Windows 11 KB5129195 fixes RDS failures: affected builds, scope and what remains
Windows 11 KB5129195 is Microsoft’s out-of-band fix for defined RDS, Plan9-sharing and multichannel USB-audio issues on versions 24H2 and 25H2.

- Windows 11 KB5129195 is a cumulative out-of-band update dated 14 September 2026 for Windows 11 24H2 and 25H2, advancing them to builds 26100.9457 and 26200.9457 respectively.
- Microsoft says the package resolves the documented September RDS instability that could cause RDP connection and sign-in failures, Remote Desktop Configuration hangs, and unresponsive management tools in affected environments.
- It also restores Plan9 host-folder access for affected HCS-managed Linux virtual machines; standard Hyper-V virtual machines that do not use Plan9 are not in that documented issue scope.
- The USB Audio Class 1.0 repair is partial: 8-channel and 3D-audio symptoms are addressed, while Code 10, no-output, volume-control and sound-settings symptoms remain under investigation.
- KB5129195 includes protections for CVE-2026-62721, but Microsoft characterises that flaw as a local, low-privilege elevation-of-privilege issue and records no active exploitation in the reviewed advisory.
KB5129195 is the Windows 11 out-of-band repair for a defined set of September issues
Windows 11 KB5129195 is Microsoft’s 14 September 2026 out-of-band, or OOB, cumulative update for all editions of Windows 11 version 24H2 and version 25H2. An out-of-band release arrives outside the usual monthly cadence when a vendor chooses to deliver a correction sooner. This one carries forward earlier fixes and adds a narrowly described combination of reliability and security work: a Remote Desktop Services repair, a Hyper-V-related Linux virtual-machine sharing repair, a partial USB audio repair, and protections for CVE-2026-62721.
The practical point is scope. KB5129195 is not a blanket answer for any computer with a remote-access, virtualisation or sound problem. Microsoft ties its most prominent reliability repair to environments affected after the September Windows security update. The company identifies specific symptoms and a specific product scope. That makes version and symptom checks more useful than deploying from a headline alone. It also means an organisation should not treat the package as a substitute for checking its own Windows servicing policies, restart controls and change records.
For Windows 11 24H2, the installed build after the update is 26100.9457. For 25H2, it is 26200.9457. Those build numbers are the cleanest post-installation confirmation point because Microsoft publishes the update as cumulative rather than as a separate feature switch. The Microsoft Update Catalog lists x64 and Arm64 variants for those two versions, so manually obtained packages must still match the device architecture.
The RDS repair addresses instability, not every cause of an RDP failure
Remote Desktop Services, or RDS, provides Windows remote-session infrastructure; Remote Desktop Protocol, or RDP, is the protocol used to connect to a remote session. Microsoft says that after the September 2026 security update, RDS could become unstable in some environments. The documented consequences include RDP connection failures after several minutes, sign-in failures, and servers hanging at the “Please wait for the Remote Desktop Configuration” screen. Microsoft Management Console, RDS Licensing Diagnoser, File Explorer and the Windows Update page could also stop responding.
KB5129195 is Microsoft’s stated resolution for that named issue on Windows 11 24H2 and 25H2. It does not establish that an RDP problem involving credentials, network routing, a gateway, a firewall, licensing, certificates or endpoint configuration has the same cause. An affected team can first record the Windows version and build, identify when the symptom began, and verify whether the failure pattern matches Microsoft’s description. That preserves a useful distinction between a confirmed Microsoft-known issue and an unrelated remote-access incident.
There is one documentation detail worth handling carefully. The KB5129195 overview refers to the September Windows security update as KB5122880, while Microsoft’s detailed 24H2 Release Health incident identifies KB5124008 and originating build 26100.9445. The reliable operational facts are that Microsoft marks the 24H2 RDS incident resolved by KB5129195 and that the OOB package is cumulative. The differing predecessor label should not be turned into a claim about root cause or used to diagnose every affected estate.
Deployment paths and verification should follow the managed estate, not a one-size-fits-all fix
Microsoft lists Windows Update, Windows Update for Business, the Microsoft Update Catalog and Server Update Services as delivery paths for KB5129195. Its release notes say the update is available through Windows Update and Microsoft Update, while the Catalog provides standalone packages for controlled deployment. Availability does not guarantee that every managed device sees or installs it at the same moment: deferral policies, approval rings, connectivity, architecture and existing servicing state can affect a device’s timing. A device that is not offered the package should be checked against the stated 24H2 or 25H2 scope before any manual action.
A measured deployment begins with a small representative group that includes the affected remote-session or virtual-machine workflow, followed by the organisation’s usual restart and monitoring steps. After the update, confirm the operating-system build, confirm that the device restarted as required, and repeat the original business workflow rather than merely confirming that the update entry exists. For the RDS incident, that can mean testing a normal sign-in and session path and checking that the previously unresponsive management surfaces behave normally. The goal is validation, not an assertion that a successful installation proves every service is healthy.
