Windows Server 2016 hit by 0xc0000409 after August updates
Microsoft says August 2026 security updates trigger 0xc0000409 errors on Windows Server 2016 when Compatibility Appraiser is enabled.
Windows Server 2016 administrators are facing a new headache: Microsoft has confirmed that the August 2026 security update can trigger 0xc0000409 errors on systems running the Compatibility Appraiser diagnostic service. The issue manifests as recurring crashes of CompatTelRunner.exe, a process tied to Microsoft's Compatibility Telemetry components.
What triggers the crashes
According to Microsoft, the problem occurs specifically on Windows Server 2016 devices where the Compatibility Appraiser diagnostic service is enabled. This background task checks whether a device meets the hardware and software requirements for the next major Windows cumulative update or feature upgrade. When it runs after the August update, it can generate repeated Application Error events (Event ID 1000) with exception code 0xc0000409, all associated with CompatTelRunner.exe.
Microsoft says the issue affects both physical machines and virtual machines, including those in VMware and Azure environments. That broad reach means many administrators could encounter the error across their fleets.
What Microsoft is saying
In a service alert spotted by Microsoft MVP Susan Bradley, the company is reassuring users that the failures do not affect device functionality. The alert states: "Although recurring CompatTelRunner.exe failures might generate Application event log entries, they do not affect device functionality. The associated event log warnings can be safely dismissed temporarily until we release a resolution in an upcoming update."
Microsoft is working on a fix that will be delivered in a future Windows update, but has not yet shared a timeline for a permanent resolution.
Recurring theme in Server updates
This is not the first time Windows Server 2016 has seen update-related headaches. In June, Microsoft fixed another known issue that caused June 2026 security updates to fail on systems that weren't up to date. That earlier problem prevented the updates from installing correctly, leaving some machines exposed to missing patches.
Last week, Microsoft also warned that Windows Server 2025 customers may experience application crashes due to recent memory management changes. That issue is narrower, affecting only apps that use Address Windowing Extensions (AWE) — a set of extensions that let apps use more than 4GB of physical memory within a 32-bit virtual address space. On affected systems, users have reported memory corruption errors, access violation exceptions (with 0xC0000005 error codes), SQL Server crash dumps, and SQL Server services stopping or restarting unexpectedly.
Practical steps for admins
While Microsoft has not yet provided a workaround for the 0xc0000409 errors, the company explicitly states the crashes do not affect device functionality. That means administrators can monitor the event logs without urgent action, but they should not ignore the underlying issue entirely. The event log entries can be dismissed temporarily, but they may obscure other, more serious errors if admins are not careful.
Given that this is a known issue with a fix in progress, the safe path is to verify whether your systems are affected — especially if you run Windows Server 2016 with the Compatibility Appraiser enabled — and to stay on top of upcoming Windows updates from Microsoft.
Why it matters to IT teams
For IT administrators, the practical consequence is that after installing the August 2026 security update, they may see a stream of Application Error Events that could be mistaken for a deeper problem. Without confirmation from Microsoft, some might spend hours troubleshooting what is, in reality, a harmless side effect. The broader lesson is that even well-tested security updates can introduce unexpected side effects on older server platforms, and that enterprises running Windows Server 2016 need to plan for such issues as the platform ages.
Until a fix ships, the key is to keep this known issue on your radar. If you see repeated 0xc0000409 errors from CompatTelRunner.exe, you can now be confident it's a known problem, not something you need to chase down as if it were a new attack or a failing disk. But that also means you should watch Microsoft's release notes for the next cumulative update — that's where the permanent fix will arrive.
For more details, refer to the Microsoft service alert on this issue.
Sources
- BleepingComputer Original source
- service alert Also reporting
Continue Reading
WeChat worm exploited before calls answered
Tencent patches zero-click flaw that allowed account takeover via VoIP calls.
Gigabud's App Cloning Bypasses Fraud Alerts
Android malware clones banking apps into separate work profiles, letting fraudsters evade detection.
Fortinet Critical Patches Target JWT Bypass and Browser Proxy
Fortinet patches two critical flaws: one bypassing FortiMonitorOnSight auth via JWT, another allowing browser traffic proxy.