The images in this article were generated with artificial intelligence. How we publish
Summary of the problem: Several third-party backup applications ceased to work after the April 2026 security update identified as KB5083769. Users and administrators report that the jobs using VSS (Volume Shadow Copy Service) fail with the error "The backup has failed because Microsoft VSS has timed out during the snapshot creation" on Windows 11 24H2 and 25H2. The products concerned include sales solutions known as Acronis, Macrium, NinjaOne and UrBackup, and some suppliers have already published technical notices and temporary guides.
Why VSS matters: Volume Shadow Copy Service is the Windows mechanism in charge of creating coherent system and data "snapshots" so that backup programs can copy blocked files or databases in use without corrupt them. When VSS fails or runs out of waiting time, the result is not just a failed copy task: it can be the silent loss of recent copies that recovery teams expect to find, compromising business continuity and RPO (recovery point targets).

What could be going on?(technical context): Although Microsoft had not disseminated a detailed explanation at the close of this note, symptoms point to a regression in how the update interacts with VSS providers or with the maximum time for snapshot creation. The snapshots that require more time (by high I / O, large volumes, or complex composition of suppliers) deplete the timeout and cause operating abortions that backup applications interpret as irreparable failures.
Operational and security impact: repeated backups failures degrade the restoration capacity; in addition, some suppliers indicate that affected equipment can disconnect from cloud consoles or appear to be "offline," which complicates remote monitoring. In a business environment this increases operational risk, and in environments with regulatory compliance may involve non-compliance if the compliant copies within required windows are not re-established.
Recommended immediate action: If you detect errors after installing KB5083769, check first the log of your backup solutions and confirm if the error corresponds to the VSS timeout. As a temporary measure and approved by several suppliers, you can uninstall the update from Settings > Windows Update > Update History > Related Settings > Uninstall updates, restart and pause updates until there is an official patch or communication. Before uninstall, document the system status and make a local copy of the records; after reversing, run a manual backup and, very important, a test restoration to validate integrity. See the supplier support note for your backup software (e.g., Acoris) and the Microsoft KB KB5083769 for official instructions and updates.
Short-term and medium-term mitigation measures: does not depend on a single copy strategy. Check that your policies include automatic restorative verification (regular restore tests), multiple retention (copies at different time points), and at least one offline copy or in removable media. In critical environments, consider running complementary copies outside the VSS scheme (e.g. block-level replication to native applications or storage snapshots) until the problem is solved. Keep inventory of agent versions and coordinate with your backup provider to apply hotfixes or recommended time settings.

Best practices for business environments: test updates in a laboratory that reproduces its topology and load before being deployed in production; automate alerts that detect backup failures and increase visibility on jobs that change to failed state; document a contingency plan that includes rapid reversal of critical patches and communication with stakeholders. To better understand the technical role of VSS and how it is used in Windows, you can consult Microsoft's official documentation on Volume Shadow Copy Service at VSS documentation.
What to expect from Microsoft and suppliers: Since there have already been other problems with April updates (including OOB corrections and BitLocker reports on servers), it is reasonable to expect patches or a KB update that will correct the interaction with VSS in the coming days or weeks. Activate the monitoring of Microsoft bulletins and support channels of your backup providers; install corrections only after validating them in controlled environments and confirming that restorations work.
Conclusion: the failure associated with KB5083769 underlines the need for prudent updating policies and previous tests, as well as the importance of verifying restorations and maintaining redundant backup strategies. If your business depends on backup for resilience, treat this incident as a reminder: the integrity of the copies is not guaranteed only by the execution of jobs, but by the proven ability to restore when needed most.
Related
More news on the same subject.

Anonymous MousKIT phishing platform identified to remove Activation Lock on iPhone and iPad
Cybersecurity researchers have documented a phishing platform as a service aimed at eliminating the protection of Activation Lock from stolen iPhones and iPads, combining forged...

United States U.S. imposes sanctions on Iranian networks linked to MOIS and Mabna in the Economic Outcast operation
The U.S. Treasury Department has launched a new round of financial sanctions against networks linked to Iran, in a campaign that the U.S. authorities describe as a coordinated e...

NemoClaw operating chain exposes Olama to unauthenticated access and alters chat templates
What has happened (confirmed facts): Oasis Security researchers have published a report describing a chain of exploitation against the NemoClaw configuration that can allow a we...

CISA adds CVE-2026-21962 to KEV by remote operation in Oracle HTTP Server and WebLogic
The United States Agency for Cybersecurity and Infrastructure (CISA) has included in its catalogue Known Exploited Vulnerabilities (KEV) the critical failure traced as CVE-2026-...

IA in code generation accelerates OSS dependencies and generates security mediation debt
A recent seminar organized by ActiveState and a survey of 300 security and development leaders in companies in different sectors confirms something that many teams already notic...

They identify WordlistLoader and SynkLoader, intermediate loaders linked to access brokers for
Cybersecurity researchers have identified two new malware families - called WordlistLoader and SynkLoader - used as intermediate stages to deploy later loads and, according to p...

TikTok will pay 400 million for COPPA; 100 M subject to annulment of decree Musical.ly
The U.S. Department of Justice. United States announced payment of $400 million by TikTok to resolve a 2024 lawsuit that accused the platform - owned by ByteDance - of violating...