NEWS
September Updates Freeze Remote Desktop on Windows Server
September Windows Server security updates freeze Remote Desktop hours after install, even as they patch a 9.8 RDS remote code execution bug.
September’s Windows Server security updates freeze Remote Desktop Services hours after install, then the only full uninstall path drops this month’s RDS code-execution patch. The cumulative updates shipped on 8 September 2026 as KB5122876, KB5122882 and KB5122871. Hosts take the patch, run for a while, and then new sessions stick while old ones cannot log off.
Microsoft added a known issue on the Server 2025 update on 12 September and had already listed the hang as mitigated on the release-health dashboard the evening before. The KB article still tells administrators to call Support for Business and wait for a later Windows update.
Remote Desktop Dies Hours After the September Patch
Admins who installed the September cumulative updates say the box looks healthy at first. Terminal servers take logons, brokers hand out sessions, and nothing in Event Viewer screams. After a few hours, and often after the first logout, new Remote Desktop connections hang and existing sessions will not disconnect cleanly.
Microsoft’s own write-up is slightly different on timing. It says some organisations see RDP connections fail after several minutes, hit sign-in problems, or stall on “Please wait for the Remote Desktop Configuration.” Related tools go with them. Microsoft Management Console, RDS Licensing Diagnoser and File Explorer can freeze, and the Windows Update page can sit on a spinner.
The loudest reports landed on the three current server releases, but Microsoft’s affected list is longer. It names Windows Server 2025, 2022, 2019, 2016, 2012 R2 and 2012, plus Windows 11 versions 26H1 through 23H2 and Windows 10 22H2, 21H2, Enterprise LTSC 2019 and Enterprise LTSC 2016. Citrix, watching its Virtual Delivery Agents, logged the same hang on those server KBs and on Windows 11 packages KB5124008 and KB5120998.
AFFECTED SERVER UPDATES AND BUILDS
| Windows Server | Cumulative update | OS build | KIR package stamp |
|---|---|---|---|
| Server 2025 | KB5122871 | 26100.33438 | 260911_18472 |
| Server 2022 | KB5122882 | 20348.5622 | 260911_18471 |
| Server 2019 | KB5122876 | 17763.9245 | 260911_18474 |
| Server 2016 | KB5123099 | unlisted | 260911_18473 |
KB5122871 also ships servicing stack update KB5122870 at 26100.33434, and the same package claims a Remote Desktop audio-redirection fix. That is the same servicing wave that later seizes the session host. Server 2012 R2 is on the dashboard against KB5123066. Once a host tips over, a normal restart often hangs with it, so shops have been reaching for a hard reset or a hypervisor power-off.
CVE-2026-69525 Makes Uninstalling the Update Costly
Pulling the cumulative update brings Remote Desktop back. It also removes every security fix in that package. Tenable counted 964 CVEs in the September release, 104 of them Critical and 860 Important, including two flaws already used in attacks, CVE-2026-81963 and CVE-2026-85880.
The one that should stop a blunt rollback on an RDS farm is CVE-2026-69525. Microsoft’s Security Update Guide describes a use-after-free in Remote Desktop Services that lets an unauthorised attacker run code over a network. The base CVSS score is 9.8 (temporal 8.5). Microsoft rated the severity Important, set exploitability to Exploitation More Likely, and said it was not publicly disclosed and not exploited when the patch shipped.
CVE-2026-69525 AT RELEASE
- Base score: Microsoft published CVSS 3.1 9.8, with a temporal score of 8.5.
- Weakness: CWE-416, use after free, in Windows Remote Desktop Services.
- Attack path: Microsoft said an in-network attacker can call arbitrary endpoints and gain remote code execution.
- Exploit status: Not exploited and not publicly disclosed on 8 September, with Exploitation More Likely on Microsoft’s index.
