HomeIntelligenceBrief
BREACH BRIEF 🟠 High Advisory

Microsoft September 2026 Windows Updates Disrupt Always On VPN Connectivity

September 2026 Windows 11 updates cause Always On VPN clients to fail when automatic protocol selection is enabled, impacting enterprise remote‑access. This highlights the need for robust configuration‑management and continuous control‑assurance to keep remote connectivity reliable.

Verisq™ Intelligence · 📅 September 23, 2026 · 📰 bleepingcomputer.com
🟠
Severity
High
AD
Type
Advisory
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
3 recommended
📰
Source
bleepingcomputer.com

Microsoft September 2026 Windows Updates Disrupt Always On VPN Connectivity

What Happened – Microsoft’s September 2026 cumulative updates for Windows 11 (KB 5124012, KB 5124008) caused Always On VPN clients to stall in a “Connecting” state or repeatedly fail, sometimes reporting “The specified port is already in use.” The issue appears when the VPN profile is set to automatic protocol selection (IKEv2 / SSTP).

Why It Matters for Trust & Control Assurance

  • It illustrates a gap in configuration‑management controls: automated updates can unintentionally break critical remote‑access settings, undermining the continuity of secure connectivity.
  • Continuous control‑assurance programs must capture such change‑impact events, provide evidence of remediation (e.g., protocol‑selection lock‑down), and maintain a defensible audit trail of remote‑access availability.

Who Is Affected – Enterprises of all sizes that rely on Windows 10/11 or Windows Server for remote work, including professional‑services firms, financial institutions, healthcare providers, and government agencies.

Recommended Actions

  • Review all Always On VPN profiles and switch from automatic protocol selection to a single protocol (either IKEv2 or SSTP) as a temporary mitigation.
  • Update your configuration‑management process to include post‑update validation of VPN connectivity and log any failures for continuous monitoring.
  • Track Microsoft’s forthcoming permanent fix and incorporate the patch into your change‑control pipeline.

Technical Notes – The problem is triggered by the September 2026 Windows 11 security updates (KB 5124012, KB 5124008). No CVE is associated; the root cause is a regression in the VPN client’s protocol‑selection logic. Affected components: Always On VPN client, IKEv2/SSTP protocols, network‑stack handling of port allocation. Source: BleepingComputer

📰 Original Source
https://www.bleepingcomputer.com/news/microsoft/microsoft-september-2026-windows-updates-break-always-on-vpn-connections/

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →