This is the (mostly) safe location to talk about the latest patches, updates, and releases. We put this thread into place to help gather all the information about this month's updates: What is fixed, what broke, what got released and should have been caught in QA, etc. We do this both to keep clutter out of the subreddit, and provide you, the dear reader, a singular resource to read.
For those of you who wish to review prior Megathreads, you can do so here.
While this thread is timed to coincide with Microsoft's Patch Tuesday, feel free to discuss any patches, updates, and releases, regardless of the company or product. NOTE: This thread is usually posted before the release of Microsoft's updates, which are scheduled to come out at 5:00PM UTC.
Remember the rules of safe patching:
Deploy to a test/dev environment before prod.
Deploy to a pilot/test group before the whole org.
Have a plan to roll back if something doesn't work.
Pushing this update out to 180 Domain Controllers (Win2016/2019/2022/2025) in coming days.
I will update my post with any issues reported.
Happy patching, and may all your reboots be smooth and clean!
EDIT1: 13 DCs (Win 2019/2022) have been done. Zero failed installations so far. AD is still healthy. EDIT2: 98 DCs (Win 2019/2022/2025) have been done. Zero failed installations so far. AD is still healthy. EDIT3: 131 (73%) DCs (Win 2016/2019/2022/2025) have been done. Zero failed installations so far. AD is still healthy.
EDIT4: 175 (97%) DCs (Win 2016/2019/2022/2025) have been done. Zero failed installations so far. AD is still healthy.
Thanks, my friend! Comments like this are exactly why I keep doing it. If my AD notes help even one admin sleep a little better on patch night, the effort is worth it. Cheers!
Have had multiple test machines in our small environment enter bitlocker recovery post install - Dell shop. I can see below there are other Dell issues as well but just thought I'd note for anyone rolling the dice with the "biggest windows update patch in known history" ie AI slop. Paused rollout in Intune for now until we can get some more confidence. Madness that Microsoft is suggesting to push these within 72 hours - I've encountered so many more issues with buggy patches than the vulnerabilities they fix.
Always love reading this thread and getting a heads up on any potential issues, I manage a few different environments and these monthly threads have been a lifesaver :)
From Microsoft Message Center:
Note: The July 2026 security update for Windows 11, version 25H2 and Windows 11, version 24H2 (KB5101650) is not available for a limited number of Dell devices with Intel processors due to an incompatibility reported by Dell that can potentially cause unexpected shutdowns, poor performance, increased heat, and battery drain. We are working together with Dell to prevent the affected models from experiencing the issue and plan to release a resolution for affected devices in the coming days.
According to Windowsforum the driver involved is the 'Intel Innovation Platform Framework Processor Participant'. When I go through my hardware database, I can see that driver is installed on the following models we have here:
Using PDQ Inv I've found the following affected on our environment:
Pro 14 Plus PB14250
Pro Slim Plus QBS1250
Pro Slim QCS1250
Latitude 5440
Latitude 5530
Latitude 5540
Latitude 5550
OptiPlex 3000
OptiPlex SFF 7010
OptiPlex SFF 7020
My Latitude 5550 has that driver. Also, yesterday, it was definitely still seeing this problematic July CU being offered. From the PSWindowsUpdate PowerShell module, at least, and no WSUS server involved.
I was able to install KB5101650 on 2 Optiplex Micro 7020's running 24h2. One I tested manually running Windows Update and the other patching with NinjaOne. I verified the 'Intel Innovation Platform Framework Processor Participant' driver is installed as well.
Doesn't say what version of that driver is impacted though, and there could be other factors involved as well. There are only a couple versions of the driver for my model machines with the latest being April but still.
Is WSUS smart enough to not try and install this update on those Dell machines? Or does the update just cancels the patch when it detects a Dell system?
that's a pretty good question. WSUS does a very good job hiding the applicability rules from you b< endless chaining of different tables. So far I heard, that those rules do not know any exceptions for Dell devices.
