[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fXxvmX2isGZM07_JlSdDiT98v0qMYMsJO62FK3-BJPu8":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":21,"created_at":22,"published_at":23,"article":24,"tags":28,"podcasts":41},"79a3d99a-e187-4aea-9481-293091aaccaf","august-net-update-breaks-wpf-printing-patch-trade-offs-demand-careful-rollout","aeaaf74e-fc2c-490f-a613-919bd56c4107","August .NET Update Breaks WPF Printing — Patch Trade-offs Demand Careful Rollout","Microsoft's August 2026 cumulative .NET Framework update introduced a regression that breaks printing and PDF export in WPF applications when specific fonts such as Calibri are used. This highlights the persistent tension between applying security patches promptly and ensuring application stability in production environments. The offered workaround — an AppContext switch — explicitly disables security protections, forcing organizations into a difficult choice between operational continuity and security posture. This situation underscores why organizations must have structured patch testing pipelines and rollback capabilities before deploying cumulative updates broadly. Without these controls, a single faulty update can cause widespread business disruption across both client and server environments.","**Immediate actions:**\n- Deploy the Microsoft-recommended AppContext switch workaround only on affected systems while formally documenting the associated security risk and obtaining change-approval sign-off.\n- Identify all WPF applications in your environment that use printing or PDF export functions and assess business impact before deciding on the workaround vs. rollback path.\n- Roll back the August cumulative update on critical production systems using Windows Update or WSUS until Microsoft releases a corrected patch.\n\n**Pre-deployment controls:**\n- Maintain a dedicated staging or UAT environment that mirrors production to test all cumulative updates — especially .NET Framework patches — against representative application workloads before broad rollout.\n- Implement a phased deployment ring strategy (pilot → broad → production) with defined go\u002Fno-go criteria, including functional regression checks for printing and document export.\n- Establish a maximum acceptable patch-hold window (e.g., 72 hours) so security risk from delaying the update is formally tracked and owned.\n\n**Long-term improvements:**\n- Build an accurate application inventory that tags dependencies on specific runtimes (.NET versions, WPF, WinForms) so patch impact analysis can be automated and targeted.\n- Define and rehearse a rollback runbook for cumulative OS and framework updates, including WSUS decline procedures and System Restore or snapshot reversion steps.\n- Subscribe to Microsoft's official release health RSS feeds and Windows Message Center alerts to receive regression notices faster and reduce mean-time-to-awareness.",[12,13,14,15,16,17,18,19,20],"CIS Control 7.3 — Perform Automated Operating System Patch Management","CIS Control 7.4 — Perform Automated Application Patch Management","CIS Control 4.1 — Establish and Maintain a Software Inventory","NIST SP 800-40 Rev. 4 — Guide to Enterprise Patch Management Planning","NIST SP 800-128 — Guide for Security-Focused Configuration Management","NIST CM-3 — Configuration Change Control","NIST SI-2 — Flaw Remediation","ITIL Change Management — Change Advisory Board (CAB) review for standard changes","ITIL Problem Management — Known Error Record for confirmed vendor regression","published","2026-08-24T14:20:41.484981+00:00","2026-08-24T14:20:41.401+00:00",{"id":7,"url":25,"slug":26,"title":27},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fmicrosoft\u002Fmicrosoft-august-updates-break-printing-pdf-export-in-wpf-apps\u002F","microsoft-august-updates-break-printing-pdf-export-in-wpf-apps-a0a0d8","Microsoft: August updates break printing, PDF export in WPF apps",[29,35],{"id":30,"name":31,"slug":32,"description":33,"color":34},"182e11d5-57c4-444e-8ec8-4682ad60261b","Incident Response","incident-response","Slow detection, poor containment, missing playbooks","#14b8a6",{"id":36,"name":37,"slug":38,"description":39,"color":40},"af7fce9e-1ce8-4156-93bc-09dcfbfdf29d","Patch Management","patch-management","Unpatched vulnerabilities, delayed updates","#ef4444",[]]