Microsoft confirmed that Windows 11 preview and cumulative updates can leave some users at a black screen after sign-in because the Windows Explorer desktop shell fails to start. The regression predominantly affects Azure Virtual Desktop hosts using FSLogix profile containers, particularly for certain existing user profiles, following the August 27 non-security preview release and later updates.
Affected releases include Windows 11 26H1 through KB5120996 (OS Build 28000.2804) and Windows 11 25H2/24H2 through KB5120998. Microsoft has deployed Known Issue Rollback mitigations for enterprise-managed devices and advised users to manually start explorer.exe as a temporary workaround; a permanent fix is in development.

See real exploitation activity before you spend the cycle.
3 events from the most recent confirmed update back to the earliest known activity.
Microsoft identified the September 2026 Patch Tuesday updates KB5124008 and KB5122880 as also being associated with the Windows desktop-loading issue.
The August 27, 2026 non-security preview updates, including KB5120996 for Windows 11 26H1 and KB5120998 for 24H2/25H2, introduced a regression that can prevent Windows Explorer from launching after sign-in. The issue was observed primarily on Azure Virtual Desktop hosts using FSLogix and can leave users at a black screen.
Microsoft confirmed the black-screen and Explorer-crash issue, advised users to manually launch explorer.exe as a temporary workaround, and marked the incident mitigated. It released Known Issue Rollback Group Policies KB5124006 for Windows 11 26H1 and KB5124010 for 24H2/25H2 while developing a permanent update.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.