LmCast :: Stay tuned in

August updates trigger 0xc0000409 errors on Windows Server 2016

Recorded: Sept. 8, 2026, 4:10 p.m.

Original Summarized

August updates trigger 0xc0000409 errors on Windows Server 2016

News

Featured
Latest

Trezor data breach impact now reaches 81,000 customers

BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations

N-able patches max severity N-central flaw amid ongoing attacks

Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain

August updates trigger 0xc0000409 errors on Windows Server 2016

SAP warns of maximum severity 'OVERPASS' kernel vulnerability

OpenAI says GPT-6 Astra can find zero-days, but is also harder to monitor

Adobe fixes critical Magento zero-day exploited to backdoor servers

Tutorials

Latest
Popular

How to access the Dark Web using the Tor Browser

How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11

How to use the Windows Registry Editor

How to backup and restore the Windows Registry

How to start Windows in Safe Mode

How to remove a Trojan, Virus, Worm, or other Malware

How to show hidden files in Windows 7

How to see hidden files in Windows

Webinars
Downloads

Latest
Most Downloaded

Qualys BrowserCheck

STOPDecrypter

AuroraDecrypter

FilesLockerDecrypter

AdwCleaner

ComboFix

RKill

Junkware Removal Tool

Deals

Categories

eLearning

IT Certification Courses

Gear + Gadgets

Security

VPNs

Popular

Best VPNs

How to change IP address

Access the dark web safely

Best VPN for YouTube

Forums
More

Virus Removal Guides
Startup Database
Uninstall Database
Glossary
Send us a Tip!
Welcome Guide

HomeNewsMicrosoftAugust updates trigger 0xc0000409 errors on Windows Server 2016

August updates trigger 0xc0000409 errors on Windows Server 2016

By Sergiu Gatlan

September 8, 2026
11:22 AM
0

Microsoft says the August 2026 security update may trigger 0xc0000409 errors on Windows Server 2016 systems where the Compatibility Appraiser diagnostic service is enabled.
On affected systems, users will see the CompatTelRunner.exe (Compatibility Appraiser Telemetry Runner) process crashing.
Microsoft Compatibility Appraiser, which controls CompatTelRunner and is a Windows Compatibility Telemetry component, is a background system task that checks if the device meets the hardware and software requirements for the next major Windows cumulative update or feature upgrade.
According to Microsoft, this known issue impacts both physical devices and virtual machines, including VMware and Azure environments.
"After installing the August 2026 Windows security update (the Originating KBs listed above), some Windows Server 2016 devices might generate recurring Application Error events (Event ID 1000, with exception code 0xc0000409) associated with CompatTelRunner.exe," Microsoft explained in a service alert spotted by Microsoft MVP Susan Bradley.
"Although recurring CompatTelRunner.exe failures might generate Application event log entries, they do not affect device functionality. The associated event log warnings can be safely dismissed temporarily until we release a resolution in an upcoming update."
Microsoft is working on a fix that will ship with a future Windows update and has not yet shared a timeline for a permanent solution.
In June, Microsoft fixed another Windows Server 2016 known issue that caused June 2026 security updates to fail on systems that weren't up to date.
Last week, it also warned customers that they may experience application crashes on some Windows Server 2025 because of recent memory management changes.
This issue only affects apps that use Address Windowing Extensions (AWE), a set of extensions that lets them use more than 4GB of physical memory within a 32-bit virtual address space.
On impacted systems, users are seeing memory corruption errors, access violation exceptions (with 0xC0000005 error codes), SQL Server crash dumps, and SQL Server services stopping or restarting unexpectedly.

Once attackers have valid credentials, only 37% of their actions are blocked

Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
Get the report

Related Articles:
Microsoft: Windows Server 2025 changes causing app crashesMicrosoft asks users to ignore 'Antivirus is turned off' errorsMicrosoft: August updates break printing, PDF export in WPF appsMicrosoft: KB5120998 mouse reset bug affects only non-English PCsMicrosoft says Windows 11 KB5120998 update resets mouse settings

0xc0000409
CompatTelRunner
KB5120418
Known Issue
Microsoft
Windows
Windows Server

Sergiu Gatlan
Sergiu is a news reporter who has covered the latest cybersecurity and technology developments for over a decade. Email or Twitter DMs for tips.

Previous Article

Post a Comment Community Rules

You need to login in order to post a comment

Not a member yet? Register Now

You may also like:

  Upcoming Webinar

Popular Stories

OpenAI admits it didn't disclose rogue AI wiki hijacking incident

Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain

BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations

Sponsor Posts

Unify ransomware protection and recovery for every client

CTI Starter Kit + 2026 SANS CTI Survey

See how attackers exploit passkey enrollment, and why hardware-bound biometrics raise enterprise identity assurance.

  Upcoming Webinar

Follow us:

Main Sections

News
Webinars
VPN Buyer Guides
SysAdmin Software Guides
Downloads
Virus Removal Guides
Tutorials
Startup Database
Uninstall Database
Glossary

Community

Forums
Forum Rules
Chat

Useful Resources

Welcome Guide
Sitemap

Company

About BleepingComputer
Contact Us
Send us a Tip!
Advertising
Write for BleepingComputer
Social & Feeds
Changelog

Terms of Use - Privacy Policy - Ethics Statement - Affiliate Disclosure

Copyright @ 2003 - 2026 Bleeping Computer® LLC - All Rights Reserved

Login

Username

Password

Remember Me

Sign in anonymously

Sign in with Twitter

Not a member yet? Register Now


Reporter

Help us understand the problem. What is going on with this comment?

Spam

Abusive or Harmful

Inappropriate content

Strong language

Other

Read our posting guidelinese to learn what content is prohibited.

Submitting...
SUBMIT

Microsoft has issued a service alert indicating that August 2026 security updates may trigger 0xc0000409 errors on Windows Server 2016 systems, specifically when the Compatibility Appraiser diagnostic service is enabled. On affected systems, users will observe the CompatTelRunner.exe (Compatibility Appraiser Telemetry Runner) process crashing. This issue stems from Microsoft Compatibility Appraiser, which governs CompatTelRunner and functions as a Windows Compatibility Telemetry component responsible for checking if hardware and software meet the prerequisites for major Windows cumulative updates or feature upgrades. Microsoft noted that this known issue impacts both physical devices and virtual machine environments, including those running VMware and Azure platforms.

Although these recurring failures in CompatTelRunner.exe may generate Application event log entries with exception code 0xc0000409, Microsoft stated that they do not affect device functionality. The associated warnings can be temporarily disregarded until a permanent resolution is released in a future update. Microsoft is currently working on a fix that will be included in a subsequent Windows update, though no timeline for the permanent solution has yet been provided. This situation relates to previous known issues where Microsoft fixed problems affecting June 2026 security updates and warnings about application crashes in Windows Server 2025 resulting from recent memory management changes affecting applications utilizing Address Windowing Extensions (AWE), which allows them to use more than four gigabytes of physical memory within a three-two bit virtual address space. When these memory management issues occur, impacted systems can experience memory corruption errors, access violation exceptions with error code 0xC0000005, SQL Server crash dumps, and unexpected stopping or restarting of SQL Server services. Furthermore, the text references data concerning general security posture, noting that once attackers possess valid credentials, prevention measures sharply decrease, as only thirty-seven percent of their actions are blocked, and the Blue Report 2026 measures defenses across customer production environments.