Microsoft confirms: April 2026 security updates cause malfunctions in backup applications

Microsoft has confirmed that the April 2026 security updates are causing failures in third-party backup applications that use the psmounterex.sys driver. This issue, first reported by BleepinComputer last week, affects software that uses Volume Shadow Copy Service (VSS) snapshots and causes failures due to a VSS service timeout.

Among the affected software are products from Macrium (Reflect), Acronis (Cyber Protect Cloud), UrBackup Server, and NinjaOne Backup, operating on Windows 11, Windows Server, and Windows 10 devices.

Technical details and causes of the problem

Microsoft has updated its support documents to confirm that the April updates include a security change that adds psmounterex.sys to the company's list of blocked vulnerable drivers. This change aims to protect users from attacks exploiting a high-severity buffer overflow vulnerability (CVE-2023-43896), which allows attackers to escalate privileges or run arbitrary code.

Microsoft has advised affected users to update to the latest versions of their applications, which use newer drivers and include the necessary protections.

Behaviors observed on affected systems

On affected systems, where the vulnerable driver is blocked by the Windows Code Integrity application, IT administrators and users may observe the following behaviors:

  • Backup applications that depend on the kernel driver psmounterex.sys may fail to mount backup image files as virtual disks.
  • Attempts to explore or restore from a backup image may result in errors or timeouts.
  • Failures may be followed by error messages, such as "Backup failed because Microsoft VSS timed out during snapshot creation" or VSSEBAD_STATE.
  • The Event Viewer may display Code Integrity errors indicating that psmounterex.sys was blocked from loading.
  • Creating backups (full image backups) may still succeed, but image mounting operations will fail.

Microsoft's recommendations

"In the April 2026 Windows security update, we added the known vulnerable kernel driver psmounterex.sys to the Vulnerable Driver Blocklist. Backup applications that depend on this driver may experience failures when attempting to mount or manage disk images," Microsoft told BleepinComputer.

"We do not recommend uninstalling or pausing this update. Customers with an affected driver should install the latest versions of the applications and validate them against the driver blocklist to remain protected."

How to verify driver blocking

To verify if Microsoft's Vulnerable Driver Blocklist blocks a driver, interested customers can look for Event ID 3077 with Policy ID {D2BDA982-CCF6-4344-AC5B-0B44427B6816} in the Code Integrity operational log.

To do this, right-click on Start, select Event Viewer, go to 'Applications and Services Logs\Microsoft\Windows\CodeIntegrity\Operational' in the left pane, and look for Event ID 3077 in the central pane.

Other reported issues

Earlier this month, Microsoft warned that some Windows Server 2025 devices may also boot into BitLocker recovery mode, requiring users to enter the BitLocker key after installing the KB5082063 update.

Microsoft has also released out-of-band (OOB) updates to address issues affecting Windows Server systems, which have caused failures in installing updates and reboot loops after installing the April 2026 security updates.

Recommendations for backup administrators

For those managing backups, the upcoming webinar "From phishing to fallout: why MSPs must rethink both security and recovery" examines how both attacks and system failures can impact recovery and what organizations can do to improve resilience.

User comments

A user reported not experiencing issues with Terabyte Unlimited's Image for Windows, specifying they are not affiliated with them.

Impact on the MSP sector

The situation highlights critical challenges for Managed Service Providers (MSPs), forced to balance security and operational continuity. Experts emphasize how security updates, while essential, can create temporary vulnerabilities in backup systems. For MSPs managing multiple clients, managing such disruptions requires updated protocols and proactive communication with end users.

Temporary alternative solutions

Some administrators have reported success using alternative solutions such as local Volume Shadow Copy Service (VSS) or third-party snapshots while waiting for official patches. However, Microsoft strongly discourages such workarounds, as they may expose systems to unmitigated security risks.

Long-term consequences

Analysts predict this incident may accelerate the adoption of cloud-based backup solutions, less dependent on system drivers. Software providers are already reporting an increase in demand for hybrid solutions that combine local and cloud backups, with more flexible recovery options.

Recommendations for companies

Organizations should consider implementing:

  • Periodic backup testing on isolated environments before applying system updates
  • Validated alternative recovery plans
  • Continuous monitoring of security patches

Informative webinar

The upcoming webinar "From phishing to fallout: why MSPs must rethink both security and recovery" (May 12 and 14) will explore advanced strategies to improve operational resilience. Register here to learn more.

Security considerations

The vulnerability CVE-2023-43896, at the heart of these security measures, has been exploited in targeted attacks. Organizations must maintain high alert against potential exploits resulting from outdated system configurations.

Global scenario

This situation fits into a broader context of increasing cyberattacks exploiting third-party vulnerabilities. Technology companies are collaborating to improve vulnerability reporting and resolution processes, but end users must be prepared to manage transition periods during critical updates.

Editorial Note and Disclaimer

The guides and content published on GoYou are the result of independent research and analysis activities, for informational, educational, and in-depth purposes.

GoYou does not constitute a journalistic publication nor an editorial product pursuant to Law No. 62/2001 and does not provide real-time information.

The GoYou project does not provide professional, technical, legal, or financial advice and disclaims any liability for the improper use of the information published.

In the Crypto sector, every investment involves risks: readers are invited to always inform themselves independently before making any decision.