KB5121003: what it fixes and who gets it

KB5121003 is a security update from Microsoft's August 2026 release for Windows 11 Version 24H2, Windows 11 Version 25H2.

Microsoft data read
194CVEs fixed
7rated Critical
1already exploited
Yesrestart required

Should you install it?

Yes, and soon: it closes a hole that was already being used in real attacks before the fix was released. Windows Update installs it automatically on supported home PCs.

If the installation fails or the PC misbehaves afterwards, note the exact error code first: the fix depends on it. We have a guide for this update below.

Known issues after KB5121003

ResolvedWindows 11 26H1, Windows 11 25H2, Windows 11 24H2fixed by KB5124012updated Sep 8, 2026

This most likely occurs on new PCs after installing the August Windows security update and does not affect other apps.

From Microsoft's Windows release health pages, read hourly. Titles and summaries are Microsoft's.

Security fixes in KB5121003

CVETypeCVSSSeverity
CVE-2026-68820Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityElevation of Privilege7.0ExploitedImportant
CVE-2026-62815Microsoft QUIC Remote Code Execution VulnerabilityRemote Code Execution9.8Critical
CVE-2026-62816Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution VulnerabilityRemote Code Execution8.8Critical
CVE-2026-62822Windows GDI+ Remote Code Execution VulnerabilityRemote Code Execution8.8Critical
CVE-2026-62819Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityRemote Code Execution8.1Critical
CVE-2026-62889Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution VulnerabilityRemote Code Execution8.1Critical
CVE-2026-62890Windows GDI+ Elevation of Privilege VulnerabilityRemote Code Execution7.8Critical
CVE-2026-66799Windows Key Guard Elevation of Privilege VulnerabilityElevation of Privilege7.8Critical
CVE-2026-49179Windows Active Directory Domain Services Remote Code Execution VulnerabilityRemote Code Execution8.8Important
CVE-2026-62784Microsoft Local Security Authority Server (lsasrv) Remote Code Execution VulnerabilityRemote Code Execution8.8Important
CVE-2026-62785Windows LDAP - Lightweight Directory Access Protocol Remote Code Execution VulnerabilityRemote Code Execution8.8Important
CVE-2026-62790Windows SMBv3 Server Remote Code Execution VulnerabilityRemote Code Execution8.8Important
CVE-2026-62795Windows LDAP - Lightweight Directory Access Protocol Remote Code Execution VulnerabilityRemote Code Execution8.8Important
CVE-2026-62800Windows SMBv3 Server Remote Code Execution VulnerabilityRemote Code Execution8.8Important
CVE-2026-62781RPC Runtime Library Remote Code Execution VulnerabilityRemote Code Execution8.1Important
CVE-2026-62792Windows TCP/IP Remote Code Execution VulnerabilityRemote Code Execution8.1Important
CVE-2026-6726MITRE: CVE-2026-6726 TPM 2.0 Improper Object Slot ReuseSpoofing7.9Important
CVE-2026-42976Remote Access Management service/API (RPC server) Elevation of Privilege VulnerabilityElevation of Privilege7.8Important
CVE-2026-54984Windows Imaging Component Remote Code Execution VulnerabilityRemote Code Execution7.8Important
CVE-2026-59127Windows Installer Elevation of Privilege VulnerabilityElevation of Privilege7.8Important
CVE-2026-61349Windows Work Folder Service Elevation of Privilege VulnerabilityElevation of Privilege7.8Important
CVE-2026-61353Windows Telephony Service Elevation of Privilege VulnerabilityElevation of Privilege7.8Important
CVE-2026-61355Windows Sensor Data Service Elevation of Privilege VulnerabilityElevation of Privilege7.8Important
CVE-2026-61356Windows Remote Desktop Services Elevation of Privilege VulnerabilityElevation of Privilege7.8Important
CVE-2026-61357Application Information Services Elevation of Privilege VulnerabilityElevation of Privilege7.8Important
CVE-2026-61358Windows Accessibility Infrastructure (ATBroker.exe) Elevation of Privilege VulnerabilityElevation of Privilege7.8Important
CVE-2026-61359Windows Storage Elevation of Privilege VulnerabilityElevation of Privilege7.8Important
