Microsoft said the Windows security update KB5082063 can cause some Windows domain controllers to enter continuous reboot loops after LSASS crashes during startup. The issue affects non-Global Catalog domain controllers in environments using Privileged Access Management, disrupting Active Directory authentication and directory services and potentially making affected domains unavailable. Impacted platforms include Windows Server 2016, 2019, 2022, 23H2, and 2025, while consumer systems and devices outside IT-managed domains are not affected.
Microsoft has not yet released a fix and is advising affected organizations to contact Microsoft Support for Business for mitigation guidance. The company also acknowledged two other known issues tied to KB5082063: installation failures on some Windows Server 2025 systems and BitLocker recovery key prompts on some Windows Server 2025 devices. The incident adds to a string of recent Windows Server update problems that have affected domain controllers and authentication services in enterprise environments.

See real exploitation activity before you spend the cycle.
3 events from the most recent confirmed update back to the earliest known activity.
Microsoft issued out-of-band emergency updates to fix problems caused by the April 2026 security updates across multiple Windows Server versions. The Windows Server 2025 OOB update KB5091157 addressed both KB5082063 installation failures and domain controller reboot loops, while OOB updates for other supported server versions fixed the restart-loop issue.
Microsoft said it was still developing a fix for the KB5082063 reboot-loop issue and directed impacted administrators to Microsoft Support for Business for mitigation guidance. The company also noted separate April 2026 problems tied to the same update, including installation failures and BitLocker recovery prompts on some Windows Server 2025 systems.
Microsoft disclosed that the April 2026 Windows security update KB5082063 can trigger LSASS crashes during startup on some non-Global Catalog domain controllers in Privileged Access Management environments, causing continuous reboot loops. The issue affects Windows Server 2016, 2019, 2022, 23H2, and 2025 and can disrupt authentication and directory services.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
4 references tracked. Mallory keeps watching after this page renders.
bleepingcomputer.com
Open sourcego.theregister.com
Open sourcetomshardware.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.