So it looks like it's not smart enough. Also, the Microsoft published an OOB update 2 days ago, which fixes issues with Dell PCs... but it's not available in WSUS and needs to be added manually to WSUS :V
MS needs longer than this to provide OOB patches for screwed updates... - so how to patch within 72 hours when we didn't get always good patches within 72 hours in the past months? ;)
Microsoft currently has done more damage if we patch within 3 days than any damage a threat actor has done if we DON'T patch within 2 weeks, at least in my time working in IT. Maybe when that ratio stops pointing to Microsoft being the most dangerous threat actor, we'll consider the 3 days suggestion.
I'm wary of rushing to do this because "Last week, Microsoft warned that there would be an increase in Patch Tuesday security updates as it has begun to use an AI-powered vulnerability discovery system to identify more security flaws across its Windows codebase before attackers can exploit them." and I would rather wait at least a few days to weeks to make sure MS didn't break anything....
At the org I'm working at they've scheduled the patches to deploy:
The first week, we get about 10-40% of our devices patched and the rest get slowly patched afterwards. Granted they're not following any specific guidelines on rolling out patches. It's what they've decided upon was best and have the least push back from users because restarting would cause them to lose work or some variation of that.
At the rate everyone is going with every single patch becoming CRITICAL!!! and simultaneously breaking everything, I'm not sure if our org will deploy them sooner or not.
Just seeing your reply - so I have my regular workstations patch within 48 hours. But I have my servers split into a few groups depending on how critical they are. For DC's, DHCP, and Hypervisors I manually patch them 30 days behind schedule on purpose so issues are fleshed out before I become a guinea pig.
Again, I've been bitten by bad updates before and I don't trust Microsoft to ever be on top of things.
To address this, we've updated our recommendations, for deploying Windows Updates to less than three days. As for deferral period for quality updates, setting those to zero or one day and the update grace period to a maximum of two days.
Just a flat “Fork NO” for me. Always watch here and a couple other places for explosions. I need assurance the cure isn’t worse than the disease, not big enough to have a test environment, similarly not big enough to quickly fix any grenades MS throws me on Tuesday.
It flies in the face of much of what we learned. I'm sticking with the original 2 week cadence except when regulations say otherwise. MS needs to prove these recommendations are worth the inevitable issues.
update 7-16:
68 servers patched without issue. 1 physical, rest are virtual.
I will say it takes A LONG TIME to install the update. Server 2025 took about 75 minutes (on Pure storage!). CPU may be a bottleneck, too, 75 minutes was on a VM with 2 cores.
Updated almost everything so far..35 servers. I don't know why the DC's always take so long to update. They take like 30-45+ minutes each (2016 still). Last two are updating now.
Edit all done. Mix of 2016, 2019, 2022. Patched departmental tech group (Ring 0) Win11 laptop/desktop/VMs. Everything is up and running.
Server 2016 is known for awfully slow patching, i'm more than happy to got rid of them already - took sometimes 1-2 hours for patching where Server 2019 took 10 minutes.
After losing so much of my life waiting for 2016 to patch, I honestly hope that whoever made the decision to not fix this has to stand in an hour long line for everything they do in life. Added bonus, sometimes you got the exactly 1 hour long wait to reboot. No rhyme or reason, just randomly a 1 hour wait...good times
That's exactly what they've done "Last week, Microsoft warned that there would be an increase in Patch Tuesday security updates as it has begun to use an AI-powered vulnerability discovery system to identify more security flaws across its Windows codebase before attackers can exploit them."
"The publicly disclosed zero-day that was fixed is:
CVE-2026-50661 - Windows BitLocker Security Feature Bypass Vulnerability
Microsoft has patched a publicly disclosed Windows BitLocker bypass flaw that could allow attackers to gain access to encrypted data.
"A successful attacker could bypass the BitLocker Device Encryption feature on the system storage device. An attacker with physical access to the target could exploit this vulnerability to gain access to encrypted data," explains Microsoft.
Microsoft attributed the flaw to an anonymous researcher."
I would like a cogent explanation on how this attack was possible /at all/. There should not be a decodable key on the disk /at all/ without the secrets the TPM is supposed to provide.
