Windows 11 KB5124008 VPN Bug: Always On VPN Fails After September 2026 Update
Enterprise IT teams and network administrators deploying Microsoft\'s September 2026 Patch Tuesday cumulative package (KB5124008) have encountered unexpected connection dropouts affecting certificate-authenticated Always On VPN tunnels.
The regression impacts Windows 11 versions 24H2 (Build 26100.9445) and 25H2 (Build 26200.9445) devices managed via Microsoft Intune and authenticating against Network Policy Server (NPS) / RRAS backends.
Key Incident Details
- Affected Update: KB5124008 (September 8, 2026 Patch Tuesday release)
- Primary Symptom: Certificate-based Always On VPN tunnels reject authentication handshakes and disconnect immediately.
- Confirmed Workaround: Uninstalling KB5124008 via Windows Settings or DISM restores the tunnel immediately upon system reboot.
- Security Context: KB5124008 also addresses two actively exploited elevation-of-privilege zero-days (CVE-2026-81963 and CVE-2026-85880), meaning administrators should consider ring-based deferrals rather than global update pauses.
For detailed root-cause telemetry analysis, RasClient event logs, and administrative deployment ring guidance:
👉 Read the Full Investigation & Rollback Guide on CyberUpdates365
Top comments (0)