Microsoft's KB5124008 security update, released on September 8, 2026, is causing issues with Windows 11 enterprise clients' Always On VPN after the patch was installed. Administrators who can reproduce the failure report that certificate-based tunnels that previously worked immediately after the patch stop connecting afterward. The first detailed account appeared on Microsoft Q&A on September 9, 2026, from an administrator running Windows 11 24H2 and 25H2 clients with Always On VPN, certificate-based authentication, Routing and Remote Access Service, and Network Policy Server on Windows Server 2019, as well as a VPN profile deployed through Microsoft Intune.
Independent advisor Domic Vo explained that the issue aligns with changes in the Windows networking stack or IPsec certificate handling, not with local configuration mistakes.
The same release is a mandatory Patch Tuesday package that covers a record number of vulnerabilities, including two zero-day elevation-of-privilege exploits: CVE-2026-81963 in the Windows Update Stack and CVE-2026-85880 in Windows Advanced Local Procedure Call. Given the trade-off between client availability and a large security backlog, many shops will opt to freeze only Always On VPN cohorts in WSUS or Intune rather than blocking the entire estate. Organizations that need to keep the patch for compliance should pilot any authentication changes in a small ring and treat uninstall-and-reboot as the only currently proven recovery method.