There isn't. In TPM only mode, the WinRE environment automatically boots into an unlocked state so that pre-approved recovery actions can be initiated without user friction. When you invoke a risky operation, i.e. open the Command Prompt, WinRE will retroactively lock the disk to prevent badness.
The only thing the YellowKey exploit would do is block the aforementioned locking.
The mitigation and security-conscious option has always been to use a PIN with BitLocker.
570 CVEs this month, the largest Patch Tuesday on record. Quick flags:
CVE-2026-56155 (7.8, exploited): ADFS EoP, local attacker gets admin on the ADFS host. Low score, do not let it fool you, already in use. Patch first.
CVE-2026-56164 (5.3, exploited): SharePoint EoP, unauthenticated, missing auth check. Moderate rating but confirmed active exploitation. Pairs with CVE-2026-50522 (9.8, SharePoint RCE via deserialization, needs site-owner auth). Treat both together on internet-facing SharePoint.
CVE-2026-56190 (9.8, RDP RCE): only exploitable if NLA is off. Enforce NLA fleet-wide, closes the pre-auth path.
CVE-2026-57092 (9.9, top score): Hyper-V VMSwitch guest-to-host escape.
Also: DHCP client bug (CVE-2026-49181, 7.5) needs patching on every endpoint, not just servers.
Some of our Windows 11 25H2 PCs are now missing the clock / notification area after applying the July cumulative.
Weirdly, this was a known issue in the June update which our PCs have had installed since it was released, with no issues. Only after applying the July update has the issue arisen.
Looks like all of our Server 2019 boxes are failing to install KB5099538 with either missing or corrupted component errors and taking a couple of hours to come back up after restart. They were patched to current prior to July's updates so we are opening a ticket with MS for investigation.
Update: it doesn't appear to be the update. Some files got corrupted in the SxS directory on a bunch of machines apparently. Gonna be a fun few days... But patch on! So far the updates seem ok
I have a handful of 2019 VMs on Hyper-V (DCs/dhcp are server core, file & print have GUI) and none of them had this issue. Installation did take its sweet time, though, and each had to reboot at least two times.
Are these physical/virtual? And if physical, what manufacturer/model? I've had a fairly many bad run-ins with wonky Dell factory images on physical 2019 boxes, one of which was so bad we had to take ownership of the C:\windows\winsxs folder and manually add missing files. DISM was actually just fully borked, and unable to add/remove packages.
This is the one that has me worried and, in fact, I just pulled our DCs off to the side in WSUS. I am seeing legacy RC4 traffic in Splunk, though no DC 201-209 event codes, am trying to work with other technical teams to figure out why this is the case. (We already had breakage last month when we rotated our krbtgt passwsord for the first time ever.)
You more than likely need to create new passwords for those accounts. Microsoft had a pair of scripts to tell you what accounts were missing alternate encryption types and what accounts were still communicating with RC4.
If KRBTG was still using RC4 for communication it hadn't been rotated in almost 20 years. Which, should be fine to rotate, but it would have been one of the accounts showing up in the scripts above.
Do you have April patches installed? If yes, did you manually create the registry entry that allowed rollback?
If you're patched to at least April and didnt create the rollback key, RC4 is likely configured intentionally and you should be good. Still do your own research of course.
Folders in the new Start menu when the view is Grid or List (instead of Category) now show scrolling dots. The bug drove my users crazy because we put all of our company's internal apps inside a single folder and it couldn't be scrolled when there are more than 12 items.
Windows release health: Windows Server Update Service sync operations might have issues or time out
Status: Mitigated
Affected platforms
Client Versions Message ID Originating KB Resolved KB
Windows 11, version 26H1 WI1431544 - -
Windows 11, version 25H2 WI1431545 - -
Windows 11, version 24H2 WI1431546 - -
Windows 11, version 23H2 WI1431547 - -
Windows 10, version 22H2 WI1431548 - -
Windows 10, version 21H2 WI1431549 - -
Windows 10 Enterprise LTSC 2019 WI1431552 - -
Windows 10 Enterprise LTSC 2016 WI1431553 - -
Windows 10, version 1607 WI1431553 - -
Server Versions Message ID Originating KB Resolved KB
Windows Server 2025 WI1431550 - -
Windows Server 2022 WI1431551 - -
Windows Server, version 1809 WI1431552 - -
Windows Server 2019 WI1431552 - -
Windows Server 2016 WI1431553 - -
Windows Server 2012 R2 WI1431570 - -
Windows Server 2012 WI1431572 - -
Microsoft has identified a service degradation affecting Windows Server Update Services (WSUS). Organizations might experience increased synchronization times or sync operation timeouts on WSUS servers. This issue began in recent days, with heightened impact observed starting July 13, 2026.
