Server 2025

Winsage
September 19, 2026
Microsoft resolved an issue that caused misleading alerts indicating that Defender Antivirus was disabled after recent updates. This fix was confirmed in an update to the Windows release health dashboard and was implemented in the Microsoft Defender Antivirus update (version 4.18.26080.4) rolled out on September 17. The bug, acknowledged by Microsoft in late August, affected users in the Release Preview Channel of the Windows Insider program since at least June and impacted all supported versions of Windows clients and servers. Users received erroneous notifications in the Windows Security app prompting them to activate Microsoft Defender Antivirus, despite it functioning correctly. Misleading alerts could appear upon Windows startup and intermittently thereafter, even when notification settings were disabled.
Winsage
September 16, 2026
Organizations using Windows Server 2022 will lose mainstream support on October 13, 2026, although security updates will continue through extended support until October 2031. Customers are encouraged to plan for an upgrade to Windows Server 2025 to avoid potential security vulnerabilities and complications in future migrations. Microsoft recommends early evaluation and testing of Windows Server 2025 to ensure compatibility and smooth transition. Additionally, support for the Azure Edition’s hotpatching capability has been extended to October 2027, providing some customers more time to strategize their migration. However, remaining on Windows Server 2022 means missing out on new features and enhancements.
Winsage
September 16, 2026
Microsoft has announced that mainstream support for Windows Server 2022 will end next month, transitioning to an extended support phase that lasts until October 2031. Windows Server 2022 was released in September 2021 and will receive its final mainstream support update on October 13, 2026. After this date, it will continue to receive essential security updates at no extra cost until October 14, 2031. Hotpatching for Windows Server 2022 will be available until October 2027 for Datacenter: Azure Edition. Microsoft encourages administrators to upgrade to Windows Server 2025, which began rolling out to Windows Insiders in January 2024 and is expected to be generally available by November 2024. Windows Server 2025 will have mainstream support until November 13, 2029, followed by five years of extended support until November 14, 2034. A 180-day trial of Windows Server 2025 is available through the Microsoft Evaluation Center.
Winsage
September 10, 2026
Microsoft's Patch Tuesday on September 8, 2026, addressed two critical Windows privilege escalation vulnerabilities: CVE-2026-85880 and CVE-2026-81963, both with a CVSS score of 7.8. CVE-2026-85880 is a heap-based buffer overflow in the Windows Advanced Local Procedure Call (ALPC), allowing attackers with low-privilege local access to escalate privileges to SYSTEM. CVE-2026-81963 involves improper link resolution in the Windows Update Stack, enabling similar privilege escalation. Both vulnerabilities require no user interaction and have been actively exploited prior to the patch release. CISA added them to its Known Exploited Vulnerabilities catalog on September 8, 2026, with a remediation deadline of September 22 for U.S. federal agencies. CVE-2026-85880 affects various Windows 10 and Server versions but excludes Windows 11 and Windows Server 2025. CVE-2026-81963 impacts newer Windows platforms, including Windows 11 and Windows Server 2025. Microsoft released security updates for both vulnerabilities on September 8, 2026, and organizations are advised to prioritize these updates. Security teams should monitor for signs of privilege escalation and unusual SYSTEM-level activities related to these vulnerabilities.
Winsage
September 9, 2026
On September 8, 2026, Microsoft disclosed a security vulnerability identified as CVE-2026-69449, related to a heap-based buffer overflow in the Windows BitLocker component, allowing authorized attackers to execute code on compromised machines. The vulnerability is classified as CWE-122, and is assessed as “Exploitation Less Likely.” It affects Windows 10, Windows 11, and Windows Server versions from 2012 to 2025. The fixes are included in cumulative updates KB5124008, KB5124012, KB5122878, and KB5122871. No public disclosure or observed exploitation occurred before the patch's release. The flaw allows for remote code execution through in-network attacks, primarily posing a risk to insiders. Affected systems include various versions of Windows 10, Windows 11, and Windows Server, applicable to both x64 and ARM64 architectures. Administrators should verify installed build numbers to ensure updates have been applied. The advisory does not specify which BitLocker code path is affected or the nature of the input that reaches the vulnerable buffer.
Search