Microsoft admits Windows update server sync has been broken for over a week
WSUS synchronization failures have blocked enterprise Windows updates since July 13, 2026, with only new installations fully restored so far.

Key points
- Microsoft confirmed on its Windows health dashboard that Windows Server Update Services sync problems began around July 13, 2026.
- The fault affects Windows 10 version 1607 and later, plus Windows Server 2012 and later.
- A fix rolled out on Saturday restored sync for newly installed or rebuilt WSUS servers only.
- Servers that were already affected still cannot sync, and Microsoft says a further fix is in progress.
- This is the fourth WSUS sync failure Microsoft has publicly acknowledged in roughly a year.
Microsoft has confirmed that a core piece of plumbing used by corporate IT departments to push Windows updates has been broken for more than a week.
The tool is called Windows Server Update Services, or WSUS. Think of it as a middleman. Instead of every office laptop downloading updates directly from Microsoft, the company's local WSUS server fetches them once and hands them out internally. It has been doing this job for nearly twenty years.
Right now, that middleman is stuck.
What actually broke?
WSUS is supposed to check in with Microsoft's update servers once a day to grab the latest information about available patches. On affected servers, that check-in either takes far too long or times out completely. The result: IT teams cannot ship the newest Windows security fixes to staff machines through WSUS or through Microsoft's Configuration Manager tool.
Microsoft posted the acknowledgement on its Windows release health dashboard. "Organizations might experience increased synchronization times or sync operation timeouts on WSUS servers," the company wrote. "This issue began in recent days, with heightened impact observed starting July 13, 2026."
The problem hits both desktop and server versions of Windows. On the desktop side, that means Windows 10 version 1607 and everything newer. On the server side, Windows Server 2012 and later.
Is there a fix yet?
Partly. Microsoft rolled out server-side changes on Saturday that stop the problem hitting fresh WSUS installations. If a company builds a new update server today, or wipes and rebuilds an existing one, sync now works normally.
Any WSUS server that was caught by the fault before Saturday is still broken. Microsoft says engineers are working on a way to strip the bad update information (the "metadata") out of those environments safely. There is no timeline for that fix.
"Synchronization times and sync operations on WSUS servers have been restored and are operating normally for new WSUS installations and rebuilds," the company added. "For WSUS servers that were previously affected, Microsoft is working on mitigation steps to help customers safely remove the affected metadata from their environments."
Why does this matter to ordinary users?
Most people never touch WSUS directly. But the machine you use at work almost certainly gets its Windows security patches through one. When WSUS stalls, those patches sit on Microsoft's servers instead of landing on your laptop. That widens the window in which a known flaw can be exploited.
For the IT team upstairs, it also means a scramble. Some will switch affected devices to pull updates directly from Microsoft as a workaround. Others will rebuild their WSUS server from scratch, which the new fix does address.
A recurring pattern
As first reported by BleepingComputer, this is not a one-off. Microsoft fixed a similar WSUS sync problem in May 2025 that hit Windows 11 22H2 and 23H2 systems. Another WSUS sync failure was patched in July 2025. A month after that, in August 2025, Microsoft resolved a separate issue that stopped the August security update reaching machines through WSUS.
Four public breakages of the same update pipeline inside roughly twelve months is a pattern worth noting for anyone still relying on it.
What affected admins should do
If your WSUS server started misbehaving on or after July 13, check Microsoft's Windows release health dashboard for the current mitigation guidance before rebuilding. If you are standing up a new WSUS server now, the fault should not affect you. In the meantime, do not let patch delivery quietly slip: confirm that critical endpoints are receiving July's security updates by some route, even if that means a temporary detour around WSUS.



