After installing certain Windows .NET Framework security updates, the Sharp OSA Capture web application (ASWebForSharp) stops working. Every page returns an HTTP 404 error:
"Server Error in '/ASWebForSharp' Application. The resource cannot be found."
This occurs both when the workflow is accessed from the Sharp MFP device panel and when the application is opened directly in a browser. Removing the affected update and restarting the server restores normal operation.
The AutoStore Status Monitor logs the following sequence when the Sharp MFP (OSA) component starts:
Information Sharp MFP (OSA): Sending test request to web application. Error Sharp MFP (OSA): An error occurred when sending test request: The remote server returned an error: (404) Not Found. Information Sharp MFP (OSA): Trying to start ftp server on port: 3285 ... Information Sharp MFP (OSA): FTP server started Information Sharp MFP (OSA): Initialization was successful. Information Send to Folder: Component initialized successfully. Information Cannot read UFI volume information.
The component-level self-test ("Sending test request to web application") fails with a 404 on every service start while the defect is present. This is a convenient regression indicator during troubleshooting.
Sharp OSA Capture identifies each scan session by embedding the session ID directly in the request URL, in the form /ASWebForSharp/(S(<sessionid>))/<page>.aspx, because the Sharp device panel does not support browser cookies. This is a deliberate, cookieless session design (cookieless="true" in Web.Config) and is unique to the Sharp integration within AutoStore.
The affected Windows updates change how ASP.NET processes this cookieless session token. ASP.NET still generates the token correctly on the outbound redirect, but no longer strips it from the inbound request path. The server therefore tries to resolve a physical file path that still contains the session token, which does not exist, and returns HTTP 404 for every request.
Other AutoStore capture components (for example WebCapture, Kyocera HyPAS) use standard cookie-based sessions and are not affected.
Workaround (recommended, keeps the security update installed):
1. Open Web.Config for the ASWebForSharp application (typically C:\Program Files\Kofax\AutoStore\ASWebForSharp\Web.Config).
2. Locate the line: <sessionState mode="InProc" ... cookieless="true" timeout="20"/>
3. Change cookieless="true" to cookieless="false".
4. Save the file and restart the Sharp Capture component / AutoStore services.
5. Validate with an end-to-end scan from the physical Sharp device, not only a browser test, since browser testing alone will not reveal all remaining edge cases.
Alternative (temporary only, not recommended long-term):
Uninstalling the affected Windows update also resolves the issue. This is not a sustainable fix, as it leaves the security vulnerabilities addressed by the update unpatched. Use only as a short-term stopgap.
| Product | Version | Environment | Hardware |
|---|---|---|---|
| ControlSuite AutoStore (Sharp OSA Capture / ASWebForSharp) | 2025.2 | Windows Server 2019, Windows 10 (1809), Windows 11 24H2/25H2 with KB5120708, KB5126048, KB5126144, or KB5126052 installed | Sharp MFP devices (Sharp OSA) |
Windows updates confirmed or expected to trigger this issue (cumulative .NET Framework 3.5/4.7.2/4.8 security updates, August/September 2026):
KB5120708 (.NET Framework 3.5/4.8.1, August 2026, original source of the regression)
KB5121645 (.NET Framework 3.5/4.7.2/4.8, August 2026, Windows Server 2019 / Windows 10 1809, same release date as KB5120708)
KB5126048 (.NET Framework 3.5/4.8, September 2026, Windows Server 2019 / Windows 10 1809)
KB5126144 (.NET Framework 3.5/4.7.2/4.8, September 2026, Windows Server 2019)
KB5126052 (.NET Framework 3.5/4.8.1, September 2026, Windows 11 24H2/25H2)
Internal reference: "Sharp OSA Capture — Technical Handover for KB5120708 Regression", Tungsten development team, 2026-08-26.
See also: "Windows Update KB5120708 Breaks AutoStore Batch Web Service" (separate, unrelated defect affecting Batch.exe).
https://knowledge.tungstenautomation.com/bundle/z-kb-articles-salesforce11/page/45807.html
Windows Server 2019, Windows 10 (1809), Windows 11 24H2/25H2 with KB5120708, KB5121645, KB5126048, KB5126144, or KB5126052 installed