Ruud, a Microsoft MVP posting as LazyAdmin, put the bind in two lines: “But the same update patches a CVSS 9.8 RDS RCE. Don’t just roll back.” Shops that already uninstalled the CU to restore logons are now running session hosts without that 9.8 fix, and without the two exploited zero-days, until they can put the package back and apply a narrower rollback.
What Happens When the First User Logs Off?
The failure is easy to miss in a quiet lab. A freshly patched session host will take the first wave of users. Trouble starts when those users disconnect or sign out and Local Session Manager has to tear the session down.
An administrator debugging Windows Server 2022 said the RDP service became unresponsive at logout and that a debugger sat in RDPSERVERBASE!WDLIB_Close with no timeout, producing a deadlock between Remote Desktop and Local Session Manager. Microsoft has not confirmed that stack trace as the cause. The behaviour still matches what independent farms are seeing: one stuck teardown blocks the next logon, the next logoff, and any tool that asks LSM for session state.
Citrix’s VDA note describes new connections hanging a few hours after reboot on “Connecting…” while existing users cannot log off. TermService shows StopPending instead of Running. Task Manager, Settings and query user wait on LSM and never come back. On a physical box that often means walking into the rack. On a virtual machine Microsoft says stopping (deallocating) and restarting can restore RDP for a while, which is a cloud-shaped version of the same hard reset.
Event 20498, a Hard Reset, and Frozen MMC Consoles
The log signatures are consistent enough to hunt before the host is fully dead. Citrix published three of them as the tell for this hang, and they match what session-host operators have been pasting around.
SIGNATURES THAT SHOW THE HANG
- Event 20498: TerminalServices-RemoteConnectionManager logs that Remote Desktop Services has taken too long to complete the client connection.
- Event 6005: Winlogon warns that the SessionEnv subscriber is taking a long time to handle the Disconnect notification.
- TermService: The service sits in StopPending rather than Running, so a normal service restart does not clear it.
- Console freeze: MMC, RDS Licensing Diagnoser, File Explorer and the Windows Update page stop responding once LSM is stuck.
One operator wrote that every terminal server in the environment failed within a day, with sessions dropping, no new connections, and a hard reset as the only recovery. Another said Remote Desktop worked until the first logout, after which nobody could sign in, and that a reboot did not help until the September update came off. Keep a BMC, iLO, hypervisor console or serial session before you patch the next host, because RDP is the thing that goes away.
Citrix Session Hosts and Azure VMs Share the Hang
This is not only a classic RD Session Host farm problem. Citrix said it is watching multiple issues after the September rollup on server and desktop VDAs, including the hung “Connecting…” state and a separate black screen at logon on desktop OS VDAs after KB5124008 or KB5120998. Those brokers sit in front of the same Windows session stack, so a deadlock in LSM takes the published desktop with it.
Azure shops get a slightly softer landing if the VM still answers the fabric. Microsoft’s workaround on the release-health page is to deallocate and restart the VM when RDP is gone. That does not fix a physical session host in a cupboard, and it does not stop the hang from coming back hours later if the cumulative update stays on. Multi-session hosts are worse than a jump box, because they generate the logoffs that seem to trip the deadlock.
The same KB5122871 package that breaks those hosts also lists a Remote Desktop audio-redirection improvement. The servicing train touched RDS on purpose this month, then left session teardown in a state where a farm can look fine until people actually use it.
Microsoft’s Dashboard Says Mitigated
The public story from Microsoft moved in pieces, and the pieces still do not agree. Administrators were already rolling back when the known-issue record opened at 11:19 PT on 11 September. By 19:20 PT that same day the dashboard status was Mitigated. The Server 2025 KB changelog caught up on 12 September. Citrix’s support note, created that morning and last published at 17:36, is what actually pointed customers at the Group Policy packages.
HOW MICROSOFT’S RECORD MOVED
- September 8, 2026: Patch Tuesday ships KB5122876, KB5122882, KB5122871 and the older-SKU rollups, including the CVE-2026-69525 fix.
- September 11, 2026, 11:19 PT: Microsoft opens the known issue “Remote Desktop Services might stop responding after Sept. 2026 security update.”
