Windows & Microsoft AI News: Entra & Rubin (Aug 23)

- Insider Wave Adds AutoPlay Redesign and Accessibility
- Entra ID CVSS 10.0 Warning Corrected: Not Exploited
- First NVIDIA Vera Rubin Systems Arrive at Microsoft
- Hidden Unified Memory Control for Copilot+ PCs
- Server 2019 VMs Blue-Screen After KB5120238
- Edge 151.0.4129.101 Fixes Twelve High-Severity CVEs
- What This Means for Windows Users and IT Teams
- • Entra ID correction: Microsoft revised the CVE-2026-69836 advisory on August 21-22 to confirm the CVSS 10.0 Entra ID flaw was not exploited in the wild; the service is fully mitigated and no customer action is required (THG, Aug 22, 2026).
- • Insider wave: Beta 26H2 build 26220.9223, Experimental 26H2 build 26340.9233, and Experimental 26H1 build 28120.2760 add an Open apps maximized accessibility setting and a WinUI-rebuilt AutoPlay dialog (Microsoft Learn, Aug 21, 2026).
- • Vera Rubin milestone: Nadella confirmed on August 21 that Microsoft received its first NVIDIA Vera Rubin production systems; inference is rated up to 5x versus Blackwell (CryptoBriefing, Aug 22, 2026).
- • Unified memory: A hidden control in Experimental build 29648.1000 lets Copilot+ PC users tune how much shared memory is reserved for AI and graphics, via feature ID 61121285 (Pureinfotech, Aug 20, 2026).
- • Server BSOD: Windows Server 2019 guests on Server 2022 Hyper-V can hit a CRITICAL_SERVICE_FAILED boot loop after KB5120238; offline DISM removal plus WSUS exclusion is the current workaround (Microsoft Learn Q&A, Aug 19, 2026).
- • Edge 12 CVE: Edge 151.0.4129.101 fixes twelve high-severity flaws (76033-76045, 76047) including remote code execution; update now (CERT-FR, Aug 20-21, 2026).
01Insider Wave Adds AutoPlay Redesign and Accessibility
Microsoft released a three-build Insider wave on August 21 that adds an Open apps maximized accessibility setting and a rebuilt, dark-mode-capable AutoPlay dialog. The Beta channel received Windows 11 26H2 build 26220.9223, while the Experimental channel received 26H2 build 26340.9233 and 26H1 build 28120.2760, according to the release notes on Microsoft Learn and IT Home’s summary on August 22.

The headline setting, Open apps maximized, lives under Settings, Accessibility, Visual effects. When enabled, desktop applications open in a maximized window, which removes an extra resize step for users with low vision or motor impairments. The second visible change is the AutoPlay dialog: Microsoft rebuilt it with WinUI so it follows the system’s dark mode and stays available from the notification center instead of disappearing after a single interaction.
The Beta build also improves the Store experience for elevated WinUI 3 apps, which matters for tools that run with administrator rights and previously struggled with in-app purchases. For most readers, the practical takeaway is directional: Insider builds are test builds, and Microsoft has not dated stable release for these changes. Enthusiasts can enable Open apps maximized today in the Beta channel and evaluate whether the AutoPlay redesign improves their workflow.
02Entra ID CVSS 10.0 Warning Corrected: Not Exploited
Microsoft corrected its Entra ID advisory on August 21-22 to confirm that CVE-2026-69836, a CVSS 10.0 remote code execution flaw, was not exploited in the wild. The Hacker News first reported the vulnerability on August 20, when the advisory still marked the Exploited status as Yes. Microsoft then revised the record to No, describing the change as informational only and confirming the service-side issue was fully mitigated.

The flaw, classified as CWE-502 insecure deserialization, carried the highest possible base score: AV:N/AC:L/PR:N/UI:N/S:C, meaning network-exposed, low-complexity, no-authentication exploitation with scope change. Because Entra ID is a managed cloud service, Microsoft handled remediation on its own infrastructure, and the revised advisory states that no customer action is required. The vulnerability is also not on CISA’s Known Exploited Vulnerabilities catalog.
The sequence is a useful case study in cloud security transparency: a 10.0 score looks alarming, but the score describes worst-case potential, not observed attack activity. IT teams should treat advisory corrections as normal, re-check the final Exploited status before escalating, and focus patch time on flaws with confirmed exploitation such as the SharePoint and Task Host items covered in our August 21 roundup.
