Windows 11 KB5129195 Update: Fixes, Known Issues, and Installation Guide
QUICK ANSWER KB5129195 is an out-of-band cumulative security update released on September 14, 2026, for Windows 11 versions 24H2 and 25H2. It updates Windows...
QUICK ANSWER
KB5129195 is an out-of-band cumulative security update released on September 14, 2026, for Windows 11 versions 24H2 and 25H2. It updates Windows 11 25H2 to OS Build 26200.9457 and Windows 11 24H2 to OS Build 26100.9457.
The update fixes Remote Desktop Services instability, inaccessible Plan9 shared folders in certain Hyper-V-based Linux virtual machines, some multichannel USB audio failures, and the CVE-2026-62721 elevation-of-privilege vulnerability. If Windows Update displays “Restart required,” save your work and restart the computer to complete installation.
What Is Windows 11 Update KB5129195?
KB5129195 is a cumulative out-of-band, or OOB, update for the following Windows releases:
| Windows version | Build after installation |
|---|---|
| Windows 11, version 25H2 | 26200.9457 |
| Windows 11, version 24H2 | 26100.9457 |
An out-of-band update is released outside Microsoft’s normal monthly update schedule to address important security or reliability problems. Because KB5129195 is cumulative, it includes applicable improvements from previous updates in addition to its new fixes. Microsoft’s KB5129195 release notes confirm that it is available through Windows Update, Windows Update for Business, Microsoft Update Catalog, and WSUS.
The screenshot shows KB5129195 downloaded and waiting for a restart. The update is not fully applied until Windows completes that restart.
What Does KB5129195 Fix?
Remote Desktop Services instability
The September 2026 security update caused Remote Desktop Services to become unstable in some environments. Possible symptoms included:
- Failed or interrupted RDP connections
- Remote Desktop sign-in failures
- Servers hanging during Remote Desktop configuration
- Microsoft Management Console, RDS Licensing Diagnoser, File Explorer, or the Windows Update page becoming unresponsive
KB5129195 resolves this problem on Windows 11 versions 24H2 and 25H2.
Organizations affected on Windows 11 23H2 require the update applicable to that version, not KB5129195.
Hyper-V and Linux VM shared-folder problems
The update fixes a problem affecting applications that use Host Compute System-managed virtual machines. Host folders shared with Linux virtual machines through Plan9 could be missing or inaccessible.
Standard Hyper-V virtual machines that do not use Plan9 sharing were not affected.
Some USB multichannel audio failures
KB5129195 fixes failures affecting some USB Audio Class 1.0 devices when using eight-channel or 3D audio modes. Devices operating in standard stereo mode were not affected by this particular problem.
However, the update does not resolve every USB audio issue introduced by the September 2026 updates. See “Known Issues” below.
Security protection
KB5129195 includes protection for CVE-2026-62721, a Windows User-Mode Power Service elevation-of-privilege vulnerability. Details are available in the Microsoft Security Response Center advisory.
Known Issues and Limitations
USB Audio Class 1.0 devices may still fail
Some USB Audio Class 1.0 devices may experience:
- Device Manager error: “This device cannot start (Code 10)”
- No audio output
- Volume controls stuck at zero
- Unresponsive or unavailable Sound settings
Microsoft states that this remaining issue is limited to USB Audio Class 1.0 devices and is working on a resolution. KB5129195 fixes certain multichannel failures but does not fix all USB audio symptoms.
If affected, check the device manufacturer’s support information and Microsoft’s release-health documentation before changing or removing drivers. Avoid downloading drivers from unofficial websites.
Domain trust issue in some managed environments
Microsoft also reports that some domain-joined devices protected by Credential Guard can lose their secure relationship with an on-premises Active Directory domain after the September update or later updates. This applies mainly where Machine Identity Isolation was configured in an unsupported environment.
The feature requires domain controllers operating at Windows Server 2025 domain functional level or later. Microsoft provides a mitigation, but it involves policy or registry changes and secure-channel repair. IT administrators should follow the official Windows 11 25H2 release-health guidance rather than making unverified registry changes.
How to Install KB5129195
Install through Windows Update
For most users, the supported installation method is:
- Open Settings.
- Select Windows Update.
- Select Check for updates.
- Allow KB5129195 to download and install.
- Save all open work.
- Select Restart now, or schedule the restart for a suitable time.
Administrator credentials may be required on managed or restricted computers. Organization-managed devices may also receive the update according to Windows Update for Business, Intune, or Group Policy settings.
Complete a pending installation
If Windows displays Restart required, the update has downloaded but installation is not complete.
Before restarting:
- Save open documents.
- Close running applications.
- Keep a laptop connected to power.
- Allow sufficient time for the update to finish.
- Do not force the computer to power off while Windows is applying the update.
The restart estimate is approximate and may vary according to storage performance, device configuration, and other pending updates.
Install manually with Microsoft Update Catalog
IT professionals can obtain the standalone package from the Microsoft Update Catalog.
Microsoft lists separate packages for x64 and Arm64 systems. The Catalog may also require one or more checkpoint cumulative updates to be installed before the target package.
Before manual installation:
- Confirm whether the computer uses x64 or Arm64 architecture.
- Download only from Microsoft Update Catalog.
