security fixes

Winsage
September 18, 2026
Microsoft acknowledged a bug affecting Excel's copy and paste functionality that emerged after the September Patch Tuesday update. They have released an out-of-band update to resolve various issues, including the Excel bug. Instructions for users to navigate the issue include using the Paste Special feature and selecting options like Formulas, Values, or Links. Microsoft is investigating the root cause of the issue and plans to implement broader fixes. Additionally, Windows 11 is being refreshed to streamline the update process and reduce bugs.
AppWizard
September 18, 2026
Google's September 2026 Pixel Update Bulletin includes patches that affect standard Android platform code, relevant to both Pixel and non-Pixel devices, which have not been included in the regular monthly Android Security Bulletin. GrapheneOS has noted that Android 17 QPR1 introduced new developer APIs not present in the Android Open Source Project (AOSP) for the first time since Android Honeycomb, with one new package and modifications to sixteen others. GrapheneOS is backporting Pixel firmware and drivers from QPR1 onto Android 17 but lacks permissions to distribute this work. Additionally, there has been a delay in Google’s compliance with a GPL source request, with access granted over two weeks after the initial request. Starting in 2027, Google will require all Android app developers to register with them and provide legal identification and signing key evidence, complicating the process of sideloading unverified apps. GrapheneOS and other organizations are advocating for the Keep Android Open campaign against these developments, which may restrict competition and tighten Google's control over the Android ecosystem.
AppWizard
September 18, 2026
Google has launched the AndroidX Security State and Security State Provider libraries, enhancing Android's security framework. These tools allow applications to assess the security status of individual components on a device, rather than relying solely on the overall security patch level. Applications can now verify specific security fixes, identify available updates, and check for pending installations. This is particularly useful for security-sensitive applications, such as banking software, which can confirm the presence of necessary security fixes before allowing transactions. The libraries also enable apps to check for the resolution of specific vulnerabilities (CVEs), ensuring critical fixes are in place before enabling features like tap-to-pay. Phone manufacturers can communicate specific security fixes without changing the overall security patch date, meaning a device may show an outdated patch date while still having resolved certain vulnerabilities.
AppWizard
September 18, 2026
The new AndroidX Security State libraries, with stable releases of Security State v1.1.0 and Security State Provider v1.0.0, allow developers to evaluate the security status of individual device components. They provide three levels of security patch information: Device Security Patch Level (DSPL), Published Security Patch Level (PSPL), and Available Security Patch Level (ASPL). These libraries enable checks on critical components of the Android operating system, including system modules and the Linux kernel, which are represented by version numbers rather than monthly patch dates. Applications that prioritize security can utilize this detailed patch information to assess vulnerabilities, particularly those tracked as Common Vulnerabilities and Exposures (CVEs). The libraries also integrate with the Open Source Vulnerabilities (OSV) database for access to Android Security Bulletin data and device-specific vulnerability reports. Additionally, Android 17 allows manufacturers to declare individual security fixes beyond the stated security patch level, and Google is working with manufacturers to transition their OTA update clients to this new standardized system.
Winsage
September 15, 2026
Microsoft announced on September 14 that the Windows 11 24H2 edition, including Home and Pro versions, has only 30 days of support remaining, with a deadline for updates set for October 13, 2026. Users are encouraged to upgrade to version 25H2 or later to continue receiving security updates. The Enterprise and Education editions will have support until October 12, 2027. Users have reported issues from September's security updates, particularly with the Office patch KB5002914, which disrupts the copy-and-paste function in Excel across multiple versions. Microsoft has acknowledged the issue but has not yet released a fix. A temporary workaround involves manually removing the problematic patch, though this also removes the associated security fixes. Additionally, users have experienced connection drops and unresponsiveness in Remote Desktop Services (RDS) across various Windows versions, including Windows 11 26H1 and Windows Server 2012. Microsoft confirmed that related tools may also stop responding, and restarting virtual machines may temporarily restore functionality. USB audio issues have been reported on certain USB Audio Class 1.0 devices across Windows 11 versions, with users experiencing loss of audio output and corrupted sound settings. Switching to 2-channel mode has helped some users, but Microsoft has not provided a timeline for a comprehensive fix. As Windows Server 2012 nears the end of its Extended Security Updates period on October 13, 2026, the RDS issues add pressure on administrators. Users on 24H2 need to prioritize migration to 25H2, while those with the latest updates should be cautious regarding Excel and Remote Desktop functionalities.
Winsage
September 15, 2026
Microsoft is facing challenges in September due to bugs in Windows 11, particularly affecting Excel's copy and paste functionality after a recent OS update. Users of Excel 2024, 2021, 2019, and 2016 may experience silent failures when attempting to paste content, with no error messages provided. Microsoft is investigating this issue. Following the September Patch Tuesday update, which included nearly 1,000 security fixes, users are advised to install the update but may consider delaying it due to existing bugs. Additionally, Microsoft has launched the Windows K2 initiative to improve the Windows 11 experience by streamlining the update process, although users have still encountered multiple updates in September.
Winsage
September 14, 2026
Microsoft's recent security updates have caused disruptions in several areas: 1. Remote Desktop Services (RDS): Users on Windows 11 26H1 and Windows Server 2012 are experiencing connectivity issues, including failed connections, freezing servers, and unresponsive tools like Microsoft Management Console (MMC). A temporary solution involves restarting the virtual machine, and Microsoft is working on a fix. 2. USB Audio Devices: Problems have been reported with USB Audio Class 1.0 devices on Windows 11 26H1, 25H2, and 24H2, leading to audio issues. A workaround includes switching to two-channel mode, and Microsoft is addressing the situation. 3. Excel Functionality: A fix for vulnerabilities in Excel has disrupted the paste operation across versions 2016, 2019, 2021, and 2024, leaving users unable to paste content correctly. Some users have resolved the issue by uninstalling and reinstalling Office or using commands to remove the security update, though this also removes the associated security fixes.
Search