Microsoft has confirmed three known issues affecting Windows 11 26H2, which shares its servicing branch with 25H2 and 24H2. A September update can break USB Audio Class 1.0 devices, removing audio input and output and potentially freezing or crashing Sound settings. Enterprise devices using Active Directory and Credential Guard can also fail to sign in when Machine Identity Isolation causes machine accounts to lose their secure channel.
A separate desktop-loading issue, first linked to the August non-security preview update KB5120998, can leave some users at a black screen after sign-in because the desktop session does not automatically load. The issue particularly affects Azure Virtual Desktop hosts using FSLogix profiles and may generate Windows Explorer crashes in the Application event log; Windows Server is not affected. Microsoft has provided Known Issue Rollback Group Policy packages for affected enterprise versions, while users can manually start explorer.exe through Task Manager; it has marked this issue mitigated and is developing a permanent update.

See real exploitation activity before you spend the cycle.
5 events from the most recent confirmed update back to the earliest known activity.
Microsoft opened a known issue for black screens and desktop-loading failures after sign-in on affected Windows 11 systems. It documented Windows Explorer crashes as a possible symptom and stated that Windows Server editions are unaffected.
A September 2026 Windows update introduced an issue that can prevent USB Audio Class 1.0 devices from starting or producing audio on Windows 11 24H2 and 25H2, with 26H2 also affected due to the shared servicing branch. Sound settings may become unresponsive or crash while affected users troubleshoot the issue.
The August 2026 non-security preview update KB5120998 introduced an issue that can leave some Windows 11 devices at a black screen after sign-in because the desktop session does not load. It affects versions 24H2, 25H2, and 26H1, particularly Azure Virtual Desktop hosts using FSLogix profiles.
Microsoft identified an issue in which Windows 11 systems using Credential Guard-protected machine accounts can lose their Active Directory secure channel when Machine Identity Isolation enforcement settings are honored. The resulting secure-channel loss can prevent domain users from signing in despite valid credentials.
Microsoft marked the Windows 11 desktop-loading issue as mitigated and released version-specific Known Issue Rollback Group Policy packages for enterprise administrators. Affected users can also manually start explorer.exe through Task Manager while Microsoft develops a permanent fix.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.