VulnerabilitiesHIGH

Vulnerabilities - Microsoft Update Fixes Sign-In Issues

BCBleepingComputer·Reporting by Sergiu Gatlan
Summary by CyberPings Editorial·AI-assisted·Reviewed by Rohit Rana
Updated:
🎯

Basically, Microsoft fixed a problem that stopped people from signing into their apps.

Quick Summary

Microsoft has launched an emergency update to resolve sign-in issues across its apps. Users faced errors despite being online. This fix is essential for restoring access to Microsoft services.

What Happened

Microsoft has rolled out an emergency update, KB5085516, to address a significant issue affecting sign-ins with Microsoft accounts. This problem emerged after users installed the KB5079473 cumulative update during March's Patch Tuesday. Users reported receiving misleading error messages stating they weren't connected to the Internet, despite being online. This glitch impacted several Microsoft applications, including Teams, OneDrive, and Microsoft Edge, causing frustration for many.

The error message typically read, "You'll need the Internet for this. It doesn't look like you're connected to the Internet." This was particularly problematic for users relying on Microsoft accounts for accessing essential features in their applications. Microsoft clarified that businesses using Entra ID for app authentication were not affected, isolating the issue primarily to personal Microsoft account users.

Who's Affected

The sign-in issues primarily impacted users of Microsoft accounts across various applications. This includes individuals using Microsoft Teams Free, OneDrive, Microsoft 365 Copilot, and Office applications like Excel and Word. Users experienced difficulties logging in, which hindered their ability to utilize these critical productivity tools.

While the problem was widespread, businesses that utilize Entra ID for authentication were spared from these disruptions. However, the situation still raised concerns among personal users who depend heavily on these services for daily tasks.

What Data Was Exposed

Fortunately, this issue did not lead to any data exposure or breaches. The problem was strictly related to the sign-in functionality and did not compromise user data or accounts. Microsoft has emphasized that while users faced connectivity errors, their data remained secure. The company acted swiftly to mitigate the impact by providing a workaround and an emergency update.

What You Should Do

If you are affected by this sign-in issue, Microsoft recommends installing the KB5085516 update as soon as possible. This update is available for Windows 11 versions 25H2 and 24H2 and can be installed through Windows Update or the Microsoft Update Catalog. Additionally, users experiencing issues can try restarting their PCs, which may temporarily resolve connectivity errors.

Staying updated with the latest patches is crucial for maintaining system security and functionality. Regularly check for updates and ensure your devices are running the latest software to avoid similar issues in the future.

🔒 Pro insight: The rapid rollout of KB5085516 underscores Microsoft's commitment to user experience and security amidst widespread application disruptions.

Original article from

BCBleepingComputer· Sergiu Gatlan
Read Full Article

Also covered by

THThe Register Security

Microsoft fixes broken Windows update days after vowing fewer broken updates

Read Article

Related Pings

CRITICALVulnerabilities

Fortinet FortiClient EMS - Critical 0-Day Vulnerability Exploited

A critical zero-day vulnerability in FortiClient EMS is actively exploited. Fortinet has released emergency patches and urges immediate action from users.

Cyber Security News·
HIGHVulnerabilities

Video Conferencing Bug - CISA Orders Agencies to Patch

A serious vulnerability in TrueConf video conferencing software is being exploited by Chinese hackers. CISA has mandated a two-week patch deadline for federal agencies. Immediate action is essential to safeguard sensitive data and communications.

The Record·
HIGHVulnerabilities

Post-Deployment Vulnerability Detection - Rethinking Strategies

A new approach to vulnerability detection is needed post-deployment. Many organizations overlook risks from newly disclosed CVEs, leaving systems exposed. Rethinking strategies can enhance security.

OpenSSF Blog·
HIGHVulnerabilities

Mobile Vulnerabilities - Enterprises Struggle with Control

Mobile devices are increasingly vulnerable due to outdated software and hidden threats like Shadow AI. This puts sensitive enterprise data at risk. Organizations must act to secure their mobile environments.

SecurityWeek·
HIGHVulnerabilities

CVE-2026-33691 - OWASP CRS Whitespace Padding Bypass Alert

A new vulnerability in OWASP CRS allows attackers to upload dangerous files by exploiting whitespace in filenames. This affects many web applications, risking severe security breaches. Immediate updates are necessary to protect your systems.

Full Disclosure·
HIGHVulnerabilities

MetInfo CMS Vulnerability - PHP Code Injection Risk

A critical vulnerability in MetInfo CMS could let attackers execute arbitrary PHP code. Versions 7.9, 8.0, and 8.1 are at risk. Stay alert for updates and potential fixes.

Full Disclosure·