Microsoft said some Windows Server 2025 devices may enter BitLocker recovery after installing the April 2026 KB5082063 security update, affecting systems with a specific and discouraged BitLocker Group Policy tied to TPM platform validation, PCR7, and Secure Boot conditions during transition to the 2023-signed Windows Boot Manager. The company said the recovery key prompt should typically appear only on the first restart, is preparing a fix, and advised administrators to remove the problematic policy before deployment or use Known Issue Rollback; the issue is mainly expected in enterprise-managed environments rather than personal devices.
Separately, researchers disclosed BitUnlocker, a downgrade attack that can expose data on BitLocker-protected Windows 11 systems in under five minutes with physical access by exploiting CVE-2025-48804 in the Windows Recovery Environment. The attack works because Secure Boot may still trust older Microsoft Windows PCA 2011-signed boot managers, allowing a pre-patch bootmgfw.efi and modified WinRE chain to launch cmd.exe with the encrypted volume already mounted; systems using TPM-only BitLocker remain at risk unless organizations migrate trust to Windows UEFI CA 2023 via KB5025885 or require TPM+PIN pre-boot authentication.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
Microsoft resolved the April 2026 BitLocker recovery problem for Windows 11 version 25H2 with cumulative update KB5089549. The company said the issue was tied to an unsupported BitLocker Group Policy and noted that fixes for Windows 10 and Windows Server would come in a future update.
A public proof of concept for BitUnlocker was released on GitHub, increasing the urgency for defenders to enable pre-boot authentication, verify boot manager certificates, and migrate away from PCA 2011 trust.
Researchers publicly described BitUnlocker, a downgrade attack that can access BitLocker-protected Windows 11 disks in under five minutes with physical access by abusing CVE-2025-48804 through a trusted older boot manager and modified WinRE chain. They said TPM-only BitLocker systems are vulnerable while TPM+PIN and systems migrated to Windows UEFI CA 2023 are protected.
Microsoft confirmed the Windows Server 2025 BitLocker recovery problem, said the recovery key should typically be needed only on the first restart, and stated it was working on a fix. The company advised admins to remove the relevant Group Policy before deployment or use Known Issue Rollback.
After installing the April 2026 KB5082063 security update, some Windows Server 2025 devices booted into BitLocker recovery. Microsoft said the issue affects systems with a specific unsupported BitLocker Group Policy configuration tied to TPM platform validation and Secure Boot conditions.
Microsoft fixed CVE-2025-48804 in bootmgfw.efi in July 2025, but older Microsoft Windows PCA 2011-signed boot managers remained trusted on affected systems. This left a downgrade path that later enabled the BitUnlocker attack scenario.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcewindowslatest.com
Open sourcebleepingcomputer.com
Open sourcecybersecuritynews.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.