Microsoft confirms April Windows updates cause backup failures
Update backup applications to versions that use newer drivers; verify Event ID 3077 to confirm blocklist; do not uninstall April updates.
Install the latest backup application versions that use updated drivers; verify Event ID 3077 to confirm blocklist; do not uninstall the April 2026 security updates.
Summary
Microsoft has confirmed that the April 2026 security updates add the psmounterex.sys driver to the Vulnerable Driver Blocklist, causing backup applications that rely on this kernel driver to fail when mounting VSS snapshots. The affected backup tools include Macrium Reflect, Acronis Cyber Protect Cloud, UrBackup Server, and NinjaOne Backup on Windows 10, Windows 11, and Windows Server. The failure manifests as timeouts or error messages such as "The backup has failed because Microsoft VSS has timed out during the snapshot creation" or VSS_E_BAD_STATE. Microsoft advises users not to uninstall the April updates and to update backup applications to newer versions that use updated drivers. The advisory also notes that some Windows Server 2025 devices may boot into BitLocker recovery mode after installing KB5082063. The issue is not a security vulnerability but a compatibility problem caused by driver blocklisting. Backup administrators should verify Event ID 3077 in the Code Integrity Operational log to confirm that psmounterex.sys was blocked.
The blocklist change was introduced to mitigate a high‑severity buffer overflow vulnerability, CVE‑2023‑43896, that could allow privilege escalation. However, the unintended side effect is widespread backup failures. The advisory recommends updating backup software rather than disabling the security update. The impact is significant for enterprises that rely on third‑party backup solutions for data protection.
Organizations should apply the latest backup application versions, monitor for blocklist events, and avoid removing the April security updates to maintain protection against the underlying vulnerability.
Key changes
- April 2026 updates add psmounterex.sys to the Vulnerable Driver Blocklist
- Backup apps using that driver fail to mount VSS snapshots, causing timeouts or VSS_E_BAD_STATE errors
- Affected tools include Macrium Reflect, Acronis Cyber Protect Cloud, UrBackup Server, and NinjaOne Backup
- Microsoft advises against uninstalling the April updates and recommends updating backup apps to newer versions
- Event ID 3077 indicates the driver was blocked by Code Integrity
- Some Windows Server 2025 devices may boot into BitLocker recovery mode after KB5082063
- The blocklist change was to mitigate CVE‑2023‑43896, a high‑severity buffer overflow
- Backup administrators should apply the latest backup app versions and monitor for blocklist events