Windows updates issue

Seif Osman 0 Reputation points
2026-09-16T13:15:06.1266667+00:00

Hello,

We are experiencing an issue with the SaaS VPN connection after installing the Windows updates KB5124008 and KB5126052.

The issue is reproducible across multiple devices, not just a single device.

Issue Description:

  • When the affected devices install KB5124008 and KB5126052, the SaaS VPN stops working.
  • The VPN was working normally before installing these updates.
  • When we uninstall both updates (KB5124008 and KB5126052) and restart the device, the SaaS VPN works normally again.
  • We have reproduced the same behavior on several different devices, which makes us suspect that one of these updates, or the combination of both, may be causing a compatibility or networking issue with the SaaS VPN.

Steps to Reproduce:

  1. Install Windows updates KB5124008 and KB5126052.
  2. Restart the device.
  3. Try to connect to the SaaS VPN.
  4. The VPN does not work.
  5. Uninstall KB5124008 and KB5126052.
  6. Uninstall Wan ports from device manager
  7. Restart the device.
  8. Re-install SaaS VPN 
  9. The SaaS VPN works normally again.

Could you please investigate whether there are any known issues or compatibility problems related to KB5124008 and KB5126052, particularly with VPN/network connectivity?

We can provide additional information such as Windows version/build, VPN logs, screenshots, and affected device details if required.

Windows for business | Windows Client for IT Pros | User experience | Other
0 comments No comments

1 answer

Sort by: Newest
  1. Tracy Le 12,245 Reputation points Independent Advisor
    2026-09-16T14:57:11.04+00:00

    Hello Seif Osman,

    Windows cumulative updates regularly introduce security enforcements across the core networking stack, such as Schannel cipher adjustments, IPsec modifications, or strict certificate validation in RasMan. When third-party SaaS VPN clients use legacy virtual miniport drivers or deprecated cryptographic suites, the connection process fails or drops immediately after the host initializes the updated networking components.

    To maintain production stability while preserving baseline protection, you should defer KB5124008 and KB5126052 temporarily using your endpoint management policy or WSUS targeting group. Concurrently, reach out to your SaaS VPN vendor to acquire their latest client build compiled for the updated Windows kernel networking binaries, or verify if their tunnel protocol requires an updated intermediate CA certificate or updated tap adapter drivers.

    Please also examine the Event Viewer under Applications and Services Logs, Microsoft, Windows, RemoteAccess-RemoteAccessServer or the SaaS VPN diagnostic logs to pinpoint the exact failure code. If this guidance helps clarify the path forward and manage the rollout, please accept the answer.

    Tracy Le.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.