Datto RMM - Syrah, Vidal - 15.0.1 Cagservice.exe being flagged as malicious (Rapidstop) by Microsoft Defender for Endpoint

Incident Report for Kaseya Inc

Postmortem

Summary

On 29 June 2026, following a third-party security intelligence definition update, a component of the Datto RMM agent was incorrectly identified as malicious on certain devices.

As a result, affected Datto RMM agents stopped functioning as expected, causing affected devices to appear offline within the Datto RMM portal.

Kaseya promptly investigated the issue, engaged with the third-party provider, and worked collaboratively to resolve the misclassification. Updated security intelligence definitions were subsequently released, resulting in misclassification no longer occurring on devices already updated with the new definitions.

Based on the investigation, this incident was determined to be the result of a false positive detection and was not caused by actual malware or ransomware activity.

Customer Impact Assessment

Affected customers may have experienced:

  • Devices appearing offline within the Datto RMM portal.
  • Complete interruption in agent-based management activities.
  • Visibility and management capabilities for affected endpoints through Datto RMM were inhibited during the incident.

Manual intervention was required on affected devices to restore agent functionality.

Root Cause

The incident was caused by a false positive security detection generated by a third-party security product, which incorrectly identified legitimate Datto RMM software activity as malicious.

While we wait for the technical RCA from the third-party provider for a formal root cause for the false positive detection, the issue was resolved through the updated security intelligence definitions that corrected the classification.

Based on the investigation, the Datto RMM software involved in this event functioned as designed and was not determined to be the source of the false positive detection.

The review also identified opportunities to strengthen pre-release validation and incident response processes to better detect and respond to similar third-party security classification issues.

Incident Timeline

  • Issue Identified: 29 June 2026 15:33 UTC
  • Public Notification: 29 June 2026 16:02
  • Incident Resolved: 29 June 2026 21:00

Lessons Learned

This incident highlighted the importance of close coordination with security vendors and the need for continued validation of software releases against evolving security detection mechanisms.

The review also reinforced the importance of rapid escalation, vendor collaboration, and timely customer communications when addressing false positive detections.

Preventative Measures

To reduce the likelihood and impact of similar incidents in the future, Kaseya is implementing the following improvements:

Proactive Vendor Collaboration

We are strengthening collaboration with security vendors to improve pre-release validation and reduce the likelihood of false positive detections affecting customers.

Enhanced Release Validation

We are expanding release validation procedures to include additional security compatibility testing across representative customer environments.

Enhanced Monitoring

We are improving monitoring and alerting capabilities to more quickly identify and assess abnormal security detections involving Datto RMM software.

Enhanced Response Procedures

We are updating incident response processes to accelerate investigation, vendor engagement, and customer communications when similar events occur.

Posted Jul 16, 2026 - 04:54 EDT

Resolved

This incident has been resolved.
Posted Jul 15, 2026 - 10:25 EDT

Monitoring

A fix has been implemented and we are monitoring the results.

The Kaseya R&D team confirmed with Microsoft counterparts that the issue was caused by misclassification of the 15.0 Datto RMM version's cagservice.exe in a recent security intelligence update for Microsoft Defender Antivirus and other Microsoft antimalware.

This issue was fixed in the security intelligence update version 1.453.344.0, and the issue should no longer occur as long as the device is on this definition version or later. Microsoft currently does not offer an automated way to revert the quarantining of a file, therefore manual action is required to bring affected devices back online in Datto RMM.

We recommend our partners to ensure that devices are updated with security intelligence version 1.453.344.0 or later to avoid the agent being falsely flagged as malicious by Microsoft antimalware.

Users can use the below commands and instructions to ensure that the latest security intelligence update is installed on the device to prevent the behavior:
Updating the security intelligence version:
- PowerShell: Update-MpSignature
- Command Prompt (CMD): MpCmdRun.exe -SignatureUpdate

After running the update, users can verify the installed version with the following command:
- Get-MpComputerStatus | Select-Object AntivirusSignatureVersion, AntivirusSignatureLastUpdated
Posted Jun 29, 2026 - 18:47 EDT

Identified

The issue has been identified and a fix is being implemented.
Posted Jun 29, 2026 - 15:36 EDT

Update

We are continuing to investigate this issue.
Posted Jun 29, 2026 - 12:07 EDT

Investigating

We are aware of a problem where Datto RMM's 15.0.1 Cagservice.exe is being flagged as malicious (Rapidstop) by Microsoft Defender for Endpoint.

The Kaseya R&D Team are investigating this issue.

Subscribe to the Kaseya Status Page for up-to-date information at https://status.kaseya.com/
Posted Jun 29, 2026 - 12:02 EDT
This incident affected: Datto RMM (Syrah (APAC), Vidal (US East)).