Microsoft says the latest servicing stack update and latest cumulative update are combined for this operating-system servicing model. In other words, the public release notes do not call for a separate pre-install of an SSU before KB5129195. Normal backups, maintenance-window decisions and rollback procedures still belong to an organisation’s own operating controls.
The Hyper-V fix is specifically about Plan9 shares in HCS-managed Linux VMs
The second reliability repair concerns applications using Host Compute Service, or HCS, managed virtual machines. Microsoft says some Linux guest environments could start normally after the September update yet fail to show or access folders shared from the Windows host through Plan9. Plan9 here is the host-folder sharing mechanism in the affected workflow; it does not mean that the entire virtual machine has failed. An application or sandbox that depends on that mounted folder can consequently fail even though the guest itself appears to be running.
Microsoft’s Release Health record makes two boundaries clear. Standard Hyper-V virtual machines that do not use Plan9 are not affected by this documented issue. The record also names Windows Subsystem for Linux and Claude Cowork as examples of affected applications or sandbox environments, but the category is broader than either named application: the relevant test is whether the workflow relies on HCS-managed Linux virtual machines and Plan9 host-folder sharing. Teams using local development environments should validate the exact mounted-folder operation that was broken, including read and write behaviour that is permitted by their own policies.
Administrators that put in a temporary Group Policy mitigation for this Plan9 issue have an extra follow-up. Microsoft says they should re-enable the policy, install the OOB update and restart to resolve the issue. That instruction differs from Microsoft’s RDS note, which says administrators using its temporary RDS Group Policy mitigation need take no action before installing the OOB update. Keeping the two instructions separate avoids a misleading single rule.
USB Audio Class 1.0 support is improved, but the remaining known issue is real
Microsoft says KB5129195 fixes a particular USB Audio Class 1.0 failure pattern: some devices that worked in standard stereo could fail when a user selected multichannel features, including 8-channel or 3D audio modes. For that scenario, the OOB update is the published resolution. This is useful for a workstation, media or conferencing setup that specifically lost multichannel capability after the September security update.
It is not accurate to describe the update as a full USB-audio repair. Microsoft’s known-issues section continues to list USB Audio Class 1.0 devices that may fail to start or produce audio after the September 8 update. It lists Device Manager error Code 10, no output, volume controls that do not respond or remain at zero, and unavailable or unresponsive sound settings. Microsoft says it is working on a resolution for those remaining symptoms. The release-health dashboard labels the broader issue “Mitigated,” not “Resolved.”
That wording matters when planning a rollout. A device that lost 8-channel or 3D audio has a Microsoft-documented repair to validate. A device with no sound, Code 10 or stuck controls may still be affected after KB5129195 and should not be declared fixed merely because the build number changed. The public documentation restricts the known issue to USB Audio Class 1.0 devices; it does not support general claims about every headset, microphone, Bluetooth device, sound driver or audio application.
CVE-2026-62721 is included security content, separate from the RDS reliability issue
KB5129195 includes protections documented in CVE-2026-62721, a Windows User-Mode Power Service, or UMPS, elevation-of-privilege vulnerability. Microsoft rates it Important with a CVSS 3.1 base score of 7.8. Its advisory says insufficient granularity of access control in UMPS could allow an authorised attacker to elevate privileges locally. The published vector is local, requires low privileges and requires no user interaction. Microsoft says a successful attacker could obtain SYSTEM privileges.
Those terms describe a meaningful security risk, but they do not make this a remote RDP flaw. Exposure means a relevant device has not received the available correction; exploitation would require a successful attack under the conditions Microsoft describes. At the time checked for this article, Microsoft marked the CVE as not publicly disclosed and not exploited, while assessing exploitation as “more likely.” Its 14 September revision says update links were added to address a missed fix. The article therefore treats the patch as security-relevant without claiming a current compromise campaign, a network entry route or an active attack.
The RDS correction and the UMPS vulnerability arrive in the same cumulative release, but Microsoft documents them as separate items. This distinction helps prevent an outage from being mistaken for evidence of an intrusion, and it prevents a CVE from being presented as the proven cause of a remote-access symptom.
Do not apply this Windows 11 package to Windows Server or Windows 10
The KB5129195 support page says it applies to Windows 11 24H2 and 25H2, all editions. That is the deployment boundary for this package. Microsoft issued other out-of-band updates for RDS problems in other product families, including separate updates for Windows Server and Windows 10. Similar RDS symptoms across products do not make a Windows 11 cumulative package interchangeable with a Server or Windows 10 package. Using the update identified for the installed operating system avoids an unsupported and potentially ineffective response.
Microsoft’s public Update Catalog also displays KB5129195 entries for a Windows 11 26H2 Insider Pre-Release build. That listing should not be used to widen the production guidance here. The supplied Microsoft Support article’s “Applies To” statement is the authoritative scope for this release story: Windows 11 24H2 and 25H2. Preview or Insider servicing follows its own channel and eligibility conditions, and an organisation should consult its applicable release documentation rather than infer coverage from a shared KB number.
