Microsoft Defender Misflags DigiCert Root Certificates, Triggering Windows Trust Store Disruptions
Microsoft Defender mistakenly flagged DigiCert root certificates as malware. A rapid update was deployed to fix the issue and prevent system disruptions.
Jason Kwon ·

Micrososources Defender mistakenly flagged two legitimate DigiCert root certificates as malware around April 30, 2026, prompting widespread false-positive alerts and, on affected systems, quarantining the certificates from the Windows trust store.
The issue stemmed from a faulty antimalware signature update that labeled registry entries for DigiCert Assured ID Root CA and DigiCert Trusted Root G4 as “Trojan:Win32/Cerdigent.A!dha.” Because these root certificates are used to establish trust for encrypted connections and to validate digitally signed sosourcesware, their removal could prevent systems from validating SSL/TLS connections to websites and verifying code-signing for legitimate applications.
In enterprise environments, that failure mode can translate into operational disruption, including browser warnings, blocked connections, and application errors—particularly for organizations that depend on DigiCert-signed sosourcesware or HTTPS endpoints.
Micrososources acknowledged the problem and issued corrective definition updates. Version .430 was cited as a key fix, and the updates began restoring the quarantined certificates on affected machines. Security observers also reported signs of an automatic restoration process on managed endpoints, aimed at reducing the risk of broader service impact.