Skip to content
Microsoft Resolves Windows Update Caching Issue Affecting Driver Policies

Microsoft Resolves Windows Update Caching Issue Affecting Driver Policies

First seen 4 Jun 2026, 15:54 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster June 5, 2026 at 15:52 UTC
  • A misconfiguration in Windows Update caused unauthorized driver installations.
  • Tens of thousands of devices were affected, treated as unmanaged endpoints.
  • Microsoft confirmed that the installed drivers were approved and posed no security threat.

On June 2, 2026, Microsoft acknowledged a misconfiguration in the Windows Update caching service that caused Windows devices to install driver updates without adhering to administrative policies. This issue temporarily dropped device enrollment information, leading to tens of thousands of devices being treated as unmanaged and allowing unauthorized driver installations. The Intune Support Team confirmed the issue and stated that the installed drivers were Microsoft approved and posed no security threat. Microsoft resolved the issue by updating the affected service cache and validating the fix by June 3. However, the exact number of affected regions or customers remains unspecified. This incident follows previous issues with Windows Server upgrades and driver installations that bypassed administrative controls.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 108d ago How this analysis works

Timeline

2026-06-02
Microsoft acknowledges driver update issue
Microsoft reported that a caching misconfiguration led to unauthorized driver installations on managed devices.
Bleepingcomputer
2026-06-03
Issue resolved
Microsoft updated the caching service and confirmed that the issue was resolved after validation from affected users.
Bleepingcomputer
Recent
Tens of thousands of devices affected
Windows admins reported issues with devices unexpectedly receiving BIOS and driver updates, impacting functionality.
Feeds.4Sysops

More articles in this cluster (3)

Following this threat?

Track Microsoft in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed