Microsoft Confirms Windows 11 Update Bug Causing Black Screens and Loading Issues
Microsoft says a Windows 11 update can black-screen Azure Virtual Desktop sessions after sign-in.
Microsoft confirmed that Windows 11 updates starting with the August 27, 2026 non-security preview can stop the desktop shell from starting after sign-in. The failure is seen mainly on Azure Virtual Desktop hosts using FSLogix with certain existing profiles, affecting 26H1 (KB5120996, OS Build 28000.2804) and 25H2/24H2 (KB5120998). Microsoft marks it mitigated and offers a manual explorer.exe launch plus Known Issue Rollback policies KB5124006 and KB5124010 while a permanent fix is developed. Windows Server is not listed as affected.
- Black screens follow sign-in when Explorer crashes and the shell fails to start.
- Impact is mainly Azure Virtual Desktop hosts using FSLogix with existing profiles.
- Affected builds: 26H1 via KB5120996; 25H2 and 24H2 via KB5120998.
- Users can launch explorer.exe; enterprises should deploy the matching KIR and reboot.
- Microsoft calls it mitigated; the rollback is temporary until a permanent fix.
Full article496 words · extracted from cybersecuritynews.com · click to collapse
Microsoft has confirmed a Windows 11 issue that can leave users staring at a black screen after signing in, with the desktop shell failing to start automatically.
The problem emerged after installation of the August 27, 2026 non-security preview updates and later cumulative updates. Microsoft lists the incident as “mitigated,” while engineers continue developing a permanent correction for a future Windows update.
The failure has been observed primarily on Azure Virtual Desktop hosts using FSLogix, particularly when sessions load certain existing user profiles. Affected users may authenticate but never reach a usable desktop.
In some cases, they can regain access only by starting the desktop session manually, while Windows Application event logs may record crashes involving Windows Explorer.
Windows 11 Update Bug Causing Black Screens
For Windows 11 version 26H1, Microsoft traces the regression to KB5120996, released as an optional preview update with OS Build 28000.2804. Windows 11 versions 25H2 and 24H2 are also affected, with Microsoft’s dashboard identifying KB5120998 as the originating August update for those releases. No Windows Server platform is currently listed as affected.
Users who encounter the black screen can apply an immediate workaround without removing the update. Press Ctrl+Shift+Esc to open Task Manager, choose “Run new task,” enter “explorer.exe,” and select OK. This manually launches the Windows shell and should restore access to the desktop for the session, although it does not eliminate the underlying update regression.
Microsoft has issued a more scalable Known Issue Rollback, or KIR, for enterprise-managed environments. Administrators managing Windows 11 26H1 should deploy the KB5124006 260924_20071 rollback policy, while Windows 11 25H2 and 24H2 environments require KB5124010 260924_20021.
Install the matching policy, configure it under Computer Configuration > Administrative Templates, and then restart the device.
KIR is designed to reverse only the problematic non-security change while preserving the remainder of the installed update. Microsoft’s deployment guidance says administrators can distribute the policy through Group Policy in Active Directory or hybrid Microsoft Entra ID environments; managed devices ordinarily refresh policy within 90 to 120 minutes, while gpupdate can accelerate retrieval. Every affected endpoint must restart after applying the setting.
For IT teams operating pooled or multi-session AVD infrastructure, the incident warrants validation before broad update deployment. Administrators should identify hosts running the affected Windows 11 builds, correlate sign-in failures with Explorer crash events, test the correct KIR against representative FSLogix profiles, and monitor session recovery after reboot.
Microsoft cautions that the rollback simply disables the offending change until a durable fix arrives, so organizations should retain the policy and track Windows release-health updates rather than treating the workaround as final remediation.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Guru Baranhttps://cybersecuritynews.com
Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.