Skip to content

Security1 publisher2 min readPublished

September's Windows Server updates take Remote Desktop down hours after install

Admins on Server 2019, 2022 and 2025 report sessions dropping and new logins hanging within a day of the September cumulative updates. The only remedy anyone has confirmed is removing them, and Microsoft has not commented.

The Watch · Security desk

Illustration accompanying September's Windows Server updates take Remote Desktop down hours after install

What happened

  • Admins say the September 2026 cumulative updates are breaking Remote Desktop Services on Windows Server 2019, 2022 and 2025, blocking user connections and in some cases requiring a hard reset.
  • On a failing server, existing Remote Desktop sessions may not disconnect or log off properly, and new connection attempts hang partway through before failing.
  • The updates named in the reports are KB5122876 on Server 2019, KB5122882 on Server 2022 and KB5122871 on Server 2025.
  • BleepingComputer asked Microsoft whether it is aware of the Remote Desktop Services problems and whether a fix or mitigation exists, and had received no response by the time it published.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • decision A Terminal Server fleet has to choose between keeping September's security content and keeping users signed in, because rollback is the only remedy on the record.
  • constraint The crash follows the first user logouts, so a post-patch smoke test inside a maintenance window can sign off a server that then fails during the working day.
  • exposure Where RDP is also the administration path into the box, the failure closes the route to the fix and recovery needs console or out-of-band access.

The only mechanism on the record comes from one administrator debugging Server 2022, who posted to Reddit that the RDP service goes unresponsive as users begin logging out [8]. "The service hangs at RDPSERVERBASE!WDLIB_Close, there seems to be no timeout set here. This results in a deadlock between RDP and LSM," reads the post [9]. Microsoft has not confirmed that as the cause of the failures [10].

The logout trigger turns up in reader reports as well. "We've had issues with Remote Desktop Services post September update. It works initially, but after the first log out, services crash and no further users can sign in," a Windows admin posted [6]. For that admin a restart did not clear the problem, and rolling back the September update did [7].

Timing varies by environment. "All terminal servers in our environment are failing (sessions dropping, no new connections possible, only solution is a hard reset) within a day," one reader posted to BleepingComputer's Patch Tuesday article [5]. Others on Reddit describe a few hours of normal operation before connections start failing [2]. Across the public reports, time to failure runs from a few hours to a day [14].

Admins who have removed the September updates say Remote Desktop functionality comes back, and the uninstall takes this month's security fixes out with it [12]. The accounts name the update packages. They do not say which vulnerabilities removing them reopens [16].

The exposure here comes from the remedy itself. A fleet that uninstalls sits at August's patch level for as long as the rollback stands [12].

What to watch

  • A Microsoft acknowledgement on the release health dashboard, a Known Issue Rollback, or an out-of-band fix for the three server KBs.
  • Whether Microsoft confirms or refutes the WDLIB_Close deadlock as the actual cause; the current evidence comes only from admin debugging.
  • Whether reports extend to Server 2016 or to RDS deployments behind Remote Desktop Gateway, which the current accounts do not cover.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories