Microsoft: September Windows updates break Always On VPN connections
Microsoft's September 2026 Windows 11 security updates have caused issues with Always On VPN connections on some systems. The problem occurs when the VPN is configured to automatically switch connection methods if the initial attempt fails, leading to connections stuck in a 'Connecting' state or repeated failed attempts with errors such as 'The specified port is already in use.' Microsoft has provided a temporary workaround by recommending administrators configure the VPN to use a single tunneling protocol (either SSTP or IKEv2) instead of automatic protocol selection. A permanent fix is still in development.
AI Analysis
Technical Summary
The September 2026 cumulative security updates for Windows 11 versions 26H1, 25H2, and 24H2 (KB5124012 and KB5124008) introduce a connectivity issue with Always On VPN. When Always On VPN is set to automatically select between IKEv2 and SSTP protocols, the VPN connection may fail to establish, remain stuck in a connecting state, or produce port usage errors. Microsoft advises IT administrators to mitigate this by configuring the VPN profile to use a single protocol rather than automatic selection. This issue affects Windows 11 systems after applying the specified updates. Microsoft is working on a permanent solution.
Potential Impact
Affected Windows 11 systems may experience failed or unstable Always On VPN connections, potentially disrupting remote access to enterprise networks. The issue specifically impacts VPN configurations that use automatic protocol selection, causing connection attempts to hang or fail with port conflicts. This may affect user productivity and access to corporate resources relying on Always On VPN.
Mitigation Recommendations
Microsoft recommends that IT administrators temporarily mitigate the issue by changing the Always On VPN profile from automatic protocol selection to a single protocol, either SSTP only or IKEv2 only, based on their environment and security requirements. A permanent fix is pending from Microsoft. Organizations should monitor official Microsoft communications for updates and apply the permanent fix once available.
Microsoft: September Windows updates break Always On VPN connections
Description
Microsoft's September 2026 Windows 11 security updates have caused issues with Always On VPN connections on some systems. The problem occurs when the VPN is configured to automatically switch connection methods if the initial attempt fails, leading to connections stuck in a 'Connecting' state or repeated failed attempts with errors such as 'The specified port is already in use.' Microsoft has provided a temporary workaround by recommending administrators configure the VPN to use a single tunneling protocol (either SSTP or IKEv2) instead of automatic protocol selection. A permanent fix is still in development.
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The September 2026 cumulative security updates for Windows 11 versions 26H1, 25H2, and 24H2 (KB5124012 and KB5124008) introduce a connectivity issue with Always On VPN. When Always On VPN is set to automatically select between IKEv2 and SSTP protocols, the VPN connection may fail to establish, remain stuck in a connecting state, or produce port usage errors. Microsoft advises IT administrators to mitigate this by configuring the VPN profile to use a single protocol rather than automatic selection. This issue affects Windows 11 systems after applying the specified updates. Microsoft is working on a permanent solution.
Potential Impact
Affected Windows 11 systems may experience failed or unstable Always On VPN connections, potentially disrupting remote access to enterprise networks. The issue specifically impacts VPN configurations that use automatic protocol selection, causing connection attempts to hang or fail with port conflicts. This may affect user productivity and access to corporate resources relying on Always On VPN.
Defensive Guidance
Microsoft recommends that IT administrators temporarily mitigate the issue by changing the Always On VPN profile from automatic protocol selection to a single protocol, either SSTP only or IKEv2 only, based on their environment and security requirements. A permanent fix is pending from Microsoft. Organizations should monitor official Microsoft communications for updates and apply the permanent fix once available.
Technical Details
- Classification
- {"confidence":0.3,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.bleepingcomputer.com/news/microsoft/microsoft-september-2026-windows-updates-break-always-on-vpn-connections/","fetched":true,"fetchedAt":"2026-09-23T11:32:56.562Z","wordCount":724}
Threat ID: 6ab3b8e8f7a7c54106b30af4
Added to database: 09/23/2026, 11:32:56 UTC
Last enriched: 09/23/2026, 11:33:02 UTC
Last updated: 09/23/2026, 13:34:34 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.