VYPR
patchPublished Sep 11, 2026· 1 source

Windows 11 Update KB5124008 Breaks Always-On VPN Connections

Microsoft's September 2026 security update KB5124008 is causing connection failures for enterprise clients using Always On VPN with certificate-based authentication.

Microsoft's September 2026 Patch Tuesday release, update KB5124008, has introduced a significant regression impacting enterprise users of Windows 11, specifically breaking Always On VPN connections that rely on certificate-based authentication. The issue, first reported by administrators on September 9, 2026, prevents VPN tunnels from establishing after the cumulative update is installed. The only confirmed workaround currently is to uninstall the problematic update and reboot the affected machine, restoring connectivity.

This regression affects both Windows 11 24H2 and 25H2 versions. Administrators have noted that the problem occurs consistently: VPN connections function correctly before the update, but fail immediately after its installation. The cycle of working, then broken, then working again after removal strongly indicates a client-side issue within the Windows networking stack or its handling of IPsec certificates, rather than a misconfiguration in network policies or servers.

While Microsoft's official support article for KB5124008 currently states no known issues, IT departments are already pausing the rollout of this update to their remote access fleets. The dilemma for organizations is significant: delaying the update leaves systems vulnerable to the two actively exploited zero-day vulnerabilities also patched in this release – CVE-2026-81963 in the Windows Update Stack and CVE-2026-85880 in Windows Advanced Local Procedure Call (ALPC).

The timing of this VPN connectivity issue is particularly inconvenient, as the same cumulative update also claimed to improve resiliency for VPN-related background processes. This creates a direct conflict where a patch intended to harden VPN functionality inadvertently breaks a core component for many enterprise remote access scenarios.

For organizations that cannot afford to delay the security patches due to compliance or risk management requirements, the situation is challenging. They must weigh the immediate impact on remote worker productivity against the risks posed by unpatched zero-day vulnerabilities. Some administrators are considering pausing the update only for Always On VPN endpoints while allowing it for other systems, or exploring alternative authentication methods as a temporary stopgap.

Independent security advisors have suggested collecting detailed diagnostic data, such as rasphone.pbk entries, RasClient event logs, and Network Policy Server (NPS) logs, to aid Microsoft in diagnosing the issue should a support case be opened. While some suggest retargeting Intune profiles to use EAP-TLS, this remains an unproven stopgap measure and not official guidance.

This incident highlights the ongoing challenges of patch management, especially when critical security updates introduce regressions that disrupt essential business operations. Until Microsoft officially acknowledges the problem and releases a hotfix or a revised cumulative update, organizations are advised to proceed with caution, potentially pausing deployment on affected systems and closely monitoring for official advisories.

Home users who do not utilize Always On VPN are not affected by this specific issue. The primary impact is on enterprise environments relying on secure, persistent remote access for their workforce.

Synthesized by Vypr AI