Skip to content
Pro IT NW

Blog · 6 min read ·

Share

RDS can stop responding after the September 2026 update

Microsoft opened this Remote Desktop Services known issue September 11, 2026, listed it Mitigated in the interim, and resolved it September 14, 2026 with out-of-band cumulative updates — a different KB per Windows version. Administrators who deployed a temporary mitigation through Group Policy do not need to take any action before installing the update.

If you run Remote Desktop Services — session hosts, an RD Gateway, or an RDP-reachable admin jump box — the September 2026 Windows security update is worth reading before you finish rolling it out. Microsoft has confirmed a known issue: RDS may become unstable, with RDP failing after several minutes, sign-in issues, or servers hanging at "Please wait for the Remote Desktop Configuration". MMC, the RDS Licensing Diagnoser, and File Explorer can also stop responding, and Windows Update can hang on a loading indicator.

Microsoft opened the issue September 11, 2026 at 11:19 AM Pacific, updated it that day at 7:20 PM Pacific, and listed it Mitigated until September 14, 2026, when Microsoft resolved it with an out-of-band cumulative update — a different KB per Windows version. If you installed the original September 8 update and paused on a Group Policy mitigation, the fix is now out and no further action is needed before you install it. The same update cycle also closes two Windows privilege-escalation CVEs — one per version — which CISA added to its KEV catalog on September 8, 2026, the day the update shipped, and which Microsoft marks as having exploitation detected.

The one-sentence version: the September 2026 update cycle — which closes two exploited Windows privilege-escalation bugs, one per version — destabilized RDS on some systems; Microsoft resolved it September 14, 2026 with a cumulative out-of-band update per version. Install that update; don't skip or uninstall the original fleet-wide.

What Microsoft's known issue actually says

Microsoft's release health page describes the problem in its own words: "After installing the September 2026 Windows security update (KB…), some organizations might experience issues with Remote Desktop Services (RDS). In some environments, RDS might become unstable, resulting in RDP connections failing after several minutes, sign-in issues, or servers hanging at 'Please wait for the Remote Desktop Configuration'. Related tools, including Microsoft Management Console (MMC), RDS Licensing Diagnoser, and File Explorer might also become unresponsive. Additionally, the Windows Update page might stop responding and continuously display a loading indicator."

Affected platforms, per Microsoft:

  • Client: Windows 11, version 26H1; Windows 11, version 25H2; Windows 11, version 24H2; Windows 11, version 23H2; Windows 10, version 22H2; Windows 10, version 21H2; Windows 10 Enterprise LTSC 2019; Windows 10 Enterprise LTSC 2016
  • Server: Windows Server 2025; Windows Server 2022; Windows Server 2019; Windows Server 2016; Windows Server 2012 R2; Windows Server 2012

The list runs from Windows Server 2012 through 2025 and Windows 10 through Windows 11 26H1.

Every server version has its own KB — this table is the point of this post

KB5124008 is the Windows 11 24H2/25H2 package. If you administer Windows Server, your originating KB is a different number. Each row comes from that version's release health page; every originating update is dated 2026-09-08. Microsoft resolved the RDS issue for every version below on September 14, 2026, 10:00 Pacific, with the out-of-band (OOB) update in the fourth column — each one is cumulative, so it includes everything the originating update did:

VersionOriginating update (RDS issue)OS buildOOB fix (resolved Sept 14, 2026)Closes KEV CVE
Windows Server 2025KB512287126100.33438KB5129235CVE-2026-81963
Windows Server 2022KB512288220348.5622KB5129237CVE-2026-85880
Windows Server 2019 (and Windows 10, version 1809)KB512287617763.9245KB5129238CVE-2026-85880
Windows Server 2016 (and Windows 10, version 1607)KB512309914393.9512KB5129239CVE-2026-85880
Windows 11, version 24H2KB512400826100.9445KB5129195CVE-2026-81963
Windows 11, version 25H2KB512400826200.9445KB5129195CVE-2026-81963
Windows 10, version 22H2KB512287819045.7725KB5129236CVE-2026-85880
Windows Server 2012 / 2012 R2Listed as affected — check each version's release health page for the RDS-issue KB—Check that version's release health page for the OOB fix KBCVE-2026-85880 (KB5123065 / KB5123066 per MSRC CVRF)

Why this isn't a reason to skip the update

The same update cycle also closes two Windows privilege-escalation CVEs CISA added to its KEV catalog that date — CVE-2026-81963 (Windows Update Stack) and CVE-2026-85880 (Windows ALPC) — each closed by a different subset of the KBs above, not both by every update. Microsoft's guide marks both "Exploitation Detected." KEV publishes no CVSS score, and its due dates bind federal civilian agencies, not private companies — but confirmed exploitation is worth patching regardless. We cover the broader "patch, then assume compromise" posture in our standing KEV piece. Uninstalling a version's update to dodge the RDS symptom trades a regression with a VM-only workaround for reopening the CVE that update closed.

The fix: install the out-of-band update

Microsoft resolved this issue on September 14, 2026, 10:00 Pacific, with an out-of-band (OOB) update — a different KB per Windows version, listed in the table above. If you already deployed a temporary mitigation through Group Policy, you do not need to take any action before installing this OOB update. The OOB update is cumulative and includes all the security protections from the original September 2026 update and every update before it, so there's nothing separate to install first. Microsoft's release health note also says this issue does not affect Windows 365 or Azure Virtual Desktop.

The interim workaround, now history

While the issue was open, Microsoft's published workaround was narrow: "If a virtual machine becomes inaccessible through RDP, customers may be able to temporarily restore connectivity by stopping (deallocating) and restarting the affected virtual machine." That was written for VMs — Microsoft did not say this about physical hosts, and a hung physical RDS host had no documented Microsoft workaround beyond console or out-of-band access. With the out-of-band fix resolved September 14, 2026, install it (or any later cumulative update) rather than relying on this workaround now.

