Microsoft's September patches are knocking Remote Desktop offline

Admins across Windows Server and Windows client versions report frozen sessions, hung sign-ins and unresponsive tools after installing this month's updates.

ThreatVectr Newsdesk· Editor: Lee Brown· 4 min read
Full-frame photoreal editorial image of a dimly lit enterprise server room with rows of blue-lit rack units, one cabinet door open showing status LEDs, faint re
Share

Key points

  • Microsoft confirmed on Friday that its September 2026 security updates are breaking Remote Desktop Services on Windows Server 2012 and later, plus Windows 10 and Windows 11.
  • Affected servers show failed sign-ins, hung Remote Desktop connections and unresponsive tools including Microsoft Management Console and File Explorer.
  • Microsoft has published Group Policy files as a temporary workaround for IT-managed devices while a permanent fix is built.
  • Rolling back the updates restores Remote Desktop, but strips out this month's security fixes, leaving machines exposed.
  • A near-identical Remote Desktop bug hit Windows systems in March 2025, introduced by the January 2025 updates.

Microsoft has confirmed that the security updates it shipped this month are breaking one of the most-used tools in corporate IT: Remote Desktop, the feature that lets staff and administrators log into a Windows machine from somewhere else as if they were sitting at it.

The problem hits Windows Server 2012 and every server version since. Windows 10 and Windows 11 are affected on the desktop side. Reported first by BleepingComputer after admins flooded forums with complaints, this month's Patch Tuesday (Microsoft's monthly bundle of security fixes) was leaving servers unusable. We covered the September rollout on 8 September in our report on KB5122878, which noted the update reached machines on Extended Security Updates or Enterprise LTSC editions.

What actually goes wrong?

Remote Desktop sessions drop out or refuse to start. In Microsoft's own words, published Friday: "RDP connections failing after several minutes, sign-in issues, or servers hanging at 'Please wait for the Remote Desktop Configuration'."

Related admin tools can lock up too: Microsoft Management Console (the built-in dashboard admins use to run a server), the Remote Desktop Services Licensing Diagnoser and File Explorer. The Windows Update page itself may sit there spinning indefinitely.

Once a server tips into this state, old sessions may refuse to log off cleanly. Fresh connection attempts hang partway through. Some admins have had to force a hard reset to get the box back.

Who is affected?

Anyone who installed the September 2026 updates on a supported Windows Server or a Windows 10 or 11 client. That's a wide net, because most IT teams apply these automatically within days of release.

The fault sits inside Remote Desktop Services, so machines nobody logs into remotely won't notice. Environments that lean on Remote Desktop for daily work, virtual desktops and jump servers being the obvious cases, are where the pain is landing.

Product Group Policy KB
Windows 11 26H1 KB5124012
Windows 11 24H2 / 25H2, Windows Server 2025 KB5124008
Windows 11 23H2 KB5122880
Windows 10 21H2 / 22H2 KB5122878
Windows Server 2022 KB5122882
Windows Server 2012 / 2012 R2 KB5123065 / KB5123066

What can admins do right now?

Microsoft has published a Known Issue Rollback delivered as a Group Policy, the mechanism IT teams use to push settings across a fleet. It sits under Computer Configuration then Administrative Templates, with a matching policy file per Windows version (see table above).

For virtual machines that have gone unreachable over Remote Desktop: stop the VM, restart it, and connectivity should temporarily return. Uninstalling the September updates also works, but it strips out the security fixes shipped alongside. On anything internet-facing, that's a bad trade.

A permanent fix is still in the works.

Haven't we seen this before?

Yes, and recently. Microsoft fixed a very similar Remote Desktop bug in March 2025, one introduced by the January 2025 updates. Two regressions in the same component inside a year isn't a great look for something this central to remote administration. September has been rough for Windows stability generally: the August updates crashed Teams and Outlook on ARM laptops, and a faulty Defender signature update in August left scans failing on Windows 10 and 11 machines.

On the honest side: multi-factor authentication wouldn't have saved anyone here. This is a reliability bug in the Remote Desktop stack itself, not a break in how users prove who they are. The right lever is patch staging, not identity controls.

My read: if you run a Remote Desktop farm and haven't deployed the Group Policy workaround yet, that's this weekend's job. If your change process still pushes Patch Tuesday straight to production on day one, September is a decent argument for revisiting it.

© 2026 Threat Vectr