Cybersecuritynews Microsoft Blocks Untrusted Kernel Drivers in Windows Update
Article Content
- •Microsoft will block untrusted kernel drivers starting April 2026.
- •Only drivers certified through the WHCP will be allowed by default.
- •The policy will initially run in evaluation mode to monitor compatibility.
Microsoft is set to enhance Windows security by blocking kernel drivers signed by the deprecated cross-signed root program starting with the April 2026 update. This change affects Windows 11 and Windows Server 2025, where only drivers certified through the Windows Hardware Compatibility Program (WHCP) will be trusted. The decision aims to mitigate risks associated with legacy drivers that have not undergone recent security evaluations. While the policy will initially operate in 'evaluation mode' to assess compatibility issues, it signals a shift towards stricter security measures in the Windows ecosystem. Administrators can still allow custom drivers through specific policies, but this is intended for internal use rather than legacy support. Microsoft emphasizes the need for a balance between security and compatibility, acknowledging potential impacts on users reliant on older drivers. The change will apply to various Windows versions, including 24H2, 25H2, and 26H1.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…