Windows 11 Update KB5124010 Triggers Crashes in Battlefield 6 and Other Titles
An optional Windows 11 update identified as KB5124010 is creating serious disruptions for gamers, particularly those playing Battlefield 6 and Battlefield 2042. The patch, released in early September, was first offered to participants in the Windows Insider program for versions 24H2 and 25H2 before being distributed more widely as a non-security update.
Users on Reddit and Steam report that affected games close abruptly after 15-30 seconds or within a few minutes of starting, often without displaying any error code. Standard troubleshooting steps such as reinstalling the game, verifying DirectX installations, and attempting to repair anti-cheat components have not resolved the crashes.
Removing KB5124010 has restored normal operation in numerous reported cases, pointing to a likely conflict between the update and anti-cheat systems. Battlefield 6 and Battlefield 2042 rely on Electronic Arts' Javelin anti-cheat, while similar issues have appeared in titles protected by Easy Anti-Cheat, including Wardogs which displays error code WD-L020-95bc94d86a0d.
The problems occur across varied hardware setups, making it difficult to attribute them to specific graphics cards or processors. Microsoft has not yet confirmed any connection to anti-cheat software, and all conclusions are based on user reports. Because the update is optional, players are recommended to avoid installing it until a resolution is available.
Related articles
Critical Microsoft SharePoint Vulnerability Allows Remote Code Execution via SafeControls Bypass
A vulnerability tracked as CVE-2026-65660 with a CVSS score of 8.8 affects Microsoft SharePoint Server 2016, SharePoint Server 2019, and Subscription Edition. The flaw permits an authenticated low-privileged attacker to achieve arbitrary code execution on on-premises servers. It stems from improper handling of quotes in attacker-controlled Register directives within the ToolPane component, bypassing the SafeControls mechanism. This allows registration of dangerous .NET classes followed by deserialization-based remote code execution. Microsoft released patches on August 11, 2026, and initially reported no public disclosure or exploitation. Publication of a detailed technical analysis has now increased the risk for unpatched installations.
Google Chrome Prepares Deferred Restart Feature to Apply Security Updates Without Disruption
Google is developing a queued restart capability for Chrome that lets the browser install updates after detecting user inactivity instead of forcing an immediate closure. The feature, tracked under the queued-restarts theme in Chromium code, offers users the choice to restart right away or wait for roughly five minutes of idle time. Chrome will automatically skip the restart if the browser is downloading files, playing audio or video, recording the screen, or using the camera. Notifications and a menu indicator labeled Scheduled Restart will inform users of the planned update, while additional reminders may appear when opening new tabs. The implementation currently lacks the ability to select a precise restart time like Windows Update and remains limited to the absence of activity. Google has previously committed to reducing the annoyance of mandatory browser restarts for security patches, though the feature has not yet reached the stable channel.
WordPress Issues Critical Security Update 7.1.2 Five Days After Previous Patch
WordPress has released version 7.1.2 to fix a new critical vulnerability that was not addressed in the 7.1.1 update issued just five days earlier. The flaw, tracked as CVE-2026-87902, is a path traversal issue rated Critical that can be exploited without authentication. It resides in the page template resolution process and allows execution of arbitrary local PHP files located outside the theme directory, provided certain conditions such as the presence of a page- prefixed directory in the parent or child theme are met. The update was published on September 22, 2026, and affects the prior release from September 17. Administrators are urged to apply the patch immediately to prevent potential remote code execution.
F5 BIG-IP APM Vulnerability CVE-2026-94127 Allows Remote Code Execution, Already Exploited in the Wild
F5 has disclosed a critical heap-based buffer overflow vulnerability in BIG-IP Access Policy Manager that is already being actively exploited. The flaw, tracked as CVE-2026-94127, affects systems configured as an OAuth authorization server with both an access policy and OAuth profile applied to a virtual server. Successful exploitation can result in arbitrary code execution from crafted network traffic. The issue also impacts appliance mode configurations. F5 rates the vulnerability 9.3 under CVSS v4.0 and 9.8 under CVSS v3.1, classifying it as Critical. The company discovered the flaw internally and has confirmed real-world exploitation, urging immediate patching and compromise assessment.