- September 11, 2026, 19:20 PT: Status on the release-health dashboard changes to Mitigated, with a deallocate-and-restart workaround for virtual machines.
- September 12, 2026: The KB5122871 changelog adds the known issue; Citrix publishes the KIR MSI links for Server 2016 through Server 2025.
Mitigated, in Microsoft’s servicing language, means a Known Issue Rollback is available, not that the code is fixed. The KB page still says administrators who need an immediate workaround should contact Support for Business, and that Microsoft is working on a future Windows update. Teams that only read the article can miss the MSI files sitting on the Download Center.
This is not the first Patch Tuesday to kick RDS. In July 2024 Microsoft confirmed that month’s security updates broke remote desktop connections on servers still using the older RPC over HTTP path on Remote Desktop Gateway, with sessions dropping about every 30 minutes. The September 2026 hang is broader. It does not need that legacy gateway setting, and it takes the session host itself.
How Do You Keep the Security Fixes?
The useful path is the KIR, which turns off the offending change and leaves the rest of the cumulative update in place, including CVE-2026-69525. Microsoft’s own KIR documentation splits devices in two. Consumer and unmanaged PCs can receive the rollback through Windows Update. Enterprise-managed devices, which is every RDS farm that matters, get a Group Policy template from the Download Center and have to apply it.
After installing the September 2026 Windows security update, some organizations might experience issues with Remote Desktop Services (RDS). In some environments, RDS might become unstable, resulting in RDP connections failing after several minutes, sign-in issues, or servers hanging at “Please wait for the Remote Desktop Configuration”.
Microsoft, KB5122871 known issues, Windows Server 2025
Citrix spelled out the server packages. Server 2025 uses the Server 2025 Known Issue Rollback package stamped 260911_18472. Server 2022 is 260911_18471, Server 2019 is 260911_18474, and Server 2016 is 260911_18473. Windows 11 has its own MSIs, including a KB5124008 template that also names Server 2025, so match the file to the KB actually installed.
KIR STEPS THAT LEAVE THE CU INSTALLED
- Install the MSI: Run the matching Known Issue Rollback package on a machine that can edit Group Policy so the ADMX template registers.
- Set the policy to Disabled: Under Computer Configuration, Administrative Templates, open the KB’s Known Issue Rollback folder and set that policy to Disabled, which is how Microsoft turns the broken change off.
- Force a refresh: Run gpupdate /force on the session hosts, or wait for the next policy cycle, then restart so LSM and TermService come up with the rollback active.
Microsoft’s longer guide on how to deploy a Known Issue Rollback is the same playbook used for earlier servicing regressions. If a host is already wedged, you still need console or hypervisor access to get the policy on the box, or you uninstall the CU as a last resort and plan to put it back once KIR is in place. Microsoft has not given a date for the code-level fix that would make the GPO unnecessary.
Until that update ships, a patched RDS host without the KIR is a box that may lock out its own operators after a few hours of real use. A host that had the CU removed to restore logons is a box missing a 9.8 RDS remote-code-execution patch. The Group Policy template is the third path, and it is the one that keeps both the sessions and the security fixes.
-
NEWS1 month agoMeta’s Smart Glasses Sell a Light That Needed Two Patches
-
NEWS1 month agoGoogle’s Free AI Pro Year Is Three Different Deals
-
NEWS1 month agoApple’s New Mac Studio Clusters Local AI on the Desk
-
NEWS1 month agoSong Yadong Stops Umar Nurmagomedov the Only Way Left
-
NEWS2 months agoThe Mahape Fake Apple Raid Repeats a Dual-Shift Pattern
-
NEWS1 month agoOpenAI Agents Hit Hugging Face to Cheat a Test
-
ENTERTAINMENT1 month agoLanterns Puts Sinestro in a Cell and Lets Him Talk
-
ENTERTAINMENT2 months agoGomez Says She Never Ran the Wondermind Investors Backed
