DattoRMM - Syrah/Vidal - Cagservice.exe is being flagged as malicious (Rapidstop) by Microsoft Defender for Endpoint.
View the provider incident record →Current answer
Kaseya Inc experienced a major incident: DattoRMM - Syrah/Vidal - Cagservice.exe is being flagged as malicious (Rapidstop) by Microsoft Defender for Endpoint.. ServiceAlert observed recovery on Sep 29, 2026.
Looking for an update now? Check the current status, or follow Kaseya Inc for future changes.
Incident Lifecycle
Affected Components
Syrah (APAC)
Vidal (US East)
Incident Timeline
Monitoring
A fix has been implemented and we are monitoring the results.
The Kaseya R&D team confirmed with Microsoft counterparts that the issue was caused by misclassification of the 15.1.1 Datto RMM version's cagservice.exe in a recent security intelligence update for Microsoft Defender Antivirus and other Microsoft antimalware.
This issue was fixed in the security intelligence update version 1.459.450.0, and the issue should no longer occur on device's with this definition version or later. Microsoft currently does not offer an automated way to revert the quarantining of a file, therefore manual action is required to bring affected devices back online in Datto RMM.
We recommend our partners to ensure that devices are updated with security intelligence version 1.459.450.0 or later to avoid the agent being falsely flagged as malicious by Microsoft antimalware.
Users can use the below commands and instructions to ensure that the latest security intelligence update is installed on the device to prevent the behavior:
Updating the security intelligence version:
- PowerShell: Update-MpSignature
- Command Prompt (CMD): MpCmdRun.exe -SignatureUpdate
After running the update, users can verify the installed version with the following command:
- Get-MpComputerStatus | Select-Object AntivirusSignatureVersion, AntivirusSignatureLastUpdated
The Kaseya R&D team confirmed with Microsoft counterparts that the issue was caused by misclassification of the 15.1.1 Datto RMM version's cagservice.exe in a recent security intelligence update for Microsoft Defender Antivirus and other Microsoft antimalware.
This issue was fixed in the security intelligence update version 1.459.450.0, and the issue should no longer occur on device's with this definition version or later. Microsoft currently does not offer an automated way to revert the quarantining of a file, therefore manual action is required to bring affected devices back online in Datto RMM.
We recommend our partners to ensure that devices are updated with security intelligence version 1.459.450.0 or later to avoid the agent being falsely flagged as malicious by Microsoft antimalware.
Users can use the below commands and instructions to ensure that the latest security intelligence update is installed on the device to prevent the behavior:
Updating the security intelligence version:
- PowerShell: Update-MpSignature
- Command Prompt (CMD): MpCmdRun.exe -SignatureUpdate
After running the update, users can verify the installed version with the following command:
- Get-MpComputerStatus | Select-Object AntivirusSignatureVersion, AntivirusSignatureLastUpdated
Sep 28, 2026 at 10:10 PM UTC
Investigating
Our team remains actively engaged with Microsoft to investigate reports of false-positive detections occurring after devices were updated to Datto RMM Agent version 15.1.1 and to support remediation efforts where needed. At this time, the issue appears to be related to a security detection classification and not confirmed as malicious activity within the Datto RMM agent. We will continue to share updates as additional information becomes available.
Should you need any additional questions or require assistance, please contact our support team at https://helpdesk.kaseya.com/hc/en-gb#/contact
Subscribe to the Kaseya Status Page for up-to-date information at https://status.kaseya.com/
Should you need any additional questions or require assistance, please contact our support team at https://helpdesk.kaseya.com/hc/en-gb#/contact
Subscribe to the Kaseya Status Page for up-to-date information at https://status.kaseya.com/
Sep 28, 2026 at 7:40 PM UTC
Investigating
We are aware of a problem where Datto RMM's 15.1.1 Cagservice.exe is being flagged as malicious (Rapidstop) by Microsoft Defender for Endpoint.
The Kaseya Engineering Team is investigating this issue with Microsoft.
Should you need any additional questions or require assistance, please contact our support team at https://helpdesk.kaseya.com/hc/en-gb#/contact
Subscribe to the Kaseya Status Page for up-to-date information at https://status.kaseya.com/
The Kaseya Engineering Team is investigating this issue with Microsoft.
Should you need any additional questions or require assistance, please contact our support team at https://helpdesk.kaseya.com/hc/en-gb#/contact
Subscribe to the Kaseya Status Page for up-to-date information at https://status.kaseya.com/
Sep 28, 2026 at 3:11 PM UTC
Was your business affected by this Kaseya Inc outage?
Follow Kaseya Inc and route available status alerts to email or a team channel.