August updates trigger 0xc0000409 errors on Windows Server 2016
Microsoft says the August 2026 security update may trigger 0xc0000409 errors on Windows Server 2016 systems where the Compatibility Appraiser diagnostic service is enabled.
On affected systems, users will see the CompatTelRunner.exe (Compatibility Appraiser Telemetry Runner) process crashing.
Microsoft Compatibility Appraiser, which controls CompatTelRunner and is a Windows Compatibility Telemetry component, is a background system task that checks if the device meets the hardware and software requirements for the next major Windows cumulative update or feature upgrade.
According to Microsoft, this known issue impacts both physical devices and virtual machines, including VMware and Azure environments.
"After installing the August 2026 Windows security update (the Originating KBs listed above), some Windows Server 2016 devices might generate recurring Application Error events (Event ID 1000, with exception code 0xc0000409) associated with CompatTelRunner.exe," Microsoft explained in a service alert spotted by Microsoft MVP Susan Bradley.
"Although recurring CompatTelRunner.exe failures might generate Application event log entries, they do not affect device functionality. The associated event log warnings can be safely dismissed temporarily until we release a resolution in an upcoming update."
Microsoft is working on a fix that will ship with a future Windows update and has not yet shared a timeline for a permanent solution.
In June, Microsoft fixed another Windows Server 2016 known issue that caused June 2026 security updates to fail on systems that weren't up to date.
Last week, it also warned customers that they may experience application crashes on some Windows Server 2025 because of recent memory management changes.
This issue only affects apps that use Address Windowing Extensions (AWE), a set of extensions that lets them use more than 4GB of physical memory within a 32-bit virtual address space.
On impacted systems, users are seeing memory corruption errors, access violation exceptions (with 0xC0000005 error codes), SQL Server crash dumps, and SQL Server services stopping or restarting unexpectedly.
Once attackers have valid credentials, only 37% of their actions are blocked
Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.
The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
Reproduced in full under licence from BleepingComputer. © BleepingComputer. Written by Sergiu Gatlan.
Coverage
One outlet has carried this so far.
2026-09-08 15:22 UTC
Related stories
- Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution
The Hacker News · 2026-09-16
- PHP Webshell Campaign Targets WordPress Through Critical WooCommerce Plugin Bug
Infosecurity Magazine · 2026-09-16
- Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories
The Hacker News · 2026-09-16
- Parallels Desktop Flaw Lets Non-Admin Mac Users Gain Root, but Intel Macs Can't Install Fix
The Hacker News · 2026-09-16
- Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation
The Hacker News · 2026-09-16 · exploited