DEV Community

Cyber Updates 365
Cyber Updates 365

Posted on Originally published at cyberupdates365.com

Windows 11 KB5124008 Update Breaks Always-On VPN: Causes, Diagnostics & Workarounds

Windows 11 KB5124008 VPN Bug: Always On VPN Fails After September 2026 Update

Enterprise IT teams and network administrators deploying Microsoft\'s September 2026 Patch Tuesday cumulative package (KB5124008) have encountered unexpected connection dropouts affecting certificate-authenticated Always On VPN tunnels.

The regression impacts Windows 11 versions 24H2 (Build 26100.9445) and 25H2 (Build 26200.9445) devices managed via Microsoft Intune and authenticating against Network Policy Server (NPS) / RRAS backends.

Key Incident Details

  • Affected Update: KB5124008 (September 8, 2026 Patch Tuesday release)
  • Primary Symptom: Certificate-based Always On VPN tunnels reject authentication handshakes and disconnect immediately.
  • Confirmed Workaround: Uninstalling KB5124008 via Windows Settings or DISM restores the tunnel immediately upon system reboot.
  • Security Context: KB5124008 also addresses two actively exploited elevation-of-privilege zero-days (CVE-2026-81963 and CVE-2026-85880), meaning administrators should consider ring-based deferrals rather than global update pauses.

For detailed root-cause telemetry analysis, RasClient event logs, and administrative deployment ring guidance:

👉 Read the Full Investigation & Rollback Guide on CyberUpdates365

Top comments (0)