The September 17 update, identified as version 4.18.26080.4 of the Defender platform, eliminates a persistent false alert that appeared at system startup and at random intervals thereafter, even when notification settings were disabled.
When users clicked the erroneous warning, the Windows Security home tab opened and displayed all protection components as active, confirming that the antivirus was in fact running.
Microsoft first acknowledged the problem on August 28, stating that it affected any supported Windows or Windows Server edition that had the latest Defender updates installed, but the company did not pinpoint a specific update as the cause because Defender patches are delivered daily.
The fix is delivered automatically through Windows Update; no manual intervention is required unless administrators have blocked mandatory security updates via Group Policy or the Registry Editor.
Windows Insider participants reported similar warnings as early as June, and the issue was covered by outlets such as TechPowerUp, with several staff members encountering the bogus alert themselves.
The roughly three‑week interval between Microsoft’s public acknowledgment and the release of the corrective update drew criticism for the visibility of the bug, though the company noted that the daily cadence of Defender updates makes rolling back to a single KB impractical.