Patch Tuesday updates

Winsage
September 15, 2026
Microsoft has released out-of-band updates for Windows 11 versions 26H1, 25H2, and 24H2 to address security vulnerabilities and improve system performance. The KB5129194 patch for version 26H1 fixes a critical elevation-of-privilege vulnerability (CVE-2026-62721) related to the Windows User-Mode Power Service (UMPS). The KB5129195 update for versions 25H2 and 24H2 also addresses a similar UMPS vulnerability and resolves a connection issue with Remote Desktop Services. Additionally, the updates fix problems with multichannel audio features on certain USB Audio Class 1.0 devices. These updates include enhancements from the September 2026 Patch Tuesday release, such as Taskbar customization, a faster Windows Search experience, and new Start Menu options. Users with unmanaged PCs will receive these updates automatically but can also check for updates manually.
Winsage
September 11, 2026
Microsoft has released new builds for Windows 11, versions 24H2 and 25H2, available for download from the Release Preview channel, specifically builds 26100.9539/26200.9539. The rollout is structured into two phases: a gradual rollout, which allows features to reach devices incrementally, and a normal rollout, which releases updates to all eligible devices simultaneously. Enhancements in this update include improvements to File Explorer, Wi-Fi support in the Windows Recovery Environment, support for Emoji 17.0, a new Tips widget, various personalization, Bluetooth, and accessibility improvements, and the ability to remap the Copilot key to Right Ctrl or Context Menu. The last updates for versions 24H2 and 25H2 were released in mid-August, and Microsoft introduced its first 26H2 build to the Release Preview channel two weeks ago. There is speculation about the potential release of Windows 11 version 26H2 in October, possibly coinciding with upcoming Patch Tuesday updates.
Winsage
September 10, 2026
Microsoft announced that the September 2026 Patch Tuesday updates resolved an issue affecting desktop settings on certain Windows devices, which caused desktop wallpapers to revert to a solid black background after the installation of the KB5120998 August 2026 preview update. This bug impacted Windows 11 24H2 and 25H2 systems, preventing the correct loading of desktop settings and also affecting mouse settings. Microsoft recommended users update their devices to the latest security update released on September 8, 2026 (KB5124008) to benefit from the fix.
Winsage
September 9, 2026
Recent investigations have identified the BlueMoon exploit kit, used by espionage-driven threat activity clusters, particularly linked to APT31, a China-aligned state-sponsored group, since August 28, 2026. BlueMoon exploits three vulnerabilities: CVE-2026-85046 (a type confusion vulnerability in Google Chrome's V8 engine), an unassigned V8 sandbox escape, and CVE-2026-85880 (a heap-based buffer overflow in Windows ALPC). Google and Microsoft have released patches for these vulnerabilities, which were exploited as "patch-gap" zero-days. The attack vectors typically begin with phishing emails that lead victims to malicious URLs, triggering the vulnerabilities for code execution and privilege escalation. Variants of BlueMoon have been detected, featuring modifications for specific campaigns. Notable attack chains include: - APT31 targeting NGOs and mining firms in the U.S. with a malicious browser add-on called GemStone. - UNK_LateNight targeting U.S. aerospace companies, deploying BlueMoon alongside the ShadowPad backdoor. - UNK_DoubleCheck targeting a Vietnamese manufacturer, using DLL sideloading to execute a Rust binary. - UNK_QuietRacket targeting government and financial organizations in Indonesia and Singapore, modifying BlueMoon to execute a .NET assembly. CISA added the Chrome flaw to its Known Exploited Vulnerabilities catalog on September 4, 2026, requiring federal agencies to apply patches by September 18, 2026. Indicators of compromise include specific process trees, files, folders, scheduled tasks, mutexes, and registry keys. Proofpoint has released detection rules to help organizations identify and mitigate these threats.
