Microsoft has pushed out KB5124010, the September 2026 optional preview update for Windows 11 24H2 and 25H2. It contains 46 changes, including Bluetooth fixes, a way to remap the Copilot key, and support for Emoji 17.0.
The release is a non-security update. Monthly preview updates like this one give administrators and users an early look at fixes and features that will reach all devices with next month's Patch Tuesday, the regular monthly release of Windows security and quality updates. Unlike the cumulative updates shipped on Patch Tuesday, previews such as KB5124010 contain only quality improvements. They do not patch security vulnerabilities.
Microsoft has confirmed that recent Windows 11 updates are stopping the desktop from loading on some systems. Affected users see a black screen after signing in.
The problem started with the August 2026 preview updates and carried into later releases, including this month's Patch Tuesday rollout. According to Microsoft, it mainly hits Azure Virtual Desktop (AVD) hosts that use FSLogix. AVD is Microsoft's cloud-based desktop and app virtualization service. FSLogix is a tool that speeds up the loading of user profiles in virtual desktop environments.
Which updates are involved
Microsoft lists the following updates as linked to the issue:
Attackers have moved beyond scanning for WordPress sites vulnerable to CVE-2026-87902. They are now exploiting the flaw to plant files that run shell commands when they are accessed, according to WordPress security firm Patchstack.
The vulnerability was fixed in WordPress 7.1.2. Scanning began less than five hours after that release. Since then, malicious traffic has grown tenfold, and attackers are now trying to deliver payloads.
Patchstack says it saw the first malicious requests at 17:44 UTC on September 22. They came from a small group of IP addresses and targeted several sites under the company's protection.
Check Point has confirmed that attackers are exploiting CVE-2026-85102, a remote code execution (RCE) vulnerability in its Security Gateway product. The flaw sits in the code that handles VPN certificates, and it can be abused without authentication.
The same advisory covers a second exploited bug, CVE-2026-93616. It is a pre-authentication path traversal flaw in the Management web service that can lead to script execution and Java class loading. According to Check Point, attackers have used it as a zero-day since July 23.
Warning from the Netherlands came first
The Security Gateway issue was already on defenders' radar. On September 10, the Nationaal Cyber Security Centrum (NCSC), the Dutch government's national cybersecurity agency, warned about the flaw. It told users to install the available security updates because it expected exploitation soon.
A critical authentication bypass in JetBrains TeamCity is now being abused by ransomware operators, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). The agency flagged the change on Wednesday, two months after JetBrains released a fix.
The vulnerability, tracked as CVE-2026-63077, affects TeamCity On-Premises. JetBrains patched it on July 25 in versions 2025.11.7 and 2026.1.3. Attackers who can reach a server over HTTP(S) can use it to run arbitrary operating system commands.
How the flaw works
TeamCity is a Continuous Integration and Continuous Deployment (CI/CD) platform. Developers and DevOps teams use it to automate how software code is built, tested and deployed. That role makes a compromised server valuable to attackers.
Guy Fawkes News is financed by advertising. You can choose how you want to use this website:
With advertising: we load an advertising script from a third-party ad network. The ad network may set cookies, use your IP address and device information, and may process data outside the EU. We also count your visits for our own visitor statistics (with a random ID stored in your browser).
Ad-free for €0.99 per month: no advertising and no advertising tracking. Cancel at any time.
You can change your decision at any time via "Cookie Settings" at the bottom of every page.