Cyber Security News

Microsoft Recent Update Breaks VPS Access for Windows Subsystem for Linux Users

Microsoft’s October 2025 non-security update is disrupting virtual private server (VPS) access for Windows Subsystem for Linux (WSL) users, particularly those relying on third-party VPNs for enterprise connectivity.

Released on October 28, 2025, as KB5067036, the update targets OS builds 26200.7019 and 26100.7019 (preview). Users report “No route to host” errors in WSL’s mirrored networking mode, blocking access to corporate VPS resources despite the Windows host functioning normally.

The glitch stems from VPN applications’ virtual interfaces failing to respond to ARP (Address Resolution Protocol) requests. This cripples VPN-dependent services, including DirectAccess tunnels to remote VPS environments. Affected users cannot reach enterprise servers, hindering remote work and security operations.

Cisco Secure Client (formerly AnyConnect) and OpenVPN bear the brunt, with reports surging on forums like Reddit and Microsoft Tech Community since late October. Home editions (Windows Home/Pro) face minimal impact, as the issue targets enterprise setups.

AspectDetails
Affected UpdateKB5067036 (Oct 28, 2025); Builds 26200.7019, 26100.7019
Impacted VPNsCisco Secure Client, OpenVPN
Error“No route to host” in WSL mirrored networking
ScopeEnterprise VPN to VPS/corporate resources

Microsoft acknowledges the issue and is actively investigating it. No patch timeline exists yet, but the company promises updates via its support channels.

In the interim, users can disable WSL’s mirrored networking mode or switch to bridged networking as a temporary fix. IT admins should test updates in staging environments before deployment, especially for hybrid Linux-Windows workflows common in cybersecurity teams analyzing threats on VPS instances.

This incident underscores the fragility of subsystem integrations post-update, potentially exposing devs and analysts to downtime in threat hunting. Monitor Microsoft’s WSL docs for resolutions.

Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

5 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

5 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

6 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

6 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

8 hours ago