Winsage
September 9, 2026
The September 2026 security cycle revealed a bifurcated approach to vulnerability management by Microsoft, focusing on cloud-side identity services with silent mitigations and traditional Patch Tuesday updates for on-premises Windows infrastructure. On September 3, Microsoft addressed nine cloud-side vulnerabilities, including two with a CVSS score of 10.0: CVE-2026-83711 (Azure AD B2C elevation of privilege) and CVE-2026-70352 (Azure AI Language Authoring missing authentication). Additionally, CVE-2026-83941 (Entra ID elevation of privilege, rated 9.9) and CVE-2026-80098 (Copilot Studio cryptographic flaw) were noted. On September 8, the Patch Tuesday update addressed 70 CVEs, including critical issues in the on-premises stack, such as CVE-2026-83939 (Windows Secure Kernel Mode elevation of privilege). CVE-2026-69414 (ShieldBreak), an elevation of privilege vulnerability in the Defender Malware Protection Engine, was patched out-of-band on September 3 after being publicly exposed for three weeks. Microsoft is shifting its Self-Service Password Reset (SSPR) enforcement to default to passkeys as of September 7, with plans to phase out SMS and voice-based authentication by February 2027. This aims to enhance security by moving away from legacy credentials.
Winsage
September 8, 2026
Microsoft released its September 2026 Patch Tuesday updates for Windows 11, focusing on versions 26H1 and 25H2/24H2. Key features include: - Taskbar customization for versions 25H2 and 24H2, allowing users to choose the taskbar's location and size. - Faster Windows Search with options to hide web and Microsoft Store suggestions. - Touch scrolling support in the "Recommended" section of File Explorer. - Start Menu customization options for size and visibility of sections. - Stability improvements for Microsoft Teams and Outlook on Arm64 PCs. For version 26H1, updates include: - Improved app search and Settings relevance in Windows Search. - Voice Isolation technology in Voice Access. - Updated taskbar notification badges and Weather widget display on the Lock Screen. - New gesture controls for Precision Touchpads. - Enhanced Sign-in Security supporting peripheral fingerprint sensors. - Optimized Windows Update progression calculations and clean-up logic. - Power settings allowing users to set energy saver activation thresholds. Microsoft is using AI to identify vulnerabilities, with 997 Common Vulnerabilities and Exposures reported, including one actively exploited vulnerability (CVE-2026-81963). Windows 11 version 26H2 has been made available to Insiders, with a public rollout expected next month.
Winsage
August 31, 2026
Windows 11 users who installed the September preview update (KB5120998) are experiencing a bug that alters or erases personalized mouse cursor settings, resulting in cursors that may be too large, too small, or invisible. Microsoft has acknowledged this issue, describing it as causing "appearance regressions and intermittent animation changes." High-DPI cursors have been replaced with larger, white cursors, and attempts to revert to previous settings have failed. Additionally, users have reported issues with wallpapers reverting to a black screen and blurry fonts, although Microsoft has not formally acknowledged the font issue. Users can uninstall the update by navigating to Settings, selecting Windows Update, clicking on Update History, and finding the option to uninstall the update labeled 2026-08 Preview Update (KB5120998). Microsoft is investigating the cursor problem and plans to provide updates by September 8.
Winsage
August 27, 2026
Microsoft addressed printing issues and gaming-related complications linked to recent .NET Patch Tuesday updates. The problems were associated with RGB applications and the inpoutx64 system driver, which caused compatibility issues when certain games were launched. Microsoft has implemented a block to prevent the inpoutx64 driver from loading on affected devices, specifically targeting systems with the driver enabled and ARC Raiders installed. Users will receive a notification after the block is implemented, and the game should launch without further issues. The block is also being extended to systems running MARVEL Tōkon: Fighting Souls, while the issue with THE FINALS has been resolved. The resolution is being distributed automatically, and users need to restart their devices after the fix is applied. For enterprise-managed devices, IT administrators must manually apply the fix. Microsoft provided a temporary workaround by suggesting users disable the inpoutx64 driver through the Windows Registry. Users can change the Start value in the Registry Editor to 4 to disable the driver and may need to restart their devices for changes to take effect. Users are advised to back up the Registry before making modifications, and they can restore the driver by reverting the Start value back to its original setting.
Search