Microsoft has acknowledged that recent Windows security updates have introduced significant issues affecting enterprise environments. The December 2025 Patch Tuesday updates have caused failures in the Message Queuing (MSMQ) service on Windows 10 22H2, Windows Server 2019, and Windows Server 2016, resulting in inactive queues, failed IIS sites, and applications unable to write to queues due to new security model changes that restrict necessary folder permissions. Additionally, recent updates to Windows 11 have broken VPN networking for users of the Windows Subsystem for Linux (WSL), particularly impacting enterprise VPN solutions like OpenVPN and Cisco Secure Client, with users experiencing "No route to host" errors due to virtual network interfaces not responding to ARP requests.
Microsoft is actively investigating both issues but has not yet provided a timeline for fixes or workarounds. The MSMQ problem primarily affects non-administrative users and clustered environments under load, while the WSL VPN issue mainly impacts enterprise users relying on mirrored mode networking to access corporate resources. Administrators are advised to monitor for further updates from Microsoft and consider the risks of applying recent patches in critical environments until resolutions are available.

See real exploitation activity before you spend the cycle.
4 events from the most recent confirmed update back to the earliest known activity.
Microsoft said business customers affected by the MSMQ-related IIS and application failures should contact Microsoft Support for temporary mitigation steps. The company still had no public patch available, but offered a support-assisted workaround while the investigation continued.
Microsoft publicly acknowledged that the December 2025 security updates were causing MSMQ functionality to break on some Windows systems and said it was investigating. At the time, the company had not provided a permanent fix or timeline, and administrators were advised to consider rollback with associated security tradeoffs.
Recent Windows 11 security updates, including KB5067036 and later KB5072033, caused enterprise WSL users with mirrored networking enabled to lose VPN access to corporate resources. Microsoft-linked reporting said third-party VPN interfaces such as OpenVPN and Cisco Secure Client were not responding to ARP requests, producing errors like 'No route to host.'
After installation of December 2025 Patch Tuesday security updates, including KB5071546, KB5071544, and KB5071543, Message Queuing (MSMQ) began failing on affected Windows 10 22H2, Windows Server 2019, and Windows Server 2016 systems. The issue was tied to security-model and NTFS permission changes that caused inactive queues, failed message writes, IIS and enterprise application outages, and problems in clustered MSMQ environments.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
5 references tracked. Mallory keeps watching after this page renders.
techrepublic.com
Open sourcebleepingcomputer.com
Open sourcecybersecuritynews.com
Open sourcebleepingcomputer.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.