VulnerabilitiesHIGH

Windows 11 - Emergency Update Fixes Critical Sign-In Bug

CSCyber Security News
Windows 11KB5085516sign-in bugMicrosoft accountPatch Tuesday
🎯

Basically, Microsoft fixed a problem that stopped people from signing into their accounts on Windows 11.

Quick Summary

Microsoft released an emergency update for Windows 11 to fix a critical sign-in bug affecting users. This impacts those relying on Microsoft accounts for essential services. Users should ensure their systems are updated to avoid disruptions.

What Happened

On March 21, 2026, Microsoft issued an emergency out-of-band (OOB) update for Windows 11, identified as KB5085516. This update addresses a critical sign-in bug that emerged after the March 2026 Patch Tuesday release. Users who installed the cumulative update KB5079473 found themselves unable to authenticate into applications using their Microsoft accounts. Despite having an active internet connection, many received a misleading “no Internet” error during the sign-in process.

This issue primarily affects consumer users and small businesses that rely on Microsoft accounts for accessing essential tools like Microsoft Teams Free and OneDrive. Organizations using Microsoft Entra ID for app authentication are not impacted, which highlights the bug's significant disruption for personal account users.

Who's Affected

The sign-in failure affects Windows 11 versions 25H2 and 24H2. Users who installed the March cumulative update are at risk. This problem is particularly concerning for individuals and small businesses that depend on Microsoft services for daily operations. The inability to sign in can halt productivity and access to critical applications, making this a pressing issue.

Microsoft's emergency update aims to restore functionality and ensure users can access their accounts without further hindrance. The update is automatically pushed to devices that previously installed the problematic update, ensuring a swift resolution for most users.

What Data Was Exposed

While the sign-in bug does not expose personal data, it does block access to Microsoft services, which can be detrimental for users relying on these services for their work. The update includes all previous fixes and improvements from earlier releases, ensuring that users benefit from enhanced security and stability.

Additionally, the update incorporates refreshed AI components, enhancing features such as intelligent search and content analysis. This reflects Microsoft's ongoing commitment to integrating AI into the Windows experience, even amidst addressing critical bugs.

What You Should Do

If you are a Windows 11 user, ensure your system is updated to the latest version. For those with automatic updates enabled, KB5085516 will be installed without any manual intervention. If you have disabled automatic updates, navigate to Settings > Windows Update and select Download & install to apply the fix manually.

For IT administrators managing enterprise environments, utilize the expedited update workflows available through Microsoft Intune or Windows Autopatch. Microsoft has provided guidance to facilitate rapid deployment without disrupting standard maintenance windows. Keeping your system updated is crucial for maintaining security and functionality.

🔒 Pro insight: The rapid deployment of KB5085516 underscores the importance of timely updates in mitigating user disruptions caused by critical vulnerabilities.

Original article from

Cyber Security News · Guru Baran

Read Full Article

Related Pings

HIGHVulnerabilities

Vulnerabilities - Microsoft Update Fixes Sign-In Issues

Microsoft has launched an emergency update to resolve sign-in issues across its apps. Users faced errors despite being online. This fix is essential for restoring access to Microsoft services.

BleepingComputer·
CRITICALVulnerabilities

CVE-2025-32975 Exploited - Critical Flaw in Quest KACE SMA

Hackers are exploiting a critical flaw in Quest KACE SMA systems. This vulnerability allows unauthorized access to administrative accounts. Organizations must apply patches to avoid severe risks.

The Hacker News·
CRITICALVulnerabilities

Critical Vulnerability - Oracle Releases Emergency Patch Now

Oracle has released an emergency patch for a critical vulnerability in its Identity Manager software. This flaw could allow hackers to execute code remotely. Organizations must act quickly to protect their systems from potential exploitation.

SecurityWeek·
CRITICALVulnerabilities

CVE-2026-21992 - Oracle Fixes Critical RCE Flaw

Oracle has addressed a critical RCE vulnerability in Identity Manager. This flaw allows attackers to gain system control without authentication. Immediate updates are essential to safeguard sensitive data and maintain system integrity.

Security Affairs·
HIGHVulnerabilities

Vulnerabilities - CISA Adds Apple, Laravel, Craft CMS Flaws

CISA has added critical vulnerabilities in Apple, Laravel Livewire, and Craft CMS to its catalog. These flaws pose serious risks to users. Immediate action is required to mitigate potential exploits.

Security Affairs·
HIGHVulnerabilities

Vulnerabilities - ScreenConnect Servers and SharePoint Flaw Exploited

Recent vulnerabilities in ScreenConnect and Microsoft SharePoint are under active exploitation. Organizations using these platforms must patch them immediately to avoid serious breaches. Stay informed and secure your systems now!

Help Net Security·