Microsoft September 2026 Windows Updates Disrupt Always On VPN Connectivity
What Happened – Microsoft’s September 2026 cumulative updates for Windows 11 (KB 5124012, KB 5124008) caused Always On VPN clients to stall in a “Connecting” state or repeatedly fail, sometimes reporting “The specified port is already in use.” The issue appears when the VPN profile is set to automatic protocol selection (IKEv2 / SSTP).
Why It Matters for Trust & Control Assurance
- It illustrates a gap in configuration‑management controls: automated updates can unintentionally break critical remote‑access settings, undermining the continuity of secure connectivity.
- Continuous control‑assurance programs must capture such change‑impact events, provide evidence of remediation (e.g., protocol‑selection lock‑down), and maintain a defensible audit trail of remote‑access availability.
Who Is Affected – Enterprises of all sizes that rely on Windows 10/11 or Windows Server for remote work, including professional‑services firms, financial institutions, healthcare providers, and government agencies.
Recommended Actions
- Review all Always On VPN profiles and switch from automatic protocol selection to a single protocol (either IKEv2 or SSTP) as a temporary mitigation.
- Update your configuration‑management process to include post‑update validation of VPN connectivity and log any failures for continuous monitoring.
- Track Microsoft’s forthcoming permanent fix and incorporate the patch into your change‑control pipeline.
Technical Notes – The problem is triggered by the September 2026 Windows 11 security updates (KB 5124012, KB 5124008). No CVE is associated; the root cause is a regression in the VPN client’s protocol‑selection logic. Affected components: Always On VPN client, IKEv2/SSTP protocols, network‑stack handling of port allocation. Source: BleepingComputer