Microsoft’s September Windows security update has created an awkward problem for PC users: the same patch that closes a record number of security holes is now confirmed to be breaking several Windows features on some systems.
Microsoft has acknowledged problems linked to the September 8, 2026 update KB5124008, including USB audio devices that can stop producing sound, Remote Desktop Services instability and host-folder sharing failures in some Hyper-V-based Linux environments. That last issue can affect Windows Subsystem for Linux (WSL) and Anthropic’s Claude Cowork.
The timing makes this more complicated than the usual buggy Windows update. As The Tech Boom reported when September Patch Tuesday landed, Microsoft’s September security release addressed 966 vulnerabilities by BleepingComputer’s count, including two zero-days already being exploited. Simply telling everyone to avoid the update is therefore not a sensible answer.
What is going wrong with KB5124008?
Microsoft’s Windows release-health documentation now lists multiple September issues associated with KB5124008. The most immediately noticeable for ordinary PC users is a problem affecting some USB Audio Class 1.0 devices.
Microsoft says affected devices may fail to start, show a Code 10 error in Device Manager or produce no sound at all. Volume controls and sound settings can also become unresponsive. In some cases, standard stereo output still works while multichannel modes such as 8-channel or 3D audio fail.
That distinction matters: this is not Microsoft saying that KB5124008 breaks audio on every Windows 11 PC. The confirmed issue is limited to certain USB Audio Class 1.0 hardware. Microsoft says it is working on a resolution.
Remote Desktop is another confirmed problem
Businesses and IT administrators have a second concern. Microsoft says some organisations may experience instability with Remote Desktop Services after installing the September security update.
Symptoms can include RDP connections failing after several minutes, sign-in problems and systems hanging at the message “Please wait for the Remote Desktop Configuration.” Microsoft also says related tools such as Microsoft Management Console, RDS Licensing Diagnoser and File Explorer can become unresponsive in affected environments.
The company has published a temporary mitigation for some virtual machines: stopping, or deallocating, the affected VM and then restarting it may temporarily restore RDP connectivity. A permanent resolution is still being developed.
WSL and Claude Cowork can lose access to shared folders
The third confirmed problem is more technical but increasingly relevant as Windows becomes a home for local development and AI tools.
After KB5124008, applications using Host Compute Service-managed virtual machines can run into problems when sharing Windows host folders with Linux virtual machines through Plan9. The virtual machine itself may start normally, but the shared Windows folders may disappear or become inaccessible from the Linux environment.
Microsoft specifically identifies WSL and Claude Cowork as two applications affected by the issue. Standard Hyper-V virtual machines that do not use Plan9 folder sharing are not affected.
That makes this more than an obscure enterprise regression. AI desktop applications are increasingly using virtualised or sandboxed environments to work with local files, and a Windows servicing change can now disrupt those workflows even when the application itself has not changed.
There are also reports of Always On VPN failures
Administrators have separately reported certificate-based Always On VPN connections failing after KB5124008 on some Windows 11 24H2 and 25H2 systems. Reports indicate that removing the update restores connectivity in affected environments.
However, this deserves a different label from the issues above. Microsoft has not yet publicly confirmed the Always On VPN regression or its root cause, so it should be treated as an emerging administrator-reported problem rather than an established KB5124008 bug.
Should you uninstall the September Windows update?
For most home users, not automatically.
September’s Patch Tuesday was unusually important. It fixed hundreds of vulnerabilities across Microsoft’s products, including actively exploited flaws. Removing the security update to solve a problem that does not affect your PC would trade a theoretical stability concern for a real security exposure.
If your PC is working normally after KB5124008, there is little reason to uninstall it pre-emptively. If you are affected by one of Microsoft’s confirmed issues, check the company’s Windows release-health page for the latest workaround or resolution before deciding what to do. Managed business environments should follow their organisation’s IT guidance rather than removing the patch independently.
For organisations, the situation is harder. Remote Desktop, Linux-based development environments and Always On VPN can be operationally critical. IT teams may need to test updates on a smaller group of machines before broad deployment while still moving quickly enough to address the vulnerabilities September’s update fixes.
The security-versus-stability problem is the real story
Windows updates have broken features before. What makes KB5124008 notable is the tension surrounding this particular release.
Microsoft’s September Patch Tuesday was one of the largest security clean-ups the company has shipped, arriving as attackers increasingly use automation and AI to move faster. Yet within days, Microsoft was documenting regressions in audio, Remote Desktop and virtualised Linux workflows.
That leaves users with an uncomfortable but increasingly familiar reality: installing security updates quickly is essential, but large updates can also introduce new problems of their own.
The best response is not to panic or blindly uninstall KB5124008. It is to know which problems Microsoft has actually confirmed, distinguish them from early reports, and watch for fixes as the company updates its release-health documentation.
Sources: Microsoft Windows release health; Microsoft KB5124008 documentation; BleepingComputer’s September 2026 Patch Tuesday reporting.
Featured image: Dell/Unsplash. Illustrative image.




