Windows 11 KB5124008 update graphic showing a broken VPN connection icon and Patch Tuesday September 2026 badge

Windows 11 KB5124008: What It Fixes, and the VPN Bug It Just Created

If your work VPN stopped connecting or you suddenly can’t log into your domain-joined PC, Windows 11 KB5124008 is probably why. Microsoft’s September Patch Tuesday update fixes the cursor and black-desktop bugs from last month, but it also broke certificate-based Always On VPN and domain sign-ins for a chunk of users. Here’s what’s actually happening and how to work around it while a real fix is pending.

Here’s the short version before you decide whether to update today:

  • Released September 8, 2026 for Windows 11 24H2 (build 26100.9445) and 25H2 (build 26200.9445)
  • Patches two actively exploited zero-days, CVE-2026-81963 and CVE-2026-85880
  • Breaks certificate-based Always On VPN on networks using RRAS plus Network Policy Server
  • Breaks domain logons on 25H2 machines talking to older Windows Server 2019 or 2022 domain controllers
  • Microsoft has not shipped an official fix yet; uninstalling the update restores normal function

What Windows 11 KB5124008 Actually Fixes

This update was supposed to clean up a messy August. It restores custom mouse cursor colors and styles, fixes Teams and Outlook crashes on Arm64 laptops, and improves audio redirection over Remote Desktop. It also patches the two zero-days mentioned above, which is the real reason you shouldn’t just skip it.

Not everything got fixed, though. The black-desktop bug from August’s preview update — where personalization settings and slideshow wallpapers fail to load — is still present for some 24H2 and 25H2 devices, and Microsoft says manually resetting the settings doesn’t help. We covered the original version of that bug in our KB5120998 cursor and wallpaper fix guide, and much of that advice still applies here.

One more wrinkle: some PCs will need an extra restart this month as Microsoft rotates Secure Boot certificates in the background. That’s expected behavior, not a bug, but it can look alarming if you weren’t warned about it.

The Always On VPN Bug No One Warned You About

If your company uses certificate-based Always On VPN through Routing and Remote Access Service and Network Policy Server, KB5124008 can stop it from connecting entirely. According to CybersecurityNews, the connection simply fails after the update installs, and uninstalling it restores service immediately — a strong sign this is a client-side regression rather than a network problem on your end.

Microsoft’s own support page still says it isn’t aware of any issues with this update, so don’t expect an acknowledgment yet. IT teams dealing with this are being told to pull rasphone.pbk data and RasClient event logs before opening a support case, since that’s what Microsoft will ask for anyway.

Domain Logons Are Failing on Windows 11 25H2

The second regression hits domain-joined 25H2 machines that authenticate against Windows Server 2019, or certain Server 2022 configurations. The machine secure channel between the PC and the domain controller fails to establish, so you get authentication errors even with the correct password. Cached credentials still work for a while, which is why some people don’t notice right away.

The cause is a stricter Netlogon secure channel negotiation level that KB5124008 now requires. Older domain controllers simply don’t support the higher negotiation level the patched client is asking for, so the handshake never completes.

Every KB5124008 Bug at a Glance

Issue Who’s Affected Status
Always On VPN fails to connect Certificate-based VPN via RRAS + NPS Unresolved; uninstall works
Domain logon fails 25H2 devices with older domain controllers Registry workaround available
Black desktop / lost personalization Some 24H2 and 25H2 devices Carried over from August; still open
Extra reboot mid-update Devices getting Secure Boot certificate rotation Expected, not a bug

The pattern here matters: three of these four problems trace back to changes Microsoft made in the name of security, whether that’s stricter VPN certificate checks or tighter Netlogon rules. Tightening security is usually the right call, but it clearly wasn’t tested against older domain controller versions still common in real networks.

Should You Install KB5124008 Anyway?

For most home users, yes. If you don’t connect to a corporate Always On VPN or a work domain, none of the regressions above apply to you, and skipping the update leaves two actively exploited vulnerabilities unpatched on your machine. That trade isn’t close.

If you’re on a managed work laptop, the calculus flips. IT admins should test KB5124008 against a representative set of domain controllers and VPN gateways before pushing it fleet-wide, and should have the registry workaround ready for any 25H2 machines that need to move faster. Our Windows 11 26H2 rollout guide has more on what’s changing under the hood this cycle if you’re planning updates around it.

Frequently Asked Questions

What is KB5124008?

KB5124008 is Microsoft’s September 2026 Patch Tuesday cumulative update for Windows 11 24H2 and 25H2, released on September 8, 2026. It fixes several bugs from August and patches two zero-day vulnerabilities.

Why did my VPN stop working after this update?

If you use certificate-based Always On VPN through RRAS and Network Policy Server, KB5124008 introduces a regression that prevents the connection from establishing. Uninstalling the update restores it until Microsoft ships a fix.

How do I fix domain logon failures after installing KB5124008?

Try setting the MachineIdentityIsolation registry value to 0 and running Test-ComputerSecureChannel -Repair. If that doesn’t resolve it, a full domain rejoin (leave, restart, rejoin) typically does.

Is the black desktop bug new in this update?

No. It first appeared in August’s preview update and carried over into KB5124008 unresolved. Microsoft hasn’t given a timeline for fixing it.

Should I uninstall KB5124008?

Only if you’re actively hit by the VPN or domain logon bug and need an immediate fix. For everyone else, the two patched zero-days make staying updated the safer choice.

Patch Tuesday updates are supposed to be the boring, safe kind of update, and this one mostly is — unless your PC happens to sit at the intersection of certificate-based VPN, an older domain controller, and a Windows 11 install that just wants to be difficult. Install it for the security fixes, keep the workarounds handy, and don’t be surprised if Microsoft needs another cumulative update before this one is actually finished.


Comments

Leave a Reply

Your email address will not be published. Required fields are marked *