Hi Harry,
What happened is the vendor’s update was signed a little differently than before, so your existing AppLocker rule no longer recognizes it. Even though the signature looks valid, AppLocker checks more than just the certificate, things like product name or version can break the match if they change. The fix is simple: create a new publisher rule directly from the updated file so AppLocker learns the new signature details. Also make sure the certificate chain is trusted on the client machines under Trusted Publishers. Once the rule is refreshed, future updates from that vendor should run without being blocked.