03First NVIDIA Vera Rubin Systems Arrive at Microsoft
Satya Nadella confirmed on August 21 that Microsoft received its first production NVIDIA Vera Rubin systems, a milestone in the AI infrastructure race. CryptoBriefing reported on August 22 that the CEO shared a photo from a data center floor alongside the announcement. NVIDIA separately confirmed the full production ramp, and The Block Beats summarized the flash on the same day.

The NVL72 rack pairs an 88-core Vera CPU with Rubin GPUs carrying 288GB of HBM4 memory, connected over NVLink with liquid cooling. NVIDIA rates inference performance up to 5x and training up to 3.5x versus the Blackwell generation, and CoreWeave claims roughly 10x throughput per megawatt. Microsoft is deploying the systems in its Wisconsin and Atlanta AI super factories, alongside early adopters Google Cloud, CoreWeave, and OpenAI.
This is a supply-chain milestone rather than a Microsoft chip announcement; it is separate from Microsoft’s own Maia silicon program covered in our August 19 roundup. For enterprises, the practical signal is capacity: more efficient accelerators in Azure regions translate into more Copilot and inference capacity downstream, even though no customer-facing service change was announced this week.
04Hidden Unified Memory Control for Copilot+ PCs
A hidden Windows 11 setting would let Copilot+ PC owners choose how much shared system memory is reserved for AI and graphics workloads. Pureinfotech reported on August 20 that the control, enabled through feature ID 61121285, appears in Experimental build 29648.1000 released on August 17. The functionality lives in SettingsHandlers_UnifiedMemory.dll and was spotted by Windows enthusiast @XenoPanther; Computer Hoy added Spanish-language coverage on August 22.
When enabled with ViveTool, the panel shows up under Settings, System, Advanced, Unified memory, with presets ranging from Recommended and High to Maximum and Don’t allow, plus a Custom option for manual tuning. The pattern mirrors how consoles and phones expose shared memory budgets: the user decides how much of the pool goes to the GPU and NPU instead of letting the system decide invisibly.
The feature requires a device with an NPU, which means Copilot+ PCs are the target audience. Microsoft has not announced a release date, and Experimental builds are not for production use, so treat this as direction. For buyers deciding between standard and Copilot+ hardware, a memory-control roadmap makes the NPU machines more future-proof, and our Windows 11 comparison below covers the practical differences.
05Server 2019 VMs Blue-Screen After KB5120238
Windows Server 2019 guests running on Server 2022 Hyper-V can enter a CRITICAL_SERVICE_FAILED boot loop after installing KB5120238, according to a Microsoft Learn Q&A filed on August 19. The poster describes a guest VM that stops booting with a blue screen after the update, while System File Checker and DISM both report a clean image. Disabling Secure Boot does not help, and the UEFI database contains signing certificates dated 2011 and 2023.
The thread’s conclusion is that KB5120238 introduces a signature or boot-loader conflict on this hardware and virtualization combination. Until a servicing update arrives, the working path is to remove the update with an offline DISM operation and exclude it through WSUS so it does not reinstall on the next sync. Affected administrators should also verify their own VM generations and UEFI certificate dates before applying the workaround broadly.
For IT teams running Server 2019 guests on Server 2022 hosts, the practical guidance is to hold KB5120238 in that combination until Microsoft ships a fix, and to test the update on a single representative VM first if it must be deployed. This is a separate issue from the KB5121003 game-crash reports covered in our August 21 roundup, even though both involve August patch-cycle regressions.
06Edge 151.0.4129.101 Fixes Twelve High-Severity CVEs
Microsoft Edge 151.0.4129.101 patches twelve high-severity vulnerabilities, including remote code execution flaws, in the browser’s August 20 security update. France’s CERT published advisory CERTFR-2026-AVI-1071 on August 21 after the official announcement, and the Czech vulnerability database entry SB2026082139 lists CVEs 76033 through 76045 plus 76047. The flaws affect all Edge builds older than 151.0.4129.101.
The batch is dominated by Chromium-derived issues: V8 type confusion and use-after-free bugs, WebGL problems, a USB race condition, and CORS-related failures, with the highest CVSSv4 score at 8.6. Several of the entries can lead to remote code execution or sandbox escapes in combination, which is why CERT-FR marks the update as high priority.
This is a new wave from the August 20 security release and distinct from the six-CVE Edge update to 151.0.4129.86 covered in our August 18 roundup. For most organizations the action is simple: let Edge update itself or push 151.0.4129.101 through your management channel, then verify the version on kiosks and servers where automatic updates are often disabled.
