Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
CEO Impersonation Emails Target Employees for $50,000 Payments
September 11, 2026
KATARU IoT Malware Exploits Linux Privilege Escalation for Mirai-Style DDoS Attacks
September 11, 2026
Russia-Aligned Hackers Use GuardBreaker Prompt Injection to Disrupt AI Malware Analysis
September 11, 2026
Home/CyberSecurity News/Windows 11 Update KB5124008 Breaks Always-On VPN Connections
CyberSecurity News

Windows 11 Update KB5124008 Breaks Always-On VPN Connections

Key Takeaways Microsoft’s September 2026 security update, KB5124008, is causing Always On VPN connections to fail for some Windows 11 enterprise users. The issue specifically impacts...

David kimber
David kimber
September 11, 2026 3 Min Read
4 0

Key Takeaways

  • Microsoft’s September 2026 security update, KB5124008, is causing Always On VPN connections to fail for some Windows 11 enterprise users.
  • The issue specifically impacts certificate-based VPN tunnels on Windows 11 versions 24H2 and 25H2.
  • Uninstalling KB5124008 and rebooting the affected device restores VPN functionality.
  • The update also addresses critical zero-day vulnerabilities, creating a dilemma for IT administrators.

Windows 11 Update KB5124008 Disrupts Always On VPN

Microsoft’s latest cumulative security update for Windows 11, identified as KB5124008, is reportedly causing significant disruption for enterprise clients relying on Always On VPN. Released on September 8, 2026, as part of Patch Tuesday, the update is preventing certificate-based VPN tunnels from establishing connections on affected Windows 11 systems.

Table Of Content

  • Key Takeaways
  • Windows 11 Update KB5124008 Disrupts Always On VPN
  • Initial Reports and Technical Analysis
  • The Dilemma for IT Departments
  • What You Should Do

System administrators have observed that VPN connectivity, which was fully functional prior to the installation of KB5124008, ceases to work immediately afterward. Crucially, uninstalling the update and performing a system reboot consistently restores the VPN connection, indicating a direct causal link between the patch and the network instability.

Initial Reports and Technical Analysis

The first detailed report of this issue emerged on Microsoft Q&A on September 9, 2026. An administrator outlined a scenario involving Windows 11 24H2 and 25H2 clients utilizing Always On VPN with certificate-based authentication, a VPN profile distributed via Microsoft Intune, and a backend infrastructure running Routing and Remote Access Service (RRAS) and Network Policy Server (NPS) on Windows Server 2019.

The consistent pattern of VPN failure post-installation and recovery post-uninstallation strongly suggests a client-side regression introduced by the update. This behavior rules out issues with Intune profiles or NPS server configurations, pointing instead to a fundamental change within the operating system itself.

Independent advisor Domic Vo corroborated this assessment, suggesting that the problem likely stems from alterations within the Windows networking stack or how the system handles IPsec certificates, rather than a misconfiguration by the user. Vo recommended gathering specific diagnostic data, including rasphone.pbk information, RasClient events from Application and Services Logs, and NPS logs, should a formal support case be initiated with Microsoft. A suggestion to modify Intune profiles to use EAP-TLS was presented as an unverified workaround, not an official solution.

The Dilemma for IT Departments

KB5124008 is the cumulative security update for Windows 11 24H2 (build 26100.9445) and 25H2 (build 26200.9445). Despite the growing number of reports, Microsoft’s official support article for the update currently states no known issues, even as many IT departments have temporarily halted its deployment to remote-access endpoints.

This situation presents a significant challenge for organizations. KB5124008 is a critical Patch Tuesday release that addresses a substantial number of vulnerabilities, including two zero-day elevation-of-privilege flaws already under active exploitation: CVE-2026-81963 in the Windows Update Stack and CVE-2026-85880 in Windows Advanced Local Procedure Call. Delaying this update means leaving systems exposed to known threats.

Compounding the problem, the same cumulative update paradoxically claimed to enhance the resiliency of VPN-related background processes. This unexpected regression, breaking core VPN functionality while simultaneously purporting to strengthen it, is precisely the type of post-Patch Tuesday issue enterprise networking teams strive to avoid. Many organizations are therefore opting to selectively block the update only for Always On VPN cohorts within WSUS or Intune, rather than preventing its deployment across their entire estate.

What You Should Do

  • Pause Deployment: For endpoints utilizing Always On VPN, IT administrators should consider temporarily pausing the deployment of KB5124008 until Microsoft acknowledges and addresses the issue.
  • Maintain Server Updates: Ensure that Routing and Remote Access Service (RRAS) and Network Policy Server (NPS) servers are kept current with the latest patches.
  • Collect Diagnostics: If experiencing issues, gather diagnostic information such as rasphone.pbk data, RasClient events from Applications and Services Logs, and NPS logs to facilitate troubleshooting and provide evidence for potential Microsoft support cases.
  • Pilot Workarounds: Any proposed workarounds, such as changing authentication methods to EAP-TLS, should be thoroughly tested in a small, controlled environment before broad implementation.
  • Recovery Strategy: The only currently proven method for restoring VPN connectivity on affected devices is to uninstall KB5124008 and reboot the system.
  • Home Users Unaffected: This issue primarily impacts enterprise environments using Always On VPN; home users without this specific setup are not affected.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

CVEExploitPatchSecurityzero-day

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

Android Ransomware Records Screens, Steals OTPs, and Takes Photos

Next Post

Russia-Aligned Hackers Use GuardBreaker Prompt Injection to Disrupt AI Malware Analysis

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Conti Ransomware Affiliate Sentenced for Attacks on 1,000+ Victims
September 11, 2026
Ubuntu 24.04.5 LTS Released With Linux 7.0 Kernel and Latest Security Updates
September 11, 2026
Critical cPanel & CSF Vulnerability Lets Attackers Run Commands
September 11, 2026
Top Authors
David kimber
David kimber
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us