Microsoft's September 2026 Windows 11 update fixes 1,000 flaws and finally lets you move the taskbar

KB5124008 and KB5122880 ship a huge security backlog alongside a taskbar you can drag to any edge of the screen.

ThreatVectr Newsdesk· 4 min read
Photoreal news-editorial shot of a modern laptop on a clean desk showing a Windows-style update progress screen with a soft blue glow, wireless earbuds and a sm
Share

Key points

  • Microsoft released Windows 11 cumulative updates KB5124008 (for 25H2 and 24H2) and KB5122880 (for 23H2) on Patch Tuesday, September 2026.
  • The updates are mandatory and contain fixes for around 1,000 security vulnerabilities logged over previous months.
  • Users can now move the taskbar to the top, left, or right of the screen for the first time in Windows 11.
  • Windows Search gains a setting to hide Bing web results and Microsoft Store suggestions.
  • Administrator Protection, a feature that hands out admin rights only when needed, begins rolling out but stays off by default.

Microsoft has pushed out its September 2026 Patch Tuesday updates for Windows 11, and the headline number is a big one. Around 1,000 security vulnerabilities are addressed in this single release, a backlog Microsoft says covers flaws found in previous months.

The updates are KB5124008 for Windows 11 versions 25H2 and 24H2, and KB5122880 for version 23H2. They install automatically through Windows Update, or you can trigger them by opening Settings, then Windows Update, and clicking Check for Updates.

Because 25H2 is built on the same code as 24H2, both versions get an identical package. There is no separate 25H2-only feature drop this month.

What actually got fixed?

Microsoft says the release addresses roughly 1,000 vulnerabilities, which is a security patch, meaning a software fix that closes holes attackers could use to break into your PC. The company has not, at the time of writing, flagged any of them as being actively used by criminals, and it says it is not aware of new problems introduced by this month's update.

In practice, that number is less scary than it sounds. Patch Tuesday bundles months of quietly reported bugs into one shipment, and most home users will never notice. The failure mode here is skipping the reboot for weeks, because unpatched Windows machines are still one of the easiest ways for attackers to get a foothold on a network.

What's new for everyday users?

Quite a lot, actually. The taskbar, the strip of icons at the bottom of the screen, can finally be moved. You can dock it to the top, left, or right by going to Settings, Personalization, Taskbar, Taskbar behaviors, Taskbar position. Long-time Windows 7 users have been asking for this since 2021.

There is also a new small taskbar mode for laptops with less screen space, which shrinks the icons and the bar itself.

The Start menu gets choices too. You can pick a small or large layout, hide your name and profile picture, and toggle the Pinned, Recommended, and All sections independently. The Recommended row has been renamed Recent, which is a more honest label for what it actually shows.

Windows Search picked up a setting that a lot of people will quietly cheer for. Under Settings, Privacy and Security, Search, you can now stop web results and Microsoft Store suggestions from cluttering local file searches. Search results also now label where each hit came from: an app, a setting, a file, the web, or the Store.

Is there anything security teams should care about?

Yes. Administrator Protection is beginning to roll out, though it is off by default. First disclosed in October 2025 as part of KB5067036, the feature stops administrator accounts from carrying full admin rights all the time. Instead, the user is granted admin power just-in-time when a task needs it, using a separate profile.

Microsoft is careful to say this is not a formal security boundary. It is a hardening measure against elevation-of-privilege attacks, where malware running as a normal user tries to gain admin rights. IT admins can enable it through Microsoft Intune or Group Policy.

Also new is Process Isolation for Microsoft Execution Containers, a lightweight sandbox aimed at code produced by AI coding agents. It restricts what that code can touch: files, networking, the user interface. Given how many developers are now running model-generated scripts on their work machines, that boundary matters.

BleepingComputer notes this is the ninth Patch Tuesday of 2026.

Operational takeaway: patch, reboot, and if you run a fleet, start piloting Administrator Protection now rather than waiting for the default to flip.

© 2026 Threat Vectr