Microsoft's cumulative Windows 11 security update KB5124008 is reportedly preventing certificate-based Always On VPN tunnels from connecting on some enterprise endpoints running Windows 11 24H2 and 25H2. Administrators using Intune-deployed VPN profiles with RRAS, NPS, and certificate authentication found that uninstalling the update and rebooting restored connectivity, indicating a likely client-side regression; Microsoft had not listed the issue in its known-issues documentation.
The failure creates an operational and security tradeoff for affected organizations: pausing or removing the update may restore remote access, but KB5124008 remediates numerous vulnerabilities, including two elevation-of-privilege zero-days reported to be actively exploited. Enterprises should identify affected Always On VPN clients, test mitigation options, and monitor Microsoft for an acknowledged issue and supported fix before broadly rolling back the security release.

See which actors are running it and whether you're in range.
2 events from the most recent confirmed update back to the earliest known activity.
A detailed report posted to Microsoft Q&A said certificate-based Always On VPN tunnels on Windows 11 24H2 and 25H2 enterprise clients failed after KB5124008 installation. Administrators reported that uninstalling the update and rebooting restored connectivity, indicating a possible client-side Windows networking or IPsec certificate-handling regression.
Microsoft released the KB5124008 cumulative security update for Windows 11 24H2 and 25H2, updating them to builds 26100.9445 and 26200.9445 respectively. The update included fixes for the actively exploited elevation-of-privilege vulnerabilities CVE-2026-81963 and CVE-2026-85880.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.