Microsoft's September 2026 Patch Tuesday “fixed a massive 966 vulnerabilities” across its products, and the company has wrapped those fixes into the new Windows 10 extended security update KB5122878, released on September 8, 2026.
KB5122878: who gets it and how to install
The KB5122878 package is an extended security update aimed at Windows 10 customers who are still on long-term servicing and paid support tracks. If you are running Windows 10 Enterprise LTSC or are enrolled in the ESU program, you can install the update through the ordinary Windows Update flow by going into Settings, clicking on Windows Update, and manually performing a 'Check for Updates.' After installation, consumer-visible build numbers change: regular Windows 10 is updated to build 19045.7725, and Windows 10 Enterprise LTSC 2021 is updated to build 19044.7725.
Scope of the security work: 966 vulnerabilities and two active zero-days
Microsoft packaged the month's record-setting Patch Tuesday work into KB5122878. According to the company, the September 2026 Patch Tuesday “fixed a massive 966 vulnerabilities” across Microsoft products and included fixes for two vulnerabilities Microsoft described as “actively exploited zero-day flaws.” KB5122878 thus acts as the delivery vehicle for that month’s broad remediation effort for eligible Windows 10 systems.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleNotable technical fixes included in KB5122878
Microsoft describes KB5122878 as primarily security updates and bug fixes — the company explicitly notes it is no longer releasing new features for Windows 10. The update lists several targeted fixes and adjustments:
- Secure Boot: The update includes “additional high confidence device targeting data,” increasing the coverage of devices eligible to automatically receive new Secure Boot certificates. Microsoft says certificate deployment via Windows updates will continue across supported PCs and non-managed business devices in the coming months.
- Date and Time: The update adjusts Morocco Standard Time to reflect Morocco's transition to permanent UTC+00:00 effective September 20, 2026, so local clocks display correctly after the change.
- OMA DM protocol: Logging for the OMA DM Client (omadmclient.exe) has been improved; more debug information is saved when connecting to a server.
- Windows Code Integrity policies: Application compatibility is improved during Windows certificate-authority rotation by recognizing “Microsoft Windows Production PCA 2026 RSA2048-SHA256” as equivalent to PCA 2011.
- Remote Desktop: An issue affecting Remote Desktop audio redirection — where audio from the remote session might not play on the local computer under certain configurations — has been addressed.
- BitLocker Group Policy: The update addresses a known issue where “devices with an unrecommended BitLocker Group Policy configuration might be required to enter their BitLocker recovery key.”
Microsoft also notes there are no known issues with this update.
Blue Report 2026 context for defenders
The release arrives alongside a Microsoft reference to the Blue Report 2026. The company writes that “Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.” The Blue Report 2026, Microsoft says, measures defenses technique by technique across 338 million simulations run in customer production environments — framing KB5122878 as one part of a broader defensive posture tied to measurement and telemetry.
What this means for technologists, enterprises, and end users
- Technologists and security teams: Teams responsible for LTSC and ESU-managed fleets should prioritize rollout, since KB5122878 contains the month’s cumulative critical fixes and two actively exploited zero-day mitigations; certificate rotation and Secure Boot certificate deployment are notable items to watch during post-update validation.
- Enterprises and procurement leaders: Organizations that remain on LTSC or ESU tracks should factor build changes (19045.7725 / 19044.7725) into their inventory and update scheduling and confirm that BitLocker Group Policy and Remote Desktop behavior remain consistent with their operational requirements.
- End users: If you are on Enterprise LTSC or enrolled in ESU, use Settings → Windows Update → 'Check for Updates' to obtain the patch and expect the Morocco time-zone change to take effect for affected systems on September 20, 2026.
Microsoft’s KB5122878 packages a very large monthly vulnerability sweep for systems still on Windows 10 support lanes. For eligible devices, the practical steps are straightforward; the operational work will be in validating certificate and BitLocker behaviors and confirming that Secure Boot certificate deployment occurs as expected.




