The September 2026 Patch Tuesday cycle is a typical month in one sense (a single cumulative update per Windows 11 servicing branch) and an unusual one in another, because Microsoft followed it with an out-of-band release aimed at Remote Desktop Services. Administrators running fleets on Windows 11 25H2 (build 10.0.26200) and the newer 26H1 branch (build 10.0.28000) need to understand both packages before approving them in WSUS, Intune or an RMM patch policy. This guide summarises what changed, what to watch for, and how to verify the install.
Applies to Windows 11 25H2 and 26H1 (KB5124008 and KB5129195)
Table of Contents
Short answer: KB5124008 is the September 2026 cumulative update for Windows 11 25H2 and 26H1; it rolls up the month’s security fixes and servicing-stack changes and installs as a single LCU. KB5129195 is an out-of-band update released after Patch Tuesday to correct a Remote Desktop Services regression introduced by the cumulative update, so environments that host RDS or rely heavily on RDP should deploy KB5129195 on top of KB5124008 rather than skipping the month.
What KB5124008 contains
The cumulative update ships as a combined package with the servicing stack update, so there is no separate SSU to sequence first. The security content covers the usual Windows components (kernel, Win32k, networking stack, Hyper-V, printing and the Windows Update client itself). As with every monthly update since the switch to combined packages, the build number changes only in the last field; the branch identity stays 26200 or 28000. Feature changes arrive in the same package as gradual enablement, so two machines on the same build may show different behaviour depending on whether the controlled feature rollout has reached them.
Check the exact fixed CVE list in the Microsoft Security Update Guide for your build before you write a change record; the list is long and differs slightly between 25H2 and 26H1.
Why KB5129195 was released
Shortly after the cumulative update went out, Microsoft confirmed that KB5124008 could cause Remote Desktop session failures in some configurations, most visibly on hosts serving many concurrent RDP connections and on clients connecting through RD Gateway. Rather than wait for the October cycle, Microsoft published KB5129195 as an out-of-band cumulative update. It supersedes KB5124008, includes all of its security content, and adds the corrected Remote Desktop components. Because it is cumulative, you do not need KB5124008 installed first; approving KB5129195 alone brings a machine to the same security level plus the fix.
Out-of-band updates are optional in Windows Update terms, which means a device on default settings will not pick up KB5129195 automatically until it is folded into the next monthly release. Managed environments must approve it explicitly.
Stage the rollout
Treat the pair as one change. A sensible sequence for a fleet:
- Pilot ring: a handful of machines including at least one RDS host or a workstation that connects through RD Gateway daily. Install KB5129195 directly.
- Broad ring: the rest of the estate after 3–5 days without incident.
- Servers: Windows Server 2025 receives its own September package; do not assume the Windows 11 KB numbers apply there.
In WSUS, decline KB5124008 once KB5129195 is approved, so machines do not install two reboots’ worth of updates. In Intune, use Windows Update rings with a deferral of a few days for the pilot group and set “Optional updates” so the out-of-band package is offered to those rings. RMM patch policies usually let you approve by KB number; approve KB5129195 and reject KB5124008.
Install and verify on a single machine
For a manual install or verification on one device, PowerShell and DISM give a definitive answer:
Get-HotFix -Id KB5129195, KB5124008
DISM /Online /Get-Packages | findstr /i "KB5129195 KB5124008"
winver
Get-ComputerInfo | Select-Object OsName, OsVersion, OsBuildNumber, OsHardwareAbstractionLayer
The build number reported by winver should match the value listed in the KB5129195 release notes for your branch. If Get-HotFix shows KB5124008 but not KB5129195 on a device that hosts RDP sessions, that device is still exposed to the regression.
To install offline from the Microsoft Update Catalog:
Add-WindowsPackage -Online -PackagePath "C:\Updates\windows11.0-kb5129195-x64.msu"
Watch for these side effects
The common pitfall is assuming that an out-of-band package is only for machines that already show the symptom. It is not; the regression can surface later as load changes, so every RDS host should receive it. Other things to watch this month:
- Devices that failed the cumulative update with 0x800f0922 or 0x80073712 usually have component store corruption; repair with DISM before retrying (see Repair Windows 11 with DISM and SFC).
- Machines under a compatibility hold will not be offered 26H1 regardless of the cumulative update state; see Windows 11 25H2 and 26H1 upgrade blockers.
- Third-party security agents that hook RDP (session recording, DLP) may need their own vendor update after KB5129195.
Keep it running
Record the build number your pilot ring reached and compare it against the fleet through your RMM or Intune’s “Windows update reports”. Any device still reporting the pre-September build a week after approval either has a stalled Windows Update client or is out of contact, and both deserve a ticket rather than a wait.
KB5124008 at a glance

Official documentation: Windows client documentation, Windows Server documentation.
Related guides: Offboarding an employee: checklist for Active Directory, Microsoft 365, Google Workspace and Zoho · Import ADMX templates (Office, Chrome, Edge) into Intune and the AD Central Store · Convert a physical Windows Server to a VMware VM (P2V) in 2026.
Frequently asked questions
Does KB5129195 replace KB5124008 or do I need both?
KB5129195 is cumulative and supersedes KB5124008, so a device that installs KB5129195 alone has all of September’s security fixes plus the Remote Desktop correction. Installing both simply costs an extra reboot.
How long does the September 2026 cumulative update take to install?
On modern SSD-based hardware expect 10–20 minutes including the reboot; older machines with a fragmented component store can take 30 minutes or more. Servers hosting many RDS sessions should be drained first because the reboot is mandatory.
Can I uninstall KB5124008 if it causes problems?
Yes, cumulative updates can be removed with wusa /uninstall /kb:5124008 or from Settings » Windows Update » Update history » Uninstall updates, but the better fix for the RDS regression is to install KB5129195 rather than roll back and lose the month’s security patches.
Maintenance record
This guide changes servers, data or security settings, so we re-check it against current versions on a fixed schedule. Take a backup or snapshot before you start.
- Maintained by
- srvScripts editorial team
- Supported versions
- Windows 11 25H2 and 26H1 (KB5124008 and KB5129195)
- Last full review
- Next review