During CPSI updates, a new folder and executable are created under c:\CPSI. Example: C:\cpsi\bin\version_1629224508
The new location for the executable requires a new firewall rule as well as new applocker or other software whitelisting rules. From what I can tell, there is no warning on where the new executable will go so all clients will be affected as soon as they update after a server patch. They wont be fixed until new rules/whitelists are created by IT and synchronized with the client.
Alternatively, move the CPSI executables to Program Files which is admin-protected