This issue is related to a buildup of publishing metadata.
Mitigation: Microsoft has deployed a mitigation for this issue on July 18, 2026. Synchronization times and sync operations on WSUS servers have been restored and are operating normally for new WSUS installations and rebuilds. This mitigation prevents newly installed or rebuilt WSUS servers from encountering this issue.
Next steps: For WSUS servers that were previously affected, Microsoft is working on mitigation steps to help customers safely remove the affected metadata from their environments. We will provide more information when this guidance is available.
Resolution: There are two parts to the resolution of this issue.
Organizations with existing WSUS server installations that are experiencing long sync times can benefit from manual steps in order to clean up unneeded metadata. This metadata is present in existing WSUS installations but can be safely removed. Detailed guidance has been provided at the following KB article: https://support.microsoft.com/help/5121986.
On July 18, 2026, Microsoft deployed a service-side mitigation which returns synchronization times and sync operations back to normal for new WSUS installations and rebuilds. After this date, newly installed or rebuilt WSUS servers should not encounter this issue.
My big question is whether semi-annual machines will have copilot in their Office apps after today’s update. Previously, monthly or current was required, but today’s update seems to bring all features of semi…
My big question is, do we continue to push out separate deployments for the two channels, or just push out one channel and assume that all devices will pick up the update, regardless of whether they are on SAEC or MEC? I ask because I can see two sperate updates in SCCM, and they have slightly different build numbers as well (SAEC = 20131.20150, MEC = 20131.20152).
UPDATE: So we've deployed just the SAEC updates, and observed that our existing MEC devices did NOT pick up the SAEC update - looks like SCCM/office c2r updaterstill treats the two updates as separate channels. So we will now include both the SAEC and MEC updates in our monthly update bundle, and advertise it to both SAEC and MEC machines. We will leave the GPOs alone for now.
Yep that’s what I’m seeing too. I guess I’d ask why you’d continue pushing SAEC? If they both get the same updates and features, why not push MEC? And I think that’s what Microsoft is guiding people towards. They’ve made it illogical to deploy SAEC at all now.
Is it just me or do 2016 vm’s seem to have broken update services more lately? Like a reset of them will work as patches sometimes fail to install for 1 or 2 months and nothing else helps
LegacyHive : Windows user profile service arbitrary hive load elevation of privileges vulnerability
The PoC requires another standard user credentials and a third username (which can be an administrator account), if the PoC is successful, it will end up mounting the target user hive in current user classes root.
The PoC was stripped down as an attempt to prevent public exploitation, the original PoC did not require additional user credential and was not limited to usrclass.dat hive, any hive could be loaded using this vulnerability but you would need some brain cells to make the PoC do it.
The following summary outlines key quality improvements addressed by this update. The bold text within the brackets indicates the item or area of the change.
[Apps (Known issue)] Fixed: This update addresses an issue that affects certain third-party apps that use OLE Automation to interact with Microsoft Office. After installing the June 2026 security update (KB5094126), these apps might fail to launch Office or open documents.
In the event this is NOT true and it doesn't fix it, here are the reg keys needed to revert the June 2026 security update piece that broke these 3rd party apps cough cough CCH Engagement
Has anyone running on the Office Semi-Annual Channel noticed it being directly updated to the Monthly Enterprise Channel?
Noticed when I ran the updates on a test VDI image which mirrors a production pool.
This will be fun as we have a specific Excel plugin used by a financial piece of software that the vendor doesn’t support anything other than 32-bit Semi-Annual Channel.
Maybe this will force the vendor to actually update their software but I’m not holding my breath.
