Windows 11 Security Update KB5124008 Breaks Always-On VPN Connections
Microsoft's September 2026 Windows 11 update KB5124008 breaks certificate-based Always On VPN on some enterprise clients, forcing admins to pause rollout.
Microsoft's September 8, 2026 cumulative update KB5124008 for Windows 11 24H2 (build 26100.9445) and 25H2 (build 26200.9445) breaks certificate-based Always On VPN tunnels on some enterprise clients, with connectivity restored after uninstalling the update and rebooting. The issue was first detailed on Microsoft Q&A on September 9 by an administrator using Intune-deployed VPN profiles with RRAS and NPS on Windows Server 2019. The same mandatory Patch Tuesday package fixes two actively exploited zero-days, CVE-2026-81963 in the Windows Update Stack and CVE-2026-85880 in Windows Advanced Local Procedure Call, so many teams are pausing only VPN cohorts rather than blocking the full rollout.
- KB5124008 breaks certificate-based Always On VPN on Windows 11 24H2 and 25H2 enterprise clients.
- Uninstalling the cumulative update and rebooting reliably restores VPN connectivity on affected machines.
- The same update patches two actively exploited zero-days: CVE-2026-81963 and CVE-2026-85880.
- Microsoft's support article says it is not currently aware of any issues with the update.
- Experts recommend pausing rollout on VPN endpoints and collecting RasClient and NPS logs.
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-81963 +1 in the same advisory: …85880 | Local Privilege Escalation via Link Following in Windows Update Stack CVE-2026-81963 is a link-following flaw (CWE-59, improper link resolution before file access) in the Microsoft Windows Update Stack, in which the component fails to correctly resolve file links before opening them. A local attacker with low privileges can plant or manipulate a link (symlink/junction) that the privileged update stack follows during operation, redirecting its file access to an attacker-controlled target. The result is local privilege escalation — CVSS 3.1 rates this 7.8 (high) with high confidentiality, integrity, and availability impact — allowing an authorized local user or malware already on the machine to gain elevated rights. Affected products are Windows 11 23H2, 24H2, 25H2, and 26H1 and Windows Server 2025; any unpatched system on those versions is exposed to any local account holder. The flaw was fixed in Microsoft's record September 2026 Patch Tuesday (974 CVEs), was added to CISA's KEV on 2026-09-08 as one of two Windows zero-days reported as exploited in the wild, and has no known public PoC or confirmed ransomware use. Do: Immediately deploy the September 2026 Patch Tuesday cumulative updates to every Windows 11 23H2/24H2/25H2/26H1 and Windows Server 2025 host; as a KEV entry under BOD 26-04, prioritize internet-exposed and high-value assets, apply vendor mitigations (or discontinue use) where patching is delayed, and follow CISA's forensics triage requirements if compromise is suspected. Verify deployment via patch telemetry and review which local accounts can trigger update-stack activity on shared or multi-user systems. | 7.8 | <1% | KEV |
| masswell over 1,000,000 |
Full article578 words · extracted from cybersecuritynews.com · click to collapse
Microsoft’s September 2026 security update KB5124008 is knocking some Windows 11 enterprise clients off Always On VPN after the Patch Tuesday package landed on September 8.
Administrators who can reproduce the failure say certificate-based tunnels that worked immediately before the patch stop connecting afterward, then recover as soon as the cumulative update is removed and the device is rebooted.
The first detailed account appeared on Microsoft Q&A on September 9, 2026, from an administrator running Windows 11 24H2 and 25H2 clients with Always On VPN, certificate-based authentication, Routing and Remote Access Service plus Network Policy Server on Windows Server 2019, and a VPN profile deployed through Microsoft Intune.
Windows 11 Security Update KB5124008
After KB5124008 is installed, Always On VPN no longer connects. Uninstalling the update and rebooting restores the tunnel on multiple machines, which is why the reporter halted the rollout. That working-broken-working cycle is the classic signature of a client-side regression rather than a bad Intune profile or a failing NPS server.
Independent advisor Domic Vo told the original poster the pattern lines up with a change in the Windows networking stack or IPsec certificate handling, not a local configuration mistake.
Vo advised collecting rasphone.pbk data, RasClient events under Applications and Services Logs, and NPS logs if a Microsoft support case is opened. A suggestion to retarget affected Intune profiles toward EAP-TLS should be treated only as an unproven stopgap, not official Microsoft guidance.
KB5124008 is the September 8 cumulative security update for Windows 11 24H2, which moves to build 26100.9445, and 25H2, which moves to build 26200.9445.
Microsoft’s support article still says the company is not currently aware of any issues with this update, even as some IT teams pause deployment on remote-access fleets.
The same release is a mandatory Patch Tuesday package covering a record volume of vulnerabilities, including two elevation-of-privilege zero-days already exploited in the wild: CVE-2026-81963 in the Windows Update Stack and CVE-2026-85880 in Windows Advanced Local Procedure Call.
Holding the client update therefore trades tunnel availability against a large security backlog, which is why many shops will freeze only Always On VPN cohorts in WSUS or Intune rather than blocking the entire estate.
The timing is especially awkward because the same cumulative update also advertised better resiliency for VPN-related background processes that could stop responding.
A security patch that claims VPN hardening while breaking certificate-based Always On VPN is exactly the kind of regression enterprise networking teams watch for after Patch Tuesday.
Until Microsoft documents the failure or ships a hotfix, the conservative path is the one the original environment already took. Pause KB5124008 on Always On VPN endpoints, keep RRAS and NPS servers current, and escalate with RasClient and NPS evidence so the case can be clustered with other reports.
Organizations that must keep the patch for compliance should pilot any authentication change in a small ring and treat uninstall-and-reboot as the only currently proven recovery. Home users without Always On VPN are unaffected.
This is an enterprise remote-access regression sitting on top of an otherwise high-priority Windows 11 security release, and it deserves a known-issue entry before the next servicing wave.
Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.
Guru Baranhttps://cybersecuritynews.com
Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cybersecuritynews.com/windows-11-security-update-kb5124008/