Windows 11 Update KB5124008 Breaks Always-On VPN Connections
Key Takeaways Microsoft’s September 2026 security update, KB5124008, is causing Always On VPN connections to fail for some Windows 11 enterprise users. The issue specifically impacts...
Key Takeaways
- Microsoft’s September 2026 security update, KB5124008, is causing Always On VPN connections to fail for some Windows 11 enterprise users.
- The issue specifically impacts certificate-based VPN tunnels on Windows 11 versions 24H2 and 25H2.
- Uninstalling KB5124008 and rebooting the affected device restores VPN functionality.
- The update also addresses critical zero-day vulnerabilities, creating a dilemma for IT administrators.
Windows 11 Update KB5124008 Disrupts Always On VPN
Microsoft’s latest cumulative security update for Windows 11, identified as KB5124008, is reportedly causing significant disruption for enterprise clients relying on Always On VPN. Released on September 8, 2026, as part of Patch Tuesday, the update is preventing certificate-based VPN tunnels from establishing connections on affected Windows 11 systems.
Table Of Content
System administrators have observed that VPN connectivity, which was fully functional prior to the installation of KB5124008, ceases to work immediately afterward. Crucially, uninstalling the update and performing a system reboot consistently restores the VPN connection, indicating a direct causal link between the patch and the network instability.
Initial Reports and Technical Analysis
The first detailed report of this issue emerged on Microsoft Q&A on September 9, 2026. An administrator outlined a scenario involving Windows 11 24H2 and 25H2 clients utilizing Always On VPN with certificate-based authentication, a VPN profile distributed via Microsoft Intune, and a backend infrastructure running Routing and Remote Access Service (RRAS) and Network Policy Server (NPS) on Windows Server 2019.
The consistent pattern of VPN failure post-installation and recovery post-uninstallation strongly suggests a client-side regression introduced by the update. This behavior rules out issues with Intune profiles or NPS server configurations, pointing instead to a fundamental change within the operating system itself.
Independent advisor Domic Vo corroborated this assessment, suggesting that the problem likely stems from alterations within the Windows networking stack or how the system handles IPsec certificates, rather than a misconfiguration by the user. Vo recommended gathering specific diagnostic data, including rasphone.pbk information, RasClient events from Application and Services Logs, and NPS logs, should a formal support case be initiated with Microsoft. A suggestion to modify Intune profiles to use EAP-TLS was presented as an unverified workaround, not an official solution.
The Dilemma for IT Departments
KB5124008 is the cumulative security update for Windows 11 24H2 (build 26100.9445) and 25H2 (build 26200.9445). Despite the growing number of reports, Microsoft’s official support article for the update currently states no known issues, even as many IT departments have temporarily halted its deployment to remote-access endpoints.
This situation presents a significant challenge for organizations. KB5124008 is a critical Patch Tuesday release that addresses a substantial number of vulnerabilities, including two zero-day elevation-of-privilege flaws already under active exploitation: CVE-2026-81963 in the Windows Update Stack and CVE-2026-85880 in Windows Advanced Local Procedure Call. Delaying this update means leaving systems exposed to known threats.
Compounding the problem, the same cumulative update paradoxically claimed to enhance the resiliency of VPN-related background processes. This unexpected regression, breaking core VPN functionality while simultaneously purporting to strengthen it, is precisely the type of post-Patch Tuesday issue enterprise networking teams strive to avoid. Many organizations are therefore opting to selectively block the update only for Always On VPN cohorts within WSUS or Intune, rather than preventing its deployment across their entire estate.
What You Should Do
- Pause Deployment: For endpoints utilizing Always On VPN, IT administrators should consider temporarily pausing the deployment of KB5124008 until Microsoft acknowledges and addresses the issue.
- Maintain Server Updates: Ensure that Routing and Remote Access Service (RRAS) and Network Policy Server (NPS) servers are kept current with the latest patches.
- Collect Diagnostics: If experiencing issues, gather diagnostic information such as
rasphone.pbkdata, RasClient events from Applications and Services Logs, and NPS logs to facilitate troubleshooting and provide evidence for potential Microsoft support cases. - Pilot Workarounds: Any proposed workarounds, such as changing authentication methods to EAP-TLS, should be thoroughly tested in a small, controlled environment before broad implementation.
- Recovery Strategy: The only currently proven method for restoring VPN connectivity on affected devices is to uninstall KB5124008 and reboot the system.
- Home Users Unaffected: This issue primarily impacts enterprise environments using Always On VPN; home users without this specific setup are not affected.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.