- Obtain every required checkpoint package.
- Follow Microsoft’s specified installation order.
- Do not mix packages intended for different architectures.
Windows Update handles these dependencies automatically and is preferable for ordinary users.
How to Verify That KB5129195 Is Installed
Check Windows Update history
- Open Settings.
- Select Windows Update.
- Open Update history.
- Look under Quality Updates for KB5129195.
A successful entry confirms that Windows recorded the installation.
Check the Windows build number
- Press Windows key + R.
- Enter:
winver
- Select OK.
After installation, the build should be:
- 26200.9457 on Windows 11 25H2
- 26100.9457 on Windows 11 24H2
A later build normally means that a newer cumulative update has superseded KB5129195 and includes its applicable fixes.
What to Do If KB5129195 Fails to Install
Restart and check again
A previous update or servicing operation may already be awaiting a restart. Restart Windows, return to Settings > Windows Update, and select Check for updates again.
Run the Windows Update troubleshooter
- Open Settings.
- Go to System > Troubleshoot > Other troubleshooters.
- Find Windows Update.
- Select Run.
- Apply recommended corrections and restart if requested.
Repair the Windows component store
If the update repeatedly fails, open Terminal (Admin) or Command Prompt (Admin) and run:
DISM.exe /Online /Cleanup-Image /RestoreHealth
After DISM completes successfully, run:
sfc /scannow
Restart the computer and check for updates again. These commands require administrator rights and may take several minutes.
Review the failure code
Open Settings > Windows Update > Update history and record the installation error code. Search for that exact code in Microsoft Support documentation or provide it to your IT administrator.
For business devices, administrators should review deployment rings, update policies, WSUS approvals, free disk space, endpoint-security controls, and Windows Update logs before attempting manual installation.
Should You Uninstall KB5129195?
Uninstalling the update is generally not recommended because it removes security protection and the included reliability fixes.
Consider removal only if:
- A serious problem began immediately after installation.
- Microsoft or the device manufacturer identifies the update as the cause.
- No supported workaround is available.
- The device can be protected while the update is temporarily removed.
If removal is necessary, open Settings > Windows Update > Update history > Uninstall updates, locate KB5129195, and select Uninstall. Administrator rights and a restart may be required. Some cumulative or servicing updates cannot be removed through this interface.
On organization-managed systems, contact the IT administrator before uninstalling or pausing updates.
What to Expect After Installation
After the required restart:
- Windows 11 should report build 26200.9457 or 26100.9457, unless a newer update is installed.
- Applicable Remote Desktop Services and Plan9 sharing problems should be resolved.
- Certain USB multichannel audio configurations should work again.
- Windows receives protection for CVE-2026-62721.
- Windows Update should no longer show KB5129195 as awaiting installation.
A later cumulative update may replace KB5129195 while retaining its applicable fixes.
FAQ
Frequently Asked Questions
Is KB5129195 a security update?
Yes. It is a cumulative out-of-band security update containing protection for CVE-2026-62721 and several reliability fixes.
Which Windows versions support KB5129195?
KB5129195 applies to all editions of Windows 11 versions 24H2 and 25H2. It is not the installation package for Windows 11 23H2 or Windows Server.
Why does Windows say that a restart is required?
Windows has downloaded and staged the update, but it must restart to replace protected system files and complete installation.
Can I continue using the computer before restarting?
Usually yes, but the update and its protections are not fully active until the restart finishes. Save your work and restart as soon as reasonably practical.
Does KB5129195 fix Remote Desktop problems?
It fixes the Remote Desktop Services instability caused by the September 2026 security update on supported Windows 11 24H2 and 25H2 systems.
Does KB5129195 fix every USB audio problem?
No. It fixes some failures involving eight-channel and 3D audio modes, but certain USB Audio Class 1.0 devices may still show Code 10, produce no sound, or have unresponsive audio controls.
Can KB5129195 be installed manually?
Yes. Packages are available from Microsoft Update Catalog for x64 and Arm64 systems. Manual installation may require checkpoint cumulative updates and should normally be handled by an administrator.
What if my build number is higher than 26200.9457 or 26100.9457?
A higher build normally indicates that a newer cumulative update is installed. Because Windows quality updates are cumulative, the newer update should include the applicable KB5129195 fixes.
FINAL RECOMMENDATION / CONCLUSION
Install KB5129195 and complete the required restart, especially on systems that use Remote Desktop Services or affected Hyper-V-based Linux environments. Verify the resulting build through winver or Windows Update history.
IT administrators should test the update on a representative device group before broad deployment, monitor the remaining USB Audio Class 1.0 issue, and review Microsoft’s release-health guidance for domain-joined devices using Machine Identity Isolation. Use Windows Update or approved enterprise-management channels whenever possible, and obtain manual packages only from Microsoft Update Catalog.
#KB5129195 #Windows11 #WindowsUpdate #Windows1125H2 #Windows1124H2 #SecurityUpdate #OutOfBandUpdate #PatchManagement #RemoteDesktop #RDS #HyperV #USBAudio #WindowsTroubleshooting #ITSupport #SystemAdministrator #MicrosoftUpdate #CVE202662721
SOURCES
Was this guide useful?
Your answer helps us keep BISONKB accurate and practical.