Use cases
Software Products E-commerce MSPs Schools Development & Marketing DevOps Agencies Help Desk
Company
Internet Status Blog Pricing Log in Get started free

Outage in Kaseya

DattoRMM - Syrah/Vidal - Cagservice.exe is being flagged as malicious (Rapidstop) by Microsoft Defender for Endpoint.

Resolved Major
September 28, 2026 - Started 7 days ago - Lasted about 24 hours
Official incident page

Incident Report

Summary AI Generated

Microsoft Defender for Endpoint falsely flagged Datto RMM Agent version 15.1.1's `cagservice.exe` as malicious (Rapidstop) due to a misclassification in a Microsoft security intelligence update, causing affected devices to go offline in Datto RMM. Microsoft resolved the misclassification in security intelligence update version 1.459.450.0, after which the false positive no longer occurs on updated devices. Because Microsoft does not offer an automated way to reverse file quarantining, affected devices required manual remediation to be brought back online, with the incident fully resolved after approximately 24 hours of monitoring.

We are aware of a problem where Datto RMM's 15.1.1 Cagservice.exe is being flagged as malicious (Rapidstop) by Microsoft Defender for Endpoint. The Kaseya Engineering Team is investigating this issue with Microsoft. Should you need any additional questions or require assistance, please contact our support team at https://helpdesk.kaseya.com/hc/en-gb#/contact Subscribe to the Kaseya Status Page for up-to-date information at https://status.kaseya.com/

Trusted by 1,000+ teams

The Status Page Aggregator with Early Outage Detection

Stop finding out about outages from your users. Monitor 6,320+ cloud services and get alerted the second something breaks.

IsDown status aggregator dashboard
Latest Updates ( sorted recent to last )
RESOLVED 6 days ago - at 09/29/2026 02:55PM

This incident has been resolved after monitoring overnight. As previously stated, this issue was fixed in the security intelligence update version 1.459.450.0, and should no longer occur on device's with this definition version or later. Please see the earlier communication for further details.

MONITORING 7 days ago - at 09/28/2026 10:10PM

A fix has been implemented and we are monitoring the results.

The Kaseya R&D team confirmed with Microsoft counterparts that the issue was caused by misclassification of the 15.1.1 Datto RMM version's cagservice.exe in a recent security intelligence update for Microsoft Defender Antivirus and other Microsoft antimalware.

This issue was fixed in the security intelligence update version 1.459.450.0, and the issue should no longer occur on device's with this definition version or later. Microsoft currently does not offer an automated way to revert the quarantining of a file, therefore manual action is required to bring affected devices back online in Datto RMM.

We recommend our partners to ensure that devices are updated with security intelligence version 1.459.450.0 or later to avoid the agent being falsely flagged as malicious by Microsoft antimalware.

Users can use the below commands and instructions to ensure that the latest security intelligence update is installed on the device to prevent the behavior:
Updating the security intelligence version:
- PowerShell: Update-MpSignature
- Command Prompt (CMD): MpCmdRun.exe -SignatureUpdate

After running the update, users can verify the installed version with the following command:
- Get-MpComputerStatus | Select-Object AntivirusSignatureVersion, AntivirusSignatureLastUpdated

INVESTIGATING 7 days ago - at 09/28/2026 07:40PM

Our team remains actively engaged with Microsoft to investigate reports of false-positive detections occurring after devices were updated to Datto RMM Agent version 15.1.1 and to support remediation efforts where needed. At this time, the issue appears to be related to a security detection classification and not confirmed as malicious activity within the Datto RMM agent. We will continue to share updates as additional information becomes available.

Should you need any additional questions or require assistance, please contact our support team at https://helpdesk.kaseya.com/hc/en-gb#/contact

Subscribe to the Kaseya Status Page for up-to-date information at https://status.kaseya.com/

INVESTIGATING 7 days ago - at 09/28/2026 03:11PM

We are aware of a problem where Datto RMM's 15.1.1 Cagservice.exe is being flagged as malicious (Rapidstop) by Microsoft Defender for Endpoint.

The Kaseya Engineering Team is investigating this issue with Microsoft.

Should you need any additional questions or require assistance, please contact our support team at https://helpdesk.kaseya.com/hc/en-gb#/contact

Subscribe to the Kaseya Status Page for up-to-date information at https://status.kaseya.com/

The Status Page Aggregator with Early Outage Detection

With IsDown, you can monitor all your critical services' official status pages from one centralized dashboard and receive instant alerts the moment an outage is detected. Say goodbye to constantly checking multiple sites for updates and stay ahead of outages with IsDown.

Start free trial

No credit card required · Cancel anytime · 6320 services available

Integrations with Slack Microsoft Teams Google Chat Datadog PagerDuty Zapier Discord Webhook