
Microsoft’s September 2026 cumulative security updates caused Remote Desktop Services (RDS) instability in some Windows Server environments. The issue could prevent new RDP connections, disrupt sign-in and leave several operating system components unresponsive.
Update — Microsoft confirms the issue and releases a resolution #
Since this article was first published, Microsoft has confirmed the incident as a known issue, expanded the documented scope and provided Known Issue Rollback (KIR) policies for managed environments.
On September 14, 2026, the company updated Windows Release Health and changed the incident status to Resolved. The resolution is delivered through cumulative out-of-band (OOB) updates specific to each Windows release and is also included in later updates. The current recommendation is to install the latest applicable update on affected systems.
The official scope includes Windows Server 2012, 2012 R2, 2016, 2019, 2022 and 2025, as well as affected Windows 10 and Windows 11 releases. The KIR mitigation remains documented below because it was the temporary response provided before the OOB update and can still be relevant during a phased deployment. Microsoft says administrators who already applied this Group Policy mitigation do not need to take any action before installing the OOB update.
What happened #
The first reports appeared after the September 8, 2026 security updates were installed. Administrators cited by BleepingComputer described servers that initially operated normally, then began rejecting connections or hanging when users signed out.
On September 12, Microsoft added the known issue to the update pages initially associated with Windows Server 2019, 2022 and 2025. The subsequent investigation confirmed a broader scope. One administrator’s debugging suggested a possible deadlock between Remote Desktop components and the Local Session Manager; Microsoft has not confirmed that hypothesis as the technical root cause.
Affected systems #
Microsoft lists the following Windows Server releases among the affected platforms. The second column identifies the September update associated with the temporary KIR package:
| Operating system | Associated KB / KIR download |
|---|---|
| Windows Server 2025 | KB5122871 — KIR Group Policy |
| Windows Server 2022 | KB5122882 — KIR Group Policy |
| Windows Server 2019 / Windows 10 1809 | KB5122876 — KIR Group Policy |
| Windows Server 2016 / Windows 10 1607 | KB5123099 — KIR Group Policy |
| Windows Server 2012 R2 | KB5123066 — KIR Group Policy |
| Windows Server 2012 | KB5123065 — KIR Group Policy |
Windows Release Health also includes Windows 11 26H1, 25H2, 24H2 and 23H2; Windows 10 22H2 and 21H2; and Windows 10 Enterprise LTSC 2019 and 2016. Microsoft says only some organizations might experience the issue and has not published criteria for predicting which servers or configurations will be affected.
Symptoms #
According to Microsoft, RDS could become unstable after the update was installed. Officially documented symptoms include:
- RDP connections failing after several minutes;
- sign-in issues;
- servers hanging at
Please wait for the Remote Desktop Configuration; - Microsoft Management Console, RDS Licensing Diagnoser and File Explorer becoming unresponsive;
- the Windows Update page continuously displaying a loading indicator.
Reports collected by BleepingComputer also describe existing sessions that cannot disconnect or sign out correctly, new connections that hang, and failures that start only several hours after patching or after the first logout. In some environments, administrators said a hard reset was required to recover service. These are operational reports, not a universal behaviour confirmed by Microsoft.
Impact on Remote Desktop Services #
On a shared Session Host, an outage does not affect just one session: it can block access for every user who depends on that server. The impact is particularly serious where RDS provides business applications, remote work access or administrative functions without an alternative access path.
Unresponsive tools such as MMC, RDS Licensing Diagnoser and File Explorer also make local diagnosis more difficult. If remote sessions stop responding, the team may need the virtual machine console, an out-of-band management interface or another pre-arranged administration method.
Official resolution and mitigation #
Current resolution: install the OOB update #
Microsoft now considers the issue resolved by out-of-band updates released on September 14, 2026 and by subsequent updates. These packages are cumulative and retain the improvements and security protections from previous updates. Administrators should install the latest update listed in Windows Release Health for the affected Windows release.
Temporary mitigation: Known Issue Rollback #
Before the OOB resolution, Microsoft provided KIR policy definition files for enterprise-managed devices. Known Issue Rollback disables only the non-security change that caused the regression while leaving the rest of the update, including its security fixes, in place.
To deploy this mitigation through Group Policy:
- identify and download the MSI file that matches the affected operating system;
- install the MSI on the computer used to manage Group Policy, which adds the policy definition to Administrative Templates;
- create or edit a GPO and configure the installed KIR policy under Computer Configuration > Administrative Templates;
- apply the policy to the affected devices and restart them.
Microsoft’s documentation says a restart is required to activate the rollback. The exact policy name depends on the installed KIR package, so administrators should use the template supplied for the correct operating system rather than reusing names or settings from another release.
A KIR is temporary. It is no longer required after the update that fixes the underlying issue has been installed.
Temporary workarounds #
When the resolution or official mitigation cannot yet be applied, there are temporary recovery options:
- Stop and start the virtual machine: Microsoft says this can temporarily restore RDS connectivity when the VM is no longer accessible through RDP. It is not a permanent fix.
- Restart the server: restarts and hard resets appear in operational reports, but the result was not consistent across all environments.
- Uninstall the September update: some administrators restored RDS by rolling back the cumulative update. This also removes the security fixes delivered in the September Patch Tuesday release and should be treated as a last resort, with risk assessment, testing and a plan to restore protection.
Uninstalling the full update is not the same as applying KIR. KIR selectively rolls back the problematic change; uninstalling removes the complete package and its security fixes.
Recommendations for administrators #
- Inventory RDS servers and confirm their Windows release, build and installed September update.
- Install the OOB update or a later update listed in Windows Release Health for each affected release.
- Use only the matching KIR package when the corrective update cannot yet be deployed immediately in a managed environment.
- Monitor service recovery, including new sign-ins, sign-outs, session stability and access to the tools identified by Microsoft.
- Maintain an alternative access path, such as a hypervisor console or out-of-band management, before working on Session Hosts that may stop accepting RDP.
- Treat update removal as a last resort, recording the security exception and defining when the corrected update will be installed.
Conclusion #
The incident initially appeared limited to newer Windows Server releases, but Microsoft subsequently confirmed a scope spanning Windows Server 2012 through 2025, as well as several client releases. KIR made it possible to mitigate the regression selectively in managed environments without removing the security fixes.
The current status is no longer investigation or mitigation only: Microsoft marked the issue as resolved by out-of-band updates released on September 14, 2026. Installing the latest applicable update should be the priority; workarounds and full update rollback are reserved for situations where the official resolution cannot yet be deployed.
Sources #
- BleepingComputer — Microsoft: September updates cause RDS failures on Windows Server
- BleepingComputer — September Windows Server updates break Remote Desktop Services
- Microsoft Windows Release Health — Windows Server 2025
- Microsoft Windows Release Health — Windows Server 2022
- Microsoft Windows Release Health — Windows Server 2012
- Microsoft Learn — Use Group Policy to deploy a Known Issue Rollback
- Microsoft — KB5122876 for Windows Server 2019
- Microsoft — KB5122882 for Windows Server 2022
- Microsoft — KB5122871 for Windows Server 2025