CVE-2026-61364Windows Remote Desktop Services Elevation of Privilege VulnerabilityElevation of Privilege7.8Important
CVE-2026-61365Windows Remote Desktop Services Elevation of Privilege VulnerabilityElevation of Privilege7.8Important
CVE-2026-61367Windows Remote Desktop Services Elevation of Privilege VulnerabilityElevation of Privilege7.8Important
CVE-2026-61923Windows Display Enhancement Service Elevation of Privilege VulnerabilityElevation of Privilege7.8Important
CVE-2026-61925Windows Installer Elevation of Privilege VulnerabilityElevation of Privilege7.8Important
CVE-2026-61926Windows USB Driver Elevation of Privilege VulnerabilityElevation of Privilege7.8Important
CVE-2026-61930Windows Kernel Elevation of Privilege VulnerabilityElevation of Privilege7.8Important
CVE-2026-61934Windows Bind Filter Driver Elevation of Privilege VulnerabilityElevation of Privilege7.8Important
CVE-2026-61937Windows HTTP.sys Elevation of Privilege VulnerabilityElevation of Privilege7.8Important
CVE-2026-62688Windows MIDI Service Module Elevation of Privileges VulnerabilityElevation of Privilege7.8Important
CVE-2026-62692Windows Remote Desktop Services Elevation of Privilege VulnerabilityElevation of Privilege7.8Important
CVE-2026-62695Windows Storage Elevation of Privilege VulnerabilityElevation of Privilege7.8Important
CVE-2026-62696Windows Program Compatibility Assistant Service Elevation of Privilege VulnerabilityElevation of Privilege7.8Important
CVE-2026-62698Microsoft Digest Authentication Elevation of Privilege VulnerabilityElevation of Privilege7.8Important
CVE-2026-62700Windows NTFS Elevation of Privilege VulnerabilityElevation of Privilege7.8Important
CVE-2026-62701Windows Telephony Service Elevation of Privilege VulnerabilityElevation of Privilege7.8Important
CVE-2026-62707Windows Modern Device Management (MDM) Elevation of Privilege VulnerabilityElevation of Privilege7.8Important
CVE-2026-62710Windows Device Association Service Elevation of Privilege VulnerabilityElevation of Privilege7.8Important
CVE-2026-62711Windows Win32k Elevation of Privilege VulnerabilityElevation of Privilege7.8Important
CVE-2026-62712Windows Win32k Elevation of Privilege VulnerabilityElevation of Privilege7.8Important
CVE-2026-62713Windows Cloud Files Mini Filter Driver Elevation of Privilege VulnerabilityElevation of Privilege7.8Important
CVE-2026-62717Windows Message Queuing Elevation of Privilege VulnerabilityElevation of Privilege7.8Important
CVE-2026-62719Windows Message Queuing Elevation of Privilege VulnerabilityElevation of Privilege7.8Important
CVE-2026-62722Microsoft Brokering File System Elevation of Privilege VulnerabilityElevation of Privilege7.8Important
CVE-2026-62732Windows Telephony Service Elevation of Privilege VulnerabilityElevation of Privilege7.8Important
CVE-2026-62733Windows Win32k Elevation of Privilege VulnerabilityElevation of Privilege7.8Important
CVE-2026-62735Windows HTTP.sys Elevation of Privilege VulnerabilityElevation of Privilege7.8Important
CVE-2026-62736Windows DHCP Client Elevation of Privilege VulnerabilityElevation of Privilege7.8Important
CVE-2026-62737Windows Kernel Elevation of Privilege VulnerabilityElevation of Privilege7.8Important
CVE-2026-62739Windows HTTP.sys Elevation of Privilege VulnerabilityElevation of Privilege7.8Important
CVE-2026-62741Windows HTTP.sys Elevation of Privilege VulnerabilityElevation of Privilege7.8Important
CVE-2026-62747Windows Device Association Service Elevation of Privilege VulnerabilityElevation of Privilege7.8Important
CVE-2026-62751Windows Projected File System Elevation of Privilege VulnerabilityElevation of Privilege7.8Important
Showing the 60 most severe of 194. The full list is in Microsoft's Security Update Guide.

Questions and experiences

Ask about this page: members and our editors answer. Reading is open; writing needs a free account.

0 comments

…

4,322 members already hereThey read, write, comment and vote. 0 verified · 31 joined this year

Cookies

We use essential cookies to run the platform. Analytics and marketing cookies are only turned on once you consent — you can change your choice at any time.