Skip to content
Pro IT NW

Blog · 5 min read ·

Share

RDS can stop responding after the September 2026 update

Microsoft opened this Remote Desktop Services known issue September 11, 2026, and lists it Mitigated — not Resolved — as of September 13, 2026. Microsoft says it is "working to release a resolution"; no date is set.

If you run Remote Desktop Services — session hosts, an RD Gateway, or an RDP-reachable admin jump box — the September 2026 Windows security update is worth reading before you finish rolling it out. Microsoft has confirmed a known issue: RDS may become unstable, with RDP failing after several minutes, sign-in issues, or servers hanging at "Please wait for the Remote Desktop Configuration". MMC, the RDS Licensing Diagnoser, and File Explorer can also stop responding, and Windows Update can hang on a loading indicator.

Microsoft opened the issue September 11, 2026 at 11:19 AM Pacific, updated it that day at 7:20 PM Pacific, and as of September 13, 2026 lists it Mitigated — not Resolved. The timing complicates the obvious response: the September 2026 update cycle also closes two Windows privilege-escalation CVEs — one per version — which CISA added to its KEV catalog on September 8, 2026, the day the update shipped, and which Microsoft marks as having exploitation detected. Holding the update back is not free.

The one-sentence version: the September 2026 update cycle — which closes two exploited Windows privilege-escalation bugs, one per version — can also destabilize RDS. Stage the rollout by pilot ring with console access on standby; don't skip or uninstall it fleet-wide.

What Microsoft's known issue actually says

Microsoft's release health page describes the problem in its own words: "After installing the September 2026 Windows security update (KB…), some organizations might experience issues with Remote Desktop Services (RDS). In some environments, RDS might become unstable, resulting in RDP connections failing after several minutes, sign-in issues, or servers hanging at 'Please wait for the Remote Desktop Configuration'. Related tools, including Microsoft Management Console (MMC), RDS Licensing Diagnoser, and File Explorer might also become unresponsive. Additionally, the Windows Update page might stop responding and continuously display a loading indicator."

Affected platforms, per Microsoft:

  • Client: Windows 11, version 26H1; Windows 11, version 25H2; Windows 11, version 24H2; Windows 11, version 23H2; Windows 10, version 22H2; Windows 10, version 21H2; Windows 10 Enterprise LTSC 2019; Windows 10 Enterprise LTSC 2016
  • Server: Windows Server 2025; Windows Server 2022; Windows Server 2019; Windows Server 2016; Windows Server 2012 R2; Windows Server 2012

The list runs from Windows Server 2012 through 2025 and Windows 10 through Windows 11 26H1.

Every server version has its own KB — this table is the point of this post

KB5124008 is the Windows 11 24H2/25H2 package. If you administer Windows Server, your originating KB is a different number. Each row comes from that version's release health page; every originating update is dated 2026-09-08:

VersionOriginating update (RDS issue)OS buildCloses KEV CVE
Windows Server 2025KB512287126100.33438CVE-2026-81963
Windows Server 2022KB512288220348.5622CVE-2026-85880
Windows Server 2019 (and Windows 10, version 1809)KB512287617763.9245CVE-2026-85880
Windows Server 2016 (and Windows 10, version 1607)KB512309914393.9512CVE-2026-85880
Windows 11, version 24H2 / 25H2KB512400826100.9445CVE-2026-81963
Windows 10, version 22H2KB512287819045.7725CVE-2026-85880
Windows Server 2012 / 2012 R2Listed as affected — check each version's release health page for the RDS-issue KBCVE-2026-85880 (KB5123065 / KB5123066 per MSRC CVRF)

Why this isn't a reason to skip the update

The same update cycle also closes two Windows privilege-escalation CVEs CISA added to its KEV catalog that date — CVE-2026-81963 (Windows Update Stack) and CVE-2026-85880 (Windows ALPC) — each closed by a different subset of the KBs above, not both by every update. Microsoft's guide marks both "Exploitation Detected." KEV publishes no CVSS score, and its due dates bind federal civilian agencies, not private companies — but confirmed exploitation is worth patching regardless. We cover the broader "patch, then assume compromise" posture in our standing KEV piece. Uninstalling a version's update to dodge the RDS symptom trades a regression with a VM-only workaround for reopening the CVE that update closed.

The status is Mitigated, not Resolved

Microsoft's own label for this issue is Mitigated. The page doesn't define that term, so we won't guess at it — the status shown is Mitigated, not Resolved, and Microsoft's next step is only that it is "working to release a resolution in a future Windows update and will provide more information when available." No fix version or date is published as of September 13, 2026. Treat "Mitigated" as "still active, watch this page," not "handled."

The workaround, and where it doesn't reach

Microsoft's published workaround is narrow: "If a virtual machine becomes inaccessible through RDP, customers may be able to temporarily restore connectivity by stopping (deallocating) and restarting the affected virtual machine." That's written for VMs — Microsoft did not say this about physical hosts. If a physical RDS host hangs, you're on console or out-of-band access, not a documented Microsoft workaround.

