Windows 11 26H1 Security Update Expands Secure Boot Certificate Protection
Microsoft's Windows 11 26H1 update KB5124012 widens Secure Boot certificate deployment and patches two elevation flaws.
Microsoft released September 2026 cumulative update KB5124012 for Windows 11 version 26H1, reaching OS Build 28000.2954 and broadening automatic deployment of new Secure Boot certificates. Servicing stack update KB5125104 is included, and installation media must contain boot.stl or Dynamic Update setup can fail with error 0xc0430001. Out-of-band update KB5129194 (Build 28000.2956) fixes Remote Desktop and virtualization issues and adds protections for elevation-of-privilege flaws CVE-2026-62721 and CVE-2026-85921. Microsoft warned Credential Guard machine accounts can lose their Active Directory secure channel unless domain controllers are at Windows Server 2025 functional level or higher. Version 26H1 is offered only on new devices with selected silicon.
- KB5124012 updates Windows 11 26H1 to OS Build 28000.2954.
- Automatic Secure Boot certificate coverage expands for consumer and unmanaged PCs.
- KB5129194 adds protections for CVE-2026-62721 and CVE-2026-85921.
- Credential Guard accounts may lose Active Directory trust after install.
- Missing boot.stl on install media can cause error 0xc0430001.
Vulnerabilities mentionedAll →
- CVE-2026-627217.8<1%Insufficient granularity of access control in User-Mode Power Service (UMPS) allows an authorized attacker to elevate privileges locallypublished · microsoft windows 10 1607
- CVE-2026-859218.2—Double Free in Windows Secure Kernel Mode Enables Local Privilege Escalationpublished
Full article579 words · extracted from gbhackers.com · click to collapse
Microsoft has released the cumulative security update for September 2026 for Windows 11 version 26H1. This update expands the range of systems that can automatically receive new Secure Boot certificates.
KB5124012, released on September 8, brings devices to OS Build 28000.2954. It includes enhanced, high-confidence device-targeting data to improve certificate deployment coverage across supported PCs and non-managed business endpoints.
Windows 11 26H1 Security Update
The rollout of Secure Boot certificates is significant because Secure Boot offers essential protection against bootkits and other pre-OS malware.
This UEFI-based protection mechanism validates trusted boot components before Windows starts, helping to prevent the execution of unsigned or tampered firmware, bootloaders, and early-stage operating system code.
By broadening automated certificate targeting, Microsoft aims to minimize deployment gaps as it continues its Secure Boot certificate transition over the coming months.
Microsoft stated that deployment will continue through Windows Update for supported consumer PCs and business devices that are not centrally managed.
Organizations using managed update processes should evaluate their update rings, firmware compatibility, and recovery procedures before broadly deploying this package. The update also includes KB5125104, which is a servicing stack update designed to improve the reliability of Windows Update installations.
Administrators updating Windows installation media should ensure they include the boot.stl file. Microsoft warned that omitting this file from Dynamic Update-enabled deployment media could prevent systems from starting the installation environment and may trigger error 0xc0430001.
This file is used during Secure Boot validation and must correspond to the Windows version and architecture being deployed. Microsoft recommends using its Update WinPE script, although administrators can manually copy the file from Windows\Boot\EFI into the corresponding folder on the installation media.
In addition to Secure Boot improvements, KB5124012 addresses September security vulnerabilities and includes several platform-level corrections.
It resolves unexpected crashes of Microsoft Teams and Outlook on Arm64 PCs, audio redirection failures in Remote Desktop, and diagnostic limitations in OMA-DM client logging.
This enhancement adds certificate-chain information for server connections, which may help enterprise administrators diagnose device-management connectivity issues.
However, the update has introduced operational risks for some enterprise environments. Microsoft has confirmed that Credential Guard-protected machine accounts may lose their secure channel to on-premises Active Directory domains after installing KB5124012 or later updates.
This issue relates to Windows beginning to enforce existing Machine Identity Isolation settings, which is supported only when devices connect to domain controllers running at the Windows Server 2025 Domain Functional Level or higher.
Affected organizations may experience failed interactive domain logins and “trust relationship” errors. Microsoft recommends disabling Machine Identity Isolation when it was configured in unsupported environments, restarting the device, and repairing the secure channel. The company plans to temporarily suspend enforcement in a future update while enhancing this feature.
Additionally, Microsoft released an out-of-band update, KB5129194, on September 14. This update advances systems to Build 28000.2956 and addresses issues such as instability in Remote Desktop Services, Plan9 host-share failures in HCS-managed Linux virtual machines, and USB Audio Class 1.0 problems affecting 8-channel and 3D modes.
It also includes protections against elevation-of-privilege vulnerabilities CVE-2026-62721 and CVE-2026-85921.
Windows 11 version 26H1 is available only on new devices using select new silicon. It is not offered as an in-place Windows Update upgrade for earlier Windows 11 versions.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.