Our advice: install the out-of-band update by ring, don't stand it down

For RDS session hosts, RD Gateways, or RDP-reachable jump hosts that haven't yet taken the September 2026 update cycle, the right response is a controlled sequence with the out-of-band fix, not all-at-once or held back indefinitely. This part is our judgment, not Microsoft's:

  • Pilot ring first. Patch a small, non-critical group with the out-of-band KB from the table above and confirm the group is stable before expanding.
  • Confirm you're on the OOB KB or later for your version — the fix is cumulative, so any update released after September 14, 2026 already includes it.
  • Keep console or out-of-band access to RDS hosts during the rollout; a hang at the RDP layer means you need a path in that doesn't depend on RDP.
  • Know the VM workaround's scope if a host was already affected before you patched it — Microsoft's fix for a hung VM is stopping (deallocating) and restarting it; plan a separate console-based path for anything physical.

Related reading

Sources

The 30-second version

The September 2026 update cycle closes two exploited Windows privilege-escalation bugs — one per version — and, on some systems, also made RDS unstable. Opened September 11, 2026; resolved September 14, 2026, with an out-of-band cumulative update — a different KB per Windows version — see the table above. If you already applied a Group Policy mitigation, no further action is needed before installing the fix. Don't uninstall a version's original update; that reopens the exploited bug it closed. Install the out-of-band update (or any later cumulative update) for your version, and keep console access to RDS hosts during rollout as a precaution.

If you want a senior engineer to sequence this rollout, the project intake form takes about three minutes. We'll come back with scope and a fixed-fee range.


Pro IT NW does not resell Microsoft licensing or support contracts. This post reflects Microsoft's published release health guidance as of September 18, 2026 (this issue was resolved September 14, 2026), plus our own judgment on sequencing — not Microsoft's guidance. Senior-led, labor-only, fixed fee.

Questions we get asked

What is the September 2026 Remote Desktop Services known issue?
After installing the September 2026 Windows security update, Microsoft confirmed that some organizations saw Remote Desktop Services (RDS) become unstable, resulting in RDP connections failing after several minutes, sign-in issues, or servers hanging at "Please wait for the Remote Desktop Configuration". Related tools including Microsoft Management Console, the RDS Licensing Diagnoser, and File Explorer could also become unresponsive, and the Windows Update page itself could hang on a loading indicator. Microsoft opened the issue on September 11, 2026, listed it Mitigated in the meantime, and resolved it September 14, 2026 with an out-of-band cumulative update — a different KB for each Windows version. This issue does not affect Windows 365 or Azure Virtual Desktop.
Which KB is responsible for the RDS issue on my Windows Server version?
There isn't one shared KB — each version has its own originating update. Windows Server 2025 is KB5122871 (OS build 26100.33438). Windows Server 2022 is KB5122882 (20348.5622). Windows Server 2019 (and Windows 10, version 1809) is KB5122876 (17763.9245). Windows Server 2016 (and Windows 10, version 1607) is KB5123099 (14393.9512). Windows 11, version 24H2 and 25H2 both trace to KB5124008, but the OS build differs by version: 24H2 is build 26100.9445, 25H2 is build 26200.9445. Windows 10, version 22H2 is KB5122878 (19045.7725). Windows Server 2012 and 2012 R2 are listed among the affected platforms, but check that version's own Microsoft release health page for its specific KB.
Is the Remote Desktop Services issue fixed now?
Yes. Microsoft resolved this issue on September 14, 2026, 10:00 Pacific, with an out-of-band cumulative update — a different KB for each Windows version (for example KB5129235 for Windows Server 2025). The issue was opened September 11, 2026 at 11:19 AM Pacific and listed Mitigated in the interim; some administrators deployed a temporary mitigation through Group Policy during that window. IT administrators who already deployed that Group Policy mitigation do not need to take any action before installing the out-of-band update, which is cumulative and includes all the security protections from earlier Windows updates.
Should we have skipped or uninstalled the September 2026 security update to avoid the RDS issue?
No — and now that Microsoft has resolved the issue, the question is moot. The same September 2026 update cycle that carried this RDS regression also closed two Windows privilege-escalation CVEs CISA added to its Known Exploited Vulnerabilities catalog on September 8, 2026 — CVE-2026-81963 (Windows Update Stack elevation-of-privilege) and CVE-2026-85880 (Windows ALPC elevation-of-privilege), each closed by a different subset of the KBs, not both by every update — and Microsoft's update guide marked both as having exploitation detected. Skipping or broadly uninstalling a version's update to avoid the RDS regression would have left that version's exploited privilege-escalation CVE open on hosts where a user or attacker already has a foothold, such as RDS session hosts. Our recommendation, while the issue was open, was to stage the rollout across RDS roles rather than hold the update back fleet-wide; now install the out-of-band fix (or any later cumulative update) rather than skipping either update.
What is the workaround if RDP stops working after the update?
Microsoft's published workaround is written specifically for virtual machines: "If a virtual machine becomes inaccessible through RDP, customers may be able to temporarily restore connectivity by stopping (deallocating) and restarting the affected virtual machine." That is Microsoft's own wording, and it applies to VMs — it is not a documented fix for physical RDS hosts, and it should not be assumed to work the same way on physical hardware just because it works for a VM.

Written by the team at · Senior-led Microsoft project consultancy · Seattle and the Pacific Northwest, delivered USA-wide.

Have a project on the runway?

Tell us the workload, the seat count, and the deadline. We'll come back with scope and a fixed-fee range.