Microsoft confirmed that September 2026 Windows security updates can prevent the built-in File History feature from creating or updating backups. Affected devices can display a false “Reconnect your drive” warning, retain stale backup timestamps, lose access to prior file versions, or log FileHistory.exe and KERNELBASE.dll crashes—while a connected backup drive may appear healthy. The issue affects multiple Windows 10 and Windows 11 releases, including Windows 11 23H2 through 26H1 and Windows 10 21H2/22H2 and Enterprise LTSC editions; Windows Server is not affected.
Microsoft has documented the regression and is developing a fix for a future Windows update, but has not provided an official workaround. Organizations should immediately validate backup job completion, backup freshness, and restoration capability on affected endpoints, and maintain separate verified backups until a corrective update is available.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
Microsoft added a known issue confirming that the September security updates can break File History backups. Affected systems can show erroneous drive-reconnection alerts, stale backup timestamps, unavailable previous versions, and FileHistory.exe/KERNELBASE.dll crash events.
Microsoft rolled out its September 2026 Windows security updates. The updates later were found to prevent File History from creating or updating backups on affected Windows systems.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
cryptika.com
Open sourcecybersecuritynews.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.