This boundary is particularly important when incident response is under pressure. An RDS outage can tempt operators to look for one package that fits every host, but build, product and channel determine what is applicable. Independent reporting from BleepingComputer also records distinct OOB releases for Windows client and Server versions, reinforcing the need to select the product-specific update rather than copying the KB5129195 package across an estate.
What is confirmed, what remains unverified, and how to read the update’s status
The confirmed record is concise. Microsoft released a cumulative Windows 11 24H2/25H2 OOB update on 14 September; it sets the documented builds to 26100.9457 and 26200.9457; it resolves the listed RDS and Plan9-sharing issues; it repairs a defined multichannel USB audio symptom; and it includes a correction for CVE-2026-62721. Microsoft’s release-health records support the RDS and Plan9 resolution status and make clear that the broader USB Audio Class 1.0 issue is only partially resolved.
What the reviewed sources do not establish is just as important. They do not show that every computer running the predecessor security update experienced RDS trouble. They do not show that all USB-audio symptoms are repaired. They do not attribute every report of Explorer crashes, GPU errors, microphone faults or legacy backup trouble to the issue addressed here, or say KB5129195 fixes those reports. Nor do they show active exploitation of CVE-2026-62721. Independent coverage can flag user experience and corroborate the release, but Microsoft’s current documentation controls the supported scope and fix list.
For a reader asking whether Windows 11 KB5129195 is the right update, the shortest answer is: verify Windows 11 24H2 or 25H2, verify the described symptom, use an approved delivery path, restart as required and confirm the resulting build and the actual workflow. Recheck the Microsoft release notes before a broad deployment because known-issue status can change. This evidence-led approach is more durable than treating an emergency update as a universal fix or a security alarm without its stated conditions.
Reader guide
Article questions, answered
Short answers to common reader questions based on the reporting above.
What does Windows 11 KB5129195 fix?
Microsoft says KB5129195 resolves a Remote Desktop Services instability issue seen after the September 2026 Windows security update, restores certain Plan9 host-folder shares for HCS-managed Linux virtual machines, and fixes the 8-channel or 3D-audio failure mode for some USB Audio Class 1.0 devices. It also includes protections for CVE-2026-62721. It is not described as a cure for every RDP, Hyper-V or audio problem.
Which Windows 11 versions and builds receive KB5129195?
Microsoft’s KB5129195 release page applies the package to all editions of Windows 11 version 24H2 and version 25H2. After installation, 24H2 is build 26100.9457 and 25H2 is build 26200.9457. The Microsoft Update Catalog has separate x64 and Arm64 packages, so a manual installer must match the device architecture.
Does KB5129195 fix Remote Desktop on Windows Server or Windows 10?
No. KB5129195 is the Windows 11 24H2/25H2 package. Microsoft released separate out-of-band updates for other Windows client and Server versions. A Windows Server or Windows 10 administrator should use the update identified for that operating system rather than download this Windows 11 package.
Does KB5129195 fully resolve the USB Audio Class 1.0 problem?
No. Microsoft says the update resolves the multichannel symptoms involving 8-channel or 3D audio modes, but it is still working on other USB Audio Class 1.0 symptoms. Those include Device Manager Code 10, no audio output, unresponsive volume controls, and unavailable or unresponsive sound settings. The known issue is limited to USB Audio Class 1.0 devices.
Is CVE-2026-62721 a remote desktop attack or evidence of active exploitation?
No. Microsoft describes CVE-2026-62721 as a Windows User-Mode Power Service elevation-of-privilege vulnerability with a local attack vector and low privileges required. Microsoft’s reviewed advisory lists it as not publicly disclosed and not exploited, while noting that successful exploitation by an authorised attacker could yield SYSTEM privileges. That security item and the RDS reliability fix appear in the same cumulative update, but they are distinct issues.
Sources and further reading
These references support the factual context used in this article. Links open the original publisher.
- September 14, 2026—KB5129195 (OS Builds 26200.9457 and 26100.9457) Out-of-bandMicrosoft Support · accessed 16 September 2026
- Windows 11, version 24H2 known issues and notificationsMicrosoft Learn · accessed 16 September 2026
- CVE-2026-62721: Windows User-Mode Power Service (UMPS) Elevation of Privilege VulnerabilityMicrosoft Security Response Center · accessed 16 September 2026
- Microsoft Update Catalog search results for KB5129195Microsoft Update Catalog · accessed 16 September 2026
- Microsoft releases emergency Windows updates to fix RDS failuresBleepingComputer · accessed 16 September 2026
- Windows 11 KB5129195 OOB Update Fixes Security Flaw, RDS Issues, and MorePrajwal Desai · accessed 16 September 2026
- Windows 11 KB5129195 is out after Microsoft confirms major issues with the September 2026 update, but it won’t fix AMD GPU errorsWindows Latest · accessed 16 September 2026