ZeroHour
Cyber Security Newspublished ()ingested Guru Baran

Microsoft Releases Emergency Windows 11 Update Following Patch Tuesday Bugs

highVulnerability exploited in the wildimportance 70CVE-2026-62721
AI summary · glm-5.3-flash

Microsoft issued emergency Windows 11 update KB5129195 to fix Patch Tuesday regressions and fully close the CVE-2026-62721 privilege escalation flaw.

Microsoft shipped out-of-band cumulative update KB5129195 for Windows 11 24H2 and 25H2 (builds 26100.9457 and 26200.9457) after the September 8 Patch Tuesday rollup, which addressed over 960 CVEs including two actively exploited flaws, broke Remote Desktop Services, Hyper-V Plan9 folder sharing, and USB audio. The emergency release also strengthens the incomplete fix for CVE-2026-62721, an elevation-of-privilege flaw in the Windows User-Mode Power Service that could let a local attacker gain SYSTEM privileges. Companion patches cover Windows 11 26H1, Windows 10, and Windows Server. Some USB Audio Class 1.0 and AMD Radeon graphics issues remain unresolved.

  • Emergency cumulative update KB5129195 targets Windows 11 24H2/25H2 builds 26100.9457 and 26200.9457.
  • September Patch Tuesday addressed 960+ CVEs, 106 rated critical, with two actively exploited.
  • Regressions broke Remote Desktop Services, Hyper-V Plan9 sharing, and USB audio devices.
  • Update strengthens the incomplete fix for CVE-2026-62721, a UMPS flaw enabling SYSTEM-level access.
  • USB Audio Class 1.0 and select AMD Radeon GPU issues remain unresolved.

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-62721
Insufficient granularity of access control in User-Mode Power Service (UMPS) allows an authorized attacker to elevate privileges locally.

Insufficient granularity of access control in User-Mode Power Service (UMPS) allows an authorized attacker to elevate privileges locally.

NVD description · AI analysis pending
7.8<1%
  • microsoft windows 10 1607
  • microsoft windows 10 1809
  • microsoft windows 10 21h2
  • +1 more
Full article891 words · extracted from cybersecuritynews.com · click to collapse

Microsoft has pushed out an emergency, out-of-band Windows 11 update after its September Patch Tuesday release triggered a wave of stability failures across enterprise and consumer machines.

The rushed fix, KB5129195, arrives less than a week after one of the largest security rollups the company has ever shipped, underscoring how quickly a massive patch can spiral into an operational headache for administrators worldwide.

The out-of-band update targets Windows 11 versions 24H2 and 25H2, advancing them to OS builds 26100.9457 and 26200.9457 respectively, and it lands as a mandatory cumulative package that installs automatically through Windows Update.

Microsoft released companion patches the same day for other affected platforms, including KB5129194 for Windows 11 26H1, KB5129236 for Windows 10 21H2 and 22H2, and separate server updates such as KB5129235, KB5129237, and KB5129238.

Because the update is cumulative, it includes every previous fix and security protection, so administrators don’t need to layer earlier packages before deploying it.

What Went Wrong After Patch Tuesday

The trouble began with KB5124008, Microsoft’s September 8 security update and the biggest Patch Tuesday of 2026. The release addressed a staggering number of vulnerabilities across more than 960 CVEs, with 106 rated critical and two already under active exploitation, including a flaw in the Windows Update Stack and another in the Advanced Local Procedure Call component.

In the rush to close such a broad attack surface, the update introduced several regressions that broke core functionality on otherwise healthy systems.

The most disruptive fallout hit Remote Desktop Services (RDS). After installing the September update, affected environments saw RDP connections fail after several minutes, sign-in errors, and servers hanging indefinitely at the “Please wait for the Remote Desktop Configuration” screen.

The instability rippled outward, leaving Microsoft Management Console, the RDS Licensing Diagnoser, File Explorer, and even the Windows Update settings page unresponsive. For organizations that depend on remote administration, the regression effectively cut off access to fleets of machines, forcing some admins into hard resets or update rollbacks as temporary measures.

Hyper-V and Virtual Machine Breakage

A second serious bug struck virtualization workflows. Applications relying on HCS-managed virtual machines lost the ability to share host folders with Linux guests using the Plan9 protocol, meaning shared directories either failed to appear or could not be mounted inside the guest environment.

Windows Subsystem for Linux (WSL) and Anthropic’s Claude Cowork were among the tools directly affected, with sandbox environments throwing errors that no Plan9 drive shares had been mounted.

Investigation traced the root cause to a change in the Plan9/9P filesystem-sharing implementation that rejected previously valid attach requests, allowing the VM to launch while blocking the guest from actually attaching to the shared filesystem. Standard Hyper-V virtual machines that do not use Plan9 were spared.

Notably, IT administrators who applied a temporary Group Policy mitigation for the earlier RDS issue must take an extra step: they need to re-enable the relevant Group Policy, install the out-of-band update, and restart the affected devices to fully clear the problem.

USB Audio and a Privilege Escalation Fix

The September update also silenced certain audio hardware. Some USB Audio Class 1.0 devices failed to start or produced no sound, surfacing “This device cannot start (Code 10)” errors in Device Manager, unresponsive volume controls, and dead sound settings.

KB5129195 only partially resolves this, restoring functionality for devices using 8-channel or 3D multichannel audio modes while other symptoms remain unfixed as Microsoft continues investigating.

Beyond stability, the emergency release carries a genuine security payload. It strengthens protections for CVE-2026-62721, an elevation-of-privilege vulnerability in the Windows User-Mode Power Service (UMPS).

Microsoft revised its advisory after determining the original September patch did not fully close the flaw, which could let a local attacker manipulate power-management requests to gain SYSTEM-level privileges.

Unresolved Issues and What Admins Should Do

Despite the rapid turnaround, KB5129195 is not a clean sweep. Microsoft acknowledges that several USB Audio Class 1.0 symptoms persist and that graphics driver crashes on select AMD Radeon hardware remain unaddressed, with the company still working toward complete resolutions. Community feedback likewise indicates the out-of-band fix did not fully cure every reported problem, keeping some environments in a holding pattern.

For administrators, the practical guidance is straightforward. The update installs in roughly ten minutes and typically needs a single restart, though machines with a pending Secure Boot certificate update may reboot more than once.

It flows automatically through Windows Update and Windows Update for Business, synchronizes to WSUS, and can be pulled manually from the Microsoft Update Catalog or deployed at scale through Intune and Configuration Manager.

Teams that had rolled back the original Patch Tuesday update to restore Remote Desktop access should now be able to reapply protections safely by moving to the out-of-band build.

Given the mix of critical security fixes and lingering regressions, organizations should test in a controlled ring where possible, prioritize systems exposed to the actively exploited September vulnerabilities, and monitor the Windows release health dashboard for updates on the audio and AMD GPU issues that Microsoft has yet to close.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.

Guru Baranhttps://cybersecuritynews.com

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Text extracted automatically; images, tables and formatting may be missing. Original: https://cybersecuritynews.com/emergency-windows-11-update/