Skip to main content
CybersecurityVulnerability Management

Microsoft Fixes Defender Bug Behind False Antivirus Alerts

Windows 11 laptop screen shows Microsoft Defender Antivirus settings with green status indicator.

"After installing the latest updates for Microsoft Defender Antivirus, notifications might appear stating that 'Microsoft Defender Antivirus is turned off,' even though the antivirus is functioning correctly and all settings show it as active," Microsoft said.

Microsoft Defender Antivirus update 4.18.26080.4 — the fix and its timing

On September 17, Microsoft released Microsoft Defender Antivirus update version 4.18.26080.4, and said the update resolves a known issue that had produced incorrect alerts warning users that Defender Antivirus was turned off. The company first acknowledged the bug in late August, though it had affected users in the Release Preview Channel of the Windows Insider program since at least June.

Which systems the bug touched: Windows 11 26H1, Windows Server 2025 and more

Microsoft reported the problem affected "all supported Windows client and server versions," explicitly naming the then-latest Windows 11 26H1 and Windows Server 2025 releases. The erroneous alerts appeared inside the Windows Security app and could show up across those supported client and server editions after recent Defender updates were installed.

How the false alerts presented and why they were disruptive

The false notification prompted users with a persistent prompt to "Tap or click to turn on Microsoft Defender Antivirus" even when the product was functioning normally and settings showed it as active. Microsoft explained that the notifications could appear when Windows starts and intermittently afterward and that they persisted even if notification settings were turned off — a combination that increased visibility for affected users and complicated standard remediation steps like silencing notifications.

A pattern: post-update false alerts and emergency fixes since 2025

This Defender alert was the latest in a string of post-update problems Microsoft told customers to ignore or patched after distribution. In April 2025 the company addressed incorrect BitLocker drive encryption errors on Windows 10 and Windows 11 devices and fixed a bug that caused invalid 0x80070643 failure errors after installing Windows Recovery Environment (WinRE) updates. In July 2025 Microsoft asked users to ignore erroneous Windows Firewall alerts that appeared after rebooting following the June 2025 preview update; one month later it warned that the July 2025 preview update and subsequent Windows 11 24H2 updates were causing incorrect CertificateServicesClient (CertEnroll) errors. This week — concurrent with the Defender fix — Microsoft also released emergency Windows updates to fix Remote Desktop Services, Hyper-V, and USB audio issues caused by the September 2026 security updates.

What this means for security teams, enterprise IT, and end users

  • Security teams: Expect and plan for noisy, update-triggered alerts that may not reflect functional degradation. The Defender message Microsoft described can appear at startup and persist despite notification controls, increasing help-desk noise even when protections remain active.
  • Enterprise IT and procurement leads: Track Defender and Windows update versions — the company cited version 4.18.26080.4 as the corrective release on September 17 — and coordinate deployment timing to avoid concurrent rollouts that could increase user confusion or service desk load.
  • End users and general IT support: Be aware that a visible "turned off" message inside Windows Security does not necessarily mean Defender is disabled. Microsoft explicitly said the antivirus could be "functioning correctly" while the alerts appeared, and that notifications may persist even if notification settings are turned off.

Microsoft’s statement and the September 17 Defender update close this particular alert thread, but the company’s recent history of post-update errors and the emergency Windows fixes released the same week underscore that update-related disruptions have continued into September 2026. For now, the immediate technical step is the availability of the Defender update 4.18.26080.4; operators and users will judge its impact by whether the incorrect notifications stop appearing after installation.

Original story at BleepingComputer