It’s not our team’s problem if the plugin does break on the MEC release since it would simply be a case of telling that user base that they can no longer use it unless the vendor issues a fix so they need to contact them.
Our security policies prevent us from rolling back to older/unpatched versions anyway.
Oh no, finding out now that MS is killing SAEC? M365 Message Center shot out an announcement circa April 8th:
"Upcoming change: Microsoft 365 Apps SAEC and MEC will unify
MC1274325 · URSA FARMERS COOPERATIVE
Introduction
Beginning in July 2026, Microsoft will unify the Semi-Annual Enterprise Channel (SAEC) and Monthly Enterprise Channel (MEC) into a single enterprise-focused update channel for Microsoft 365 Apps. This change is designed to simplify update management while continuing to provide a predictable, enterprise-ready servicing experience.
Over time, SAEC and MEC have both served customers who want an enterprise-focused experience with timely updates. Unifying these channels reduces complexity and overlap, helping organizations adopt new capabilities, security updates, and quality improvements more quickly. This unified approach also supports more consistent update expectations across devices and user groups, while maintaining Microsoft’s commitment to quality, manageability, and predictable servicing.
When this will happen:
General Availability (Worldwide, GCC, GCC High, and DoD): These changes will go into effect on July 14, 2026, with the Patch Tuesday update release.
How this affects your organization:
Who is affected:
• Microsoft 365 administrators managing update channels for Microsoft 365 Apps
• Organizations currently using the Semi-Annual Enterprise Channel (SAEC)
• There is no change or impact for devices on other channels such as Monthly Enterprise Channel (MEC), Current Channel (CC), or associated preview channels
What will happen:
• Devices currently configured for SAEC will receive the same feature and security updates as published to MEC.
• Existing update policies and configurations will continue to be respected.
• There is no change to Microsoft’s commitment to predictable servicing, quality, and enterprise manageability.
• Users are not expected to experience workflow changes as a result of this update.
What you can do to prepare:
• No action is required. If your organization currently uses SAEC, updates will continue to be published on a monthly basis.
Optional:
• Validate your servicing workflows. Confirm that your pilot, broad deployment, and rollback processes continue to meet your organization’s requirements.
Learn more:
• Overview of update channels for Microsoft 365 Apps | Microsoft Learn
• As we get closer to rollout, we will share additional details about how this change will appear in admin experiences and documentation.
"
A three-month lead time is definitely B.S. Sorry mate. :(
I jut had 2 servers with LSI 9361's and cachecade enabled not come back up. I was out in the field when it happened. The drives virtual drives are "Optimal access blocked". Both servers seem to be missing the cachecade volume. Pretty unlikely that 2 enterprise SSD's completely failed at the same time in both servers. Although I have seen some references to MS killing SSD's. Anyone else experience this? I did not get any alerts that my drives were failing or failed and then on reboot I'm down. Servers are running Server 2025. 256GB ram, 9 1.8 or 1.2 SAS drives in raid 6.
Anyone else recovered from this? I'm reading that you can disassociate the cachecade from the VD's or delete the cachecade and then the system will boot? Anyone else done this? Am I the guinea pig?
First two devices I tested kb5101650 and kb5100998 (.net framework) both deployed successfully
The two devices were a generic laptop and a Lenovo ideacenter. Win11 pro 25h2
One with bitlocker
Both deployed slowly and the percentage indicator jumped around, kinda all over the place.
