Mode Power Service elevation-of-privilege vulnerability.

Privacy impact

Microsoft has not identified a direct privacy impact associated with these regressions.

Affected audience: Windows administrators and IT operations teams, Organizations running Remote Desktop Services, WSL and Claude Cowork users relying on Plan9 host shares, Users of USB Audio Class 1.0 hardware, Enterprise endpoint management teams, Security teams tracking CVE-2026-62721

Action required.

Technical details

CVEs
CVE-2026-62721
CVSS
7.8
EPSS
0.00408
Attack vector
local
Affected versions
Windows 11 version 24H2 before build 26100.9457, Windows 11 version 25H2 before build 26200.9457
Patched versions
Windows 11 version 24H2 build 26100.9457, Windows 11 version 25H2 build 26200.9457
CWEs
CWE-1220
MITRE ATT&CK
T1068 - Exploitation for Privilege Escalation

Detection methods

  • Verify the installed OS build with winver or endpoint inventory: 26100.9457 for 24H2 or 26200.9457 for 25H2.

Mitigations

  • Install KB5129195 through Windows Update, Windows Update for Business, WSUS or the Microsoft Update Catalog.
  • Use staged deployment rings and validate RDS, Plan9 shares, USB audio and the domain secure channel before broad rollout.
  • Keep following the Windows release-health dashboard for the remaining known issues.

Workarounds

  • For the domain trust issue, follow Microsoft’s documented administrator procedure to adjust Machine Identity Isolation enforcement and restore the secure channel; test the change before broad use.

Technical references

Response

Vendor statement

Microsoft released KB5129195 as an out-of-band cumulative security update and documented the resolved regressions, the partial USB audio fix and the remaining known issue in its support and release-health pages.

Authorities

No separate government or national CERT statement was identified at the time of verification.

Customer guidance

Install the update through a supported servicing channel, validate affected workloads and continue monitoring Microsoft’s Windows release-health dashboard for the remaining audio and domain trust issues.

Response status: Patched

Patch available: No

Workaround available: No

Updates

  1. Initial article prepared and verified

    Original English analysis completed with Microsoft sources, SEO metadata, FAQ, CVE context, and a generated cover image.

    Updated by Emanuel De Almeida

    Major update

    Update source

FAQ

What does KB5129195 fix?

KB5129195 fixes Remote Desktop Services instability, restores HCS Plan9 host folder shares, repairs 8-channel and 3D modes on USB Audio Class 1.0 devices, and adds protection for CVE-2026-62721.

Which Windows 11 builds receive KB5129195?

Windows 11 24H2 moves to build 26100.9457 and Windows 11 25H2 moves to build 26200.9457. Use winver or your device-management inventory to confirm the installed build.

Do I need the September 8 update before installing KB5129195?

No. KB5129195 is cumulative, so it can be installed directly and includes the September security protections together with the out-of-band fixes.

Does KB5129195 completely fix the USB audio problem?

No. Microsoft says the update fixes 8-channel and 3D audio modes, but some Code 10, no-output and unresponsive-control symptoms remain under investigation.

What known issue remains after installing KB5129195?

Microsoft documents a domain secure-channel trust issue on some domain-joined devices using Credential Guard with Machine Identity Isolation enforcement. Administrators should follow the official workaround and test it carefully.

The bottom line

KB5129195 is the cumulative out-of-band update that Windows 11 24H2 and 25H2 administrators needed after September’s RDS, Plan9 and USB audio regressions. It restores the two most disruptive workloads, partially repairs audio and includes CVE-2026-62721 protection.

Deploy KB5129195 through a controlled rollout, verify the exact workloads and hardware affected, and keep tracking Windows release health for the issues that remain open.

What happens next

Microsoft is still working on the remaining USB Audio Class 1.0 symptoms and the known Credential Guard domain trust issue. Future cumulative updates are expected to carry these fixes forward.

What to do

Identify Windows 11 24H2 and 25H2 systems in your fleet, approve KB5129195, then test RDS, Plan9 shares, USB audio and the domain secure channel before broad deployment.

Sources

  1. Microsoft · Sep 14, 2026 · Primary source

    Claims supported
    • Release date, supported builds, cumulative servicing model, fixes, CVE protection, and known issues.
  2. Microsoft · Sep 14, 2026 · Primary source

    Claims supported
    • Current incident status, unresolved audio symptoms, and domain trust guidance.
  3. Microsoft · Sep 14, 2026 · Primary source

    Claims supported
    • Official package availability through the Microsoft Update Catalog.
  4. HTMD Community · Sep 15, 2026

    Claims supported
    • Independent report of affected workloads and residual issues, used only as a secondary lead.
    • Published September 15, 2026 with a readable overview of the KB5129195 fixes.
  5. Microsoft Security Response Center · Aug 11, 2026 · Primary source

    Claims supported
    • CVE title, publication date, CVSS 7.8, local attack vector, privilege-escalation impact, and CWE-1220.
    • Official Microsoft advisory and patch reference for CVE-2026-62721.

Reader feedback

Was this helpful?
Rate this articleRate

Written reviews

Loading reviews…