Our advice: stage the rollout, don't stand it down

For RDS session hosts, RD Gateways, or RDP-reachable jump hosts, the right response is a controlled sequence, not all-at-once or held-back-everywhere. This part is our judgment, not Microsoft's:

  • Pilot ring first. Patch a small, non-critical group per the KB table above and watch for the symptoms above before expanding.
  • Check the release health entry before each ring — check whether the status has moved to Resolved (and a fix KB is named), and whether a new symptom has been added.
  • Keep console or out-of-band access to RDS hosts during the rollout; a hang at the RDP layer means you need a path in that doesn't depend on RDP.
  • Know the VM workaround's scope before you need it — Microsoft's fix for a hung VM is stopping (deallocating) and restarting it; plan a separate console-based path for anything physical.

Related reading

Sources

The 30-second version

The September 2026 update cycle closes two exploited Windows privilege-escalation bugs — one per version — and, on some systems, can also make RDS unstable. Opened September 11, 2026; status Mitigated, not Resolved, as of September 13, with Microsoft "working to release a resolution in a future Windows update" and no date set. Each Windows Server version has its own KB and closes one of the two CVEs — see the table above. Don't uninstall a version's update; that reopens the exploited bug it closed. Stage the rollout by ring, watch the release health page between rings, and keep console access to RDS hosts until the fix lands.

If you want a senior engineer to sequence this rollout, the project intake form takes about three minutes. We'll come back with scope and a fixed-fee range.


Pro IT NW does not resell Microsoft licensing or support contracts. This post reflects Microsoft's published release health guidance as of September 13, 2026, plus our own judgment on sequencing — not Microsoft's guidance. Senior-led, labor-only, fixed fee.

Questions we get asked

What is the September 2026 Remote Desktop Services known issue?
After installing the September 2026 Windows security update, Microsoft has confirmed that some organizations may see Remote Desktop Services (RDS) become unstable, resulting in RDP connections failing after several minutes, sign-in issues, or servers hanging at "Please wait for the Remote Desktop Configuration". Related tools including Microsoft Management Console, the RDS Licensing Diagnoser, and File Explorer can also become unresponsive, and the Windows Update page itself can hang on a loading indicator. Microsoft opened the issue on September 11, 2026, and lists its status as Mitigated, not Resolved, as of September 13, 2026.
Which KB is responsible for the RDS issue on my Windows Server version?
There isn't one shared KB — each version has its own originating update. Windows Server 2025 is KB5122871 (OS build 26100.33438). Windows Server 2022 is KB5122882 (20348.5622). Windows Server 2019 (and Windows 10, version 1809) is KB5122876 (17763.9245). Windows Server 2016 (and Windows 10, version 1607) is KB5123099 (14393.9512). Windows 11, version 24H2 and 25H2 is KB5124008 (26100.9445). Windows 10, version 22H2 is KB5122878 (19045.7725). Windows Server 2012 and 2012 R2 are listed among the affected platforms, but check that version's own Microsoft release health page for its specific KB.
Is the Remote Desktop Services issue fixed now?
No. Microsoft's release health entry lists the status as Mitigated, and Microsoft's stated next step is only that it is "working to release a resolution in a future Windows update and will provide more information when available." The issue was opened September 11, 2026 at 11:19 AM Pacific and last updated the same day at 7:20 PM Pacific. As of September 13, 2026, no Resolved status or fix date has been published.
Should we skip or uninstall the September 2026 security update to avoid the RDS issue?
We would advise against it. The same September 2026 update cycle that carries this RDS regression also closes two Windows privilege-escalation CVEs CISA added to its Known Exploited Vulnerabilities catalog on September 8, 2026 — CVE-2026-81963 (Windows Update Stack elevation-of-privilege) and CVE-2026-85880 (Windows ALPC elevation-of-privilege), each closed by a different subset of the KBs, not both by every update — and Microsoft's update guide marks both as having exploitation detected. Skipping or broadly uninstalling a version's update to avoid the RDS regression means leaving that version's exploited privilege-escalation CVE open on hosts where a user or attacker already has a foothold, such as RDS session hosts. Our recommendation is to stage the rollout across RDS roles rather than hold the update back fleet-wide.
What is the workaround if RDP stops working after the update?
Microsoft's published workaround is written specifically for virtual machines: "If a virtual machine becomes inaccessible through RDP, customers may be able to temporarily restore connectivity by stopping (deallocating) and restarting the affected virtual machine." That is Microsoft's own wording, and it applies to VMs — it is not a documented fix for physical RDS hosts, and it should not be assumed to work the same way on physical hardware just because it works for a VM.

Written by the team at · Senior-led Microsoft project consultancy · Seattle and the Pacific Northwest, delivered USA-wide.

Have a project on the runway?

Tell us the workload, the seat count, and the deadline. We'll come back with scope and a fixed-fee range.