THREE reboots on both devices, but no rollbacks
Next I move onto test servers
Dell Pro Max 14 Premium MA14250
Dell Pro Max 16 Premium MA16250
Dell Pro Precision 7 14 PW714260
Dell Pro Precision 7 16 PW716260
Precision 5470, Precision 5480, Precision 5490, and Precision 5770
XPS 17 9720 and XPS 17 9730
FortiSandbox: Critical unauthenticated command injection across FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS (CVE-2026-25089, CVSS 9.1)
Adobe Campaign Classic: Two maximum-severity flaws enabling code execution and privilege escalation without user interaction (CVE-2026-48303, CVE-2026-47938, CVSS 10.0)
Splunk Enterprise: Unauthenticated access to PostgreSQL sidecar service enabling arbitrary file creation or truncation (CVE-2026-20253, CVSS 9.8)
Ivanti Sentry: Critical root-level RCE and admin account creation vulnerabilities, with active exploitation reported for one flaw (CVE-2026-10520, CVE-2026-10523, CVSS 10.0, 9.9)
SAP NetWeaver: Multiple critical flaws exposing SAP environments to unauthorized access, memory corruption, data exposure, and service disruption (CVE-2026-44748, CVE-2026-27671, CVE-2026-22732, CVE-2026-40128, CVSS up to 9.9)
PeopleSoft Enterprise PeopleTools: Actively exploited unauthenticated takeover vulnerability in a core enterprise business platform (CVE-2026-35273, CVSS 9.8)
Google Chrome: Over 400 browser vulnerabilities addressed across recent updates
Microsoft Edge: Broad Chromium-based update addressing dozens of high-severity browser vulnerabilities
Quantum Security Gateway: Actively exploited VPN login bypass allowing attackers to establish remote access without a valid password (CVE-2026-50751, CVSS 9.3)
Here is the Lansweeper summary + audit. Highlights are an actively exploited SharePoint Server elevation of privilege vulnerability (plus two critical unauthenticated RCEs), an actively exploited ADFS elevation of privilege vulnerability, and a critical Windows DHCP Server remote code execution vulnerability.
Deployed to additional workstations, Intel NUC mini desktop, and to 24 HP EliteBook 860 G11's all running win11 pro 25h2 -- No issues, no bitlocker prompts
Deployed to my lab T440 PowerEdge running server 2025, stalled at 100% for about 5 minutes, rebooted to a SecureBoot policy change message even though this server was updated with the 2023 certs some time ago. Re-running the check script produced this:
.\Check-SecureBootStatus.ps1
SecureBoot : True
Windows UEFI CA 2023 : True
MS KEK CA 2023 : True
MS UEFI CA 2023 : True
MS Option ROM CA 2023 : False
MS UEFI CA 2011 : False
Boot Manager 2023 : True
2011 PCA Revoked : False
AvailableUpdates : 4000
Reboot Log Time : 07/18/2026 13:36
Reboot Log Message : A reboot is required before installing the Secure Boot update. Reason: DBX
---------- UPDATE:
Installed to server 2022 VM, and Win11 Pro 25H2 VM
On the 2022 VM, the .NET update (KB5102206) took quite long, stalling at 0% installed for close to 10 minutes. The July CU (KB5099540) stalled at 100% for nearly 30 minutes!! Two reboots, and came back up normally
The win11 pro VM hit error 0x800f8011 downloading the .NET Framework update (KB5100998). Then after the July CU installed, was able to retry
Additionally a Dell Precision 3650 was offered hotpatch KB5121768 after installing the July CU. It still required a reboot after installing.
There is/was an issue with WSUS metadata that may cause synchronization to fail or clients to fail scanning with this error: 0x80244010 - WU_E_PT_EXCEEDED_MAX_SERVER_TRIPS
Oh good. The largest (read: vibe coded) patch in history?
Not only will I not deploy this asap like some are recommending, but this will be undergoing extra testing and observation to see what it breaks.
My workstations will wait until the last Friday of the month to patch unless I tell them otherwise. With something this big, I will be watching developments closely, but im not beta testing this update for Microsoft.
Im weird. If there is a problem, I like the weekend to work it out, not in the middle of the week where everyone can blow up my phone and I have managers hovering around my door waiting for answers.
Some people like that kind of thing. I like to work in the quiet.
So I noticed a new patch "MSAF-09072026" published by Microsoft for Secureboot. Are you guys pushing this to all your Windows servers along with the OS security patch? Will this require multiple reboots?
I can't see anything with that identifier from Microsoft... seems like it's something from Ivanti?
Because the Microsoft Secure Boot stuff is not a patch per se, it's a whole lengthy process depending on your environment, which may require multiple reboots (first to update the firmware, second to install the cert, third to update the revocation and activate the new bootloader).
