LIVE · cybersecurity feed
Live wire
patch

Microsoft releases emergency Windows updates to fix RDS failures

Microsoft has released emergency out-of-band Windows updates to fix Remote Desktop Services failures caused by this month's security updates, along with Hyper-V and USB audio problems on some Windows versions. [...]

zeroday.news ·

Photo: Ank Kumar (CC BY-SA 4.0) via Wikimedia Commons

Microsoft has released emergency out-of-band updates for various Windows versions to address critical issues, including Remote Desktop Services (RDS) failures, Hyper-V problems, and USB audio malfunctions. These issues were introduced by the security updates deployed earlier in September 2026.

The September security updates caused widespread instability in Remote Desktop Services on affected systems, leading to failures in RDP connections and sign-ins, and in some instances, rendering servers unresponsive. Microsoft had previously acknowledged these problems following numerous reports from Windows administrators. Related components such as Microsoft Management Console (MMC), RDS Licensing Diagnoser, File Explorer, and the Windows Update page could also become unresponsive on affected systems.

The new out-of-band updates, released on September 14, are intended to resolve these issues. Specific updates include KB5129194 for Windows 11 26H1, KB5129195 for Windows 11 24H2 and 25H2, and KB5129236 for Windows 10 21H2 and 22H2. For server environments, KB5129235 addresses issues on Windows Server 2025, while KB5129237 targets Windows Server 2022. These server updates specifically fix RDS failures caused by KB5122871 on Windows Server 2025 and KB5122882 on Windows Server 2022.

Prior to the release of these permanent fixes, Microsoft had offered Group Policy mitigations for affected Windows and Windows Server systems. Administrators also found that uninstalling the problematic September security updates restored Remote Desktop functionality, though this action also removed the security patches included in those updates.

The new updates are available through various channels. KB5129194 for Windows 11 26H1 can be obtained via Windows Update, Windows Update for Business, the Microsoft Update Catalog, and Windows Server Update Services (WSUS). The out-of-band updates for Windows Server 2022 and Windows Server 2025 are accessible through the Microsoft Update Catalog.

Beyond RDS, the out-of-band Windows 11 updates also address a Hyper-V issue impacting applications that utilize Host Compute Service (HCS)-managed virtual machines. Some applications experienced difficulties when attempting to share Windows host folders with Linux virtual machines using Plan9, resulting in shared folders either not appearing or becoming inaccessible within the guest environment.

Furthermore, the updates resolve an audio problem affecting certain USB Audio Class 1.0 devices when operating in multichannel audio modes, such as 8-channel and 3D audio. While these devices functioned normally in standard stereo mode, they could fail when switching to multichannel configurations.

However, these emergency updates do not resolve all USB audio problems introduced by the September updates. Microsoft has stated that some USB Audio Class 1.0 devices may still fail to start or produce audio after installing the September 8, 2026, security update. Symptoms can include a "This device cannot start (Code 10)" error in Device Manager, no audio output, unresponsive volume controls, or unavailable sound settings. This specific issue is confined to USB Audio Class 1.0 devices, and Microsoft is actively working on a further fix for the remaining audio problems.

patch
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

The vulnpocalypse rains iBugs down on Apple with record-setting number of patches

September Patch Tuesday part 2?

vulnerabilitycritical

Oracle September 2026 Critical Security Patch Update addresses 672 CVEs

Oracle addresses 672 CVEs in its September 2026 Critical Security Patch Update with 673 patches, including 104 critical updates. Key Takeaways The September 2026 Critical Security Patch Update (CSPU) contains fixes for 672 unique CVEs in 673 security updates 104 issues (15.5% of all patches) were assigned a critical severity rating Oracle E-Business Suite received the highest number of patches at

patch

Before You Patch. Why Patch Reliability Matters for Confident Deployment

Executive Summary Microsoft’s September 2026 security updates, KB5124008 and KB5124012, have been linked to USB audio failures on some Windows systems, highlighting the operational risk that can accompany security patching. Qualys TruRisk Eliminate classified both updates as Low Reliability, signaling the need for additional validation before production deployment. Patch Reliability helps IT and s

vulnerabilityhigh

Acronis warns of actively exploited flaw in its cPanel backup plugin

Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. [...]

malware

KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

Cybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN. Elastic Security Labs is tracking the activity under the moniker REF9334. Active since at least May 2025, the threat actor has used lures that impersonate a dozen Brazilian banks and install a malicious browser extension on Google Chrome and

malware

Iranian spies hit Windows machines with Chosen Brick data-stealing malware

'Enemies of the regime' on notice