September’s Windows Updates Can Freeze Remote Desktop and Leave Administrators Outside
Microsoft says September’s Windows security updates can make Remote Desktop Services unstable. Connections may fail after several minutes, sign-ins can stop working and servers can hang while waiting for Remote Desktop configuration. In the worst operational case, the update intended to protect a server can leave its administrators outside it.
The company lists the issue across Windows Server releases from Server 2012 through Server 2025 and across supported Windows 10 and Windows 11 versions. Microsoft has labelled the issue mitigated, but it has not released a permanent fix. Its published workaround is a temporary recovery action for virtual machines that have become inaccessible through RDP.
This is not a cyberattack and Microsoft has not described it as a vulnerability. It is a servicing regression with security consequences for patch planning: organisations still need the September fixes, but Remote Desktop estates now require a tested route back into a machine if the normal route freezes.
The connection can work first and fail minutes later
Microsoft opened the known-issue record on 11 September 2026, three days after the September security updates were released. The company says that some organisations may experience Remote Desktop Services instability after installing the update.
Reported symptoms include RDP connections failing after several minutes, sign-in problems and servers hanging at “Please wait for the Remote Desktop Configuration”. The failure is not limited to the remote session itself. Microsoft Management Console, RDS Licensing Diagnoser and File Explorer may become unresponsive. The Windows Update page may also remain stuck on a loading indicator.
That combination can turn a routine deployment into an access and recovery incident. A server may be running while the tools normally used to diagnose, license, update and administer it are unavailable or unreliable.
“Mitigated” does not mean fixed
Microsoft’s release-health dashboard marks the issue as mitigated. The mitigation is narrow: if a virtual machine becomes inaccessible through RDP, customers may be able to restore connectivity temporarily by stopping, deallocating and restarting that virtual machine.
The wording matters. Microsoft says the action “may” restore connectivity and describes the result as temporary. Stopping and deallocating a production virtual machine is also a service interruption, not a transparent repair. The guidance does not promise that a normal guest restart has the same effect, and it does not provide an equivalent recovery procedure for a physical Remote Desktop server.
Microsoft says it is working on a resolution for a future Windows update. It has not published a release date, root cause or permanent configuration workaround.
Affected Windows platforms
| Platform family | Versions Microsoft lists as affected |
|---|---|
| Windows Server | Windows Server 2025, 2022, 2019, 2016, 2012 R2 and 2012 |
| Windows 11 | Versions 26H1, 25H2, 24H2 and 23H2 |
| Windows 10 | Versions 22H2 and 21H2, plus Enterprise LTSC 2019 and Enterprise LTSC 2016 |
On Windows Server 2025, Microsoft identifies KB5122871, OS Build 26100.33438, as the originating update. On Windows 11 version 26H1, the corresponding release-health page identifies KB5124012, OS Build 28000.2954. Administrators should check the release-health page for the exact Windows version they operate rather than applying one KB number across the entire estate.
Microsoft has not said that every device on those platforms will fail. Its language is limited to some organisations and some environments. The company has not disclosed how many devices are affected or which RDS roles, policies, infrastructure patterns or workloads trigger the instability.
Why removing the security update is not the default answer
The September release contains security fixes, including updates for vulnerabilities Microsoft says are already being exploited. BlackTree’s September Patch Tuesday analysis separates those urgent attack paths from the rest of the monthly workload.
Removing a cumulative update can restore an older software state, but it can also reopen vulnerabilities that the maintenance was meant to close. Microsoft has not advised customers in its public release-health entry to uninstall the September update. A blanket removal across affected platform names would therefore exchange a confirmed operational risk in some environments for known security exposure across all rolled-back systems.
The safer decision is service-specific. Test the actual RDS workload, confirm a recovery path and control the rollout rings. Where business impact forces a rollback decision, record which security fixes are being removed, apply compensating controls and restore the current update as soon as Microsoft provides a validated resolution.
What Windows and infrastructure teams should do now
- Identify Remote Desktop dependencies. Find session hosts, connection brokers, licensing servers, jump hosts, administrative endpoints and ordinary servers whose only practical management route is RDP.
- Map the installed September update. Record the operating-system version, build and KB on each affected role. Use Microsoft’s version-specific release-health page to confirm applicability.
- Pause broad RDS rollout long enough to test. Use a representative pilot for each operating-system and RDS role. Test connection establishment, session stability over time, sign-in, licensing diagnostics, MMC, File Explorer and Windows Update.
- Prepare out-of-band access before maintenance. Confirm hypervisor, cloud-console, lights-out-management or local access. Test the credentials and authorisation required to stop or restart a machine without RDP.
- Plan the deallocation consequence. For virtual machines, document service interruption, cluster or broker behaviour, storage implications and dependencies before using Microsoft’s temporary recovery step.
- Preserve diagnostic evidence. If a system becomes unstable, capture relevant event logs, service state, update history and timing before a disruptive restart where possible. This can help distinguish the known issue from an unrelated access failure.
- Avoid an estate-wide uninstall reflex. Escalate systems with intolerable impact through the organisation’s change and risk process, accounting for the vulnerabilities restored by rollback.
- Monitor Microsoft’s release-health record. The current workaround is temporary. Validate the permanent update in a pilot before resuming the full deployment.
What remains unknown
Microsoft has not published the technical root cause, prevalence, precise trigger, full role matrix or date for a permanent fix. It has not said that attackers are exploiting the regression or that installing the update creates a security compromise.
What is known is enough to change the rollout plan. Remote administration is itself a business dependency. Before the next RDS server receives September’s update, the organisation should know how it will confirm that sessions remain stable and how it will regain control if the main administrative door stops opening.
Sources
- Microsoft Windows Server 2025 release health, issue opened 11 September 2026 at 11:19 PT and last updated 11 September at 19:20 PT.
- Microsoft Windows 11 version 26H1 release health, version-specific record for the same RDS issue and KB5124012.
- Microsoft: September 8, 2026, KB5122871, OS Build 26100.33438, Windows Server 2025 security-update details.


