Microsoft patches false antivirus shutdown warnings triggered by recent updates

Microsoft has released an update to resolve a known issue that caused Windows Security to incorrectly notify users that Defender Antivirus was disabled, despite the software running normally. The fix, included in Defender Antivirus version 4.18.26080.4 from September 17, addresses erroneous alerts that appeared on all supported Windows client and server versions, including Windows 11 26H1 and Server 2025. The company had previously acknowledged the bug in late August after it affected users in the Windows Insider Release Preview Channel since June.
The erroneous alerts appeared at system startup and continued intermittently afterward, persisting even when users disabled notification settings. The bug affected every supported Windows client and server edition, from older versions through Windows 11 26H1 and Windows Server 2025. Microsoft first acknowledged the problem in late August, though Windows Insider Release Preview users had experienced it since June.
This fix follows a pattern of similar false alarms from Microsoft this year, including incorrect BitLocker encryption errors in April, bogus Windows Firewall warnings in July, and spurious CertEnroll errors in August. The company also issued emergency updates this week addressing Remote Desktop Services, Hyper-V, and USB audio failures tied to September 2026 security patches.
The false alerts could erode user confidence in Windows Security's reliability, potentially leading some to ignore genuine warnings or switch to third-party antivirus tools unnecessarily. Organizations managing large Windows fleets may face increased helpdesk volume as employees report phantom notifications, though the swift patch suggests Microsoft is responsive to feedback. The recurring pattern of similar notification bugs could prompt enterprises to delay automatic updates, trading security timeliness for operational stability.