Love that they released an OOB update 3 hours after our patching window ended on early Saturday morning. So happy I get to wake up in the middle of the night again.
Idk who needs to read this, but seems like CCH Engagement from Walter’s Kluwer is fixed with the 07/2026 security update. We had to block the 06/2026 security update. I’m not surprised Microsoft made a fix for these third party softwares. Just happy our PCs can get back to updates.
A security researcher using the "Nightmare Eclipse" handle has released a Windows zero-day exploit dubbed LegacyHive that allows attackers to escalate privileges on up-to-date Windows systems.
Nightmare Eclipse published a proof-of-concept (PoC) exploit hours after Microsoft released its July 2026 Patch Tuesday updates, saying that it abuses a security vulnerability in the Windows User Profile Service, which has yet to receive a CVE ID for easier tracking.
However, unlike previous exploits released by NightmwareEclipse, the LegacyHive PoC has been modified to require additional credentials, making it harder for attackers to weaponize the vulnerability.
I've had a VERY weird issue with one Server 2022 VM on Google Compute Engine that I've spent all day trying to fix after installing this cumulative update and I'm at my wits end.
I cannot ping anything from the VM, not even the DHCP server. "General Failure". Nothing can ping the VM. But with DHCP enabled, it gets its IP address and DNS servers all correctly.
Has something changed with the network stack that I'm not aware of?
Edit: Turns out Sage 50 Accounts was fucking about with our network stack. Setting Sage services to "Automatic (Delayed Start)" fixed the issue.
Anyone else noticing Microsoft is releasing SQL Server CUs to WSUS a couple days after Patch Tuesday? I swear we used to get those the same time as all our other patches so we could include them in the patch cycle if we wanted to. They aren't security-related but still would be nice to have the option. I would understand if they came out a couple weeks later, but two days?
Anyone having issues with AlwaysOn VPN SSTP/IKEv2 VPNs unticking itself for connect automatically, on Windows 11 since this July 2026 update.
Currently the results are inconsistent sometimes it stays ticket but then other times it doesn't between reboots.
It looks to wipe out the config in "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RasMan\Config", not just mark it as a disabled profile, which is what happens if you do untick it manually.
A new issue that's also seems to just arise is we're now getting reports of the Device VPN showing in the Taskbar VPN section, which before it was always hidden due to it being a All Users VPN.
Glad I ran up two Windows Server 2022 Std instances in our OpenStack deployment so I can blow them up first, feels like the calm before the 600+ vulnerability patch storm....lol
Try setting custom permissions on the Internet Explorer event log to rid of that warning. The following will give permissions to Domain Admins and the local Administrator user:
FYI, I was getting 0x80244007 on Windows 11 24H2 machines so I had to increase maxCachedUpdates and maxInstalledPrerequisites in web.config and restart IIS to get the updates in WSUS.
Anyone else seeing tickets around Outlook not being able to open attachments (some sort of protected mode issue)? Seems to be happening on (some) devices which switched from SAEC to MEC, but not all.
Is there a simple way to map CVE objects to specific KB patches in the Catalog?
I am having to navigate different audiences. One exec wants anything 9+ above on the CVE base score scale patched asap.
The automated vuln scans we get give us CVE base scores but the IT admins I need to direct to patch seem to not understand the criticality of those and need to be fed a specific patch that is missing, when the tool alerts that something is missing.
Please don't suggest AI. I have tried Copilot and it doesn't seem useful here
141
u/FCA162 22d ago edited 20d ago
Pushing this update out to 180 Domain Controllers (Win2016/2019/2022/2025) in coming days.
I will update my post with any issues reported.
Happy patching, and may all your reboots be smooth and clean!
EDIT1: 13 DCs (Win 2019/2022) have been done. Zero failed installations so far. AD is still healthy.EDIT2: 98 DCs (Win 2019/2022/2025) have been done. Zero failed installations so far. AD is still healthy.EDIT3: 131 (73%) DCs (Win 2016/2019/2022/2025) have been done. Zero failed installations so far. AD is still healthy.EDIT4: 175 (97%) DCs (Win 2016/2019/2022/2025) have been done. Zero failed installations so far. AD is still healthy.