07What This Means for Windows Users and IT Teams
This week’s Windows and Microsoft AI news condenses into three actions: update Edge to 151.0.4129.101, hold KB5120238 for affected Server 2019-on-2022 setups, and treat the Insider wave and unified memory control as previews worth tracking. The Entra ID story is the week’s most important correction: a headline 10.0 score that was never exploited, which is exactly why security teams should verify the final advisory before escalating.
For Windows users: check that Edge is on 151.0.4129.101 or later, since twelve CVEs including code execution are patched; enable Open apps maximized in the Beta channel if accessibility matters to you; and if you are choosing a Copilot+ PC, the unified memory control preview is a sign that NPU hardware will gain user-facing controls down the line.
For IT teams: exclude or hold KB5120238 on Server 2022 hosts running Server 2019 guests until Microsoft ships a fix; verify Edge version on every managed endpoint; and keep an eye on the Vera Rubin deployments in Wisconsin and Atlanta for future Azure capacity. For licensing decisions that intersect with these changes, the Best Windows License Buying Guide 2026, the Windows 11 Pro vs Home guide, and the Windows 10 vs Windows 11 comparison cover the common paths.
The through-line is verification: verify the Edge version, verify the advisory’s final exploitation status, and verify patch combinations on virtualized servers before broad rollout. Teams that do that this week will avoid both the panic of a corrected CVE and the disruption of a server boot loop.
FAQ
Was the Entra ID CVSS 10.0 vulnerability actually exploited?
No. Microsoft revised the advisory for CVE-2026-69836 on August 21-22 to set Exploited to No, noting it was not exploited in the wild and the change was informational only. The cloud service is fully mitigated and no customer action is required (THG, Aug 22, 2026).
Which Windows Insider builds shipped on August 21?
Beta 26H2 build 26220.9223, Experimental 26H2 build 26340.9233, and Experimental 26H1 build 28120.2760. The wave adds an Open apps maximized accessibility setting and a WinUI-rebuilt AutoPlay dialog that supports dark mode (Microsoft Learn, Aug 21, 2026).
Does the unified memory setting require special hardware?
Yes. The hidden control targets devices with an NPU, such as Copilot+ PCs. It is currently behind feature ID 61121285 in Experimental build 29648.1000 and has no announced release date (Pureinfotech, Aug 20, 2026).
How do I fix a Server 2019 VM that blue-screens after KB5120238?
The reported workaround is to remove KB5120238 with an offline DISM operation and exclude it through WSUS so it does not reinstall. Microsoft has not yet shipped a formal servicing fix for the signature or boot-loader conflict (Microsoft Learn Q&A, Aug 19, 2026).
What should I do about the August 20 Edge update?
Update Edge to 151.0.4129.101 or later. The release fixes twelve high-severity CVEs (76033-76045 and 76047), including remote code execution issues, and older builds are at risk (CERT-FR, Aug 20-21, 2026).
External References
- • Microsoft Learn: Windows Insider Experimental build 26340.9233 release notes (Aug 21, 2026)
- • Microsoft Learn: Windows Insider Beta build 26220.9223 release notes (Aug 21, 2026)
- • IT Home via 17173: Three Windows Insider channel builds for 26H2 and 26H1 (Aug 22, 2026)
- • The Hacker’s Guide: Microsoft Entra ID RCE CVE-2026-69836, corrected exploitation status (Aug 21-22, 2026)
- • The Hacker News: Microsoft Entra ID flaw rated CVSS 10.0 (Aug 20, 2026)
- • ComputerBase: Microsoft corrects Entra ID warning; flaw not exploited (Aug 21, 2026)
- • CryptoBriefing: First NVIDIA Vera Rubin production systems arrive at Microsoft (Aug 22, 2026)
- • The Block Beats: NVIDIA confirms full Vera Rubin production ramp (Aug 2026)
- • Pureinfotech: Windows 11 hidden unified memory setting for AI graphics (Aug 20, 2026)
- • Computer Hoy: Windows 11 unified memory setting for AI graphics (Aug 22, 2026)
- • Microsoft Learn Q&A: Windows Server 2019 guest VM BSOD on Server 2022 Hyper-V after KB5120238 (Aug 19, 2026)
- • CERT-FR: Microsoft Edge security update 151.0.4129.101 advisory (Aug 20-21, 2026)
- • Cybersecurity Help: Edge 151.0.4129.101 12-CVE vulnerability database entry (Aug 21, 2026)
This article was compiled with AI assistance for research and drafting and has been editorially reviewed. All sources are listed above.