
A plain-English guide for UK business owners, managers and staff
Updated 16 September 2026
If your team has recently struggled to connect to its remote desktop, September’s Windows updates could be responsible. Microsoft has confirmed that its security updates released on 8 September can make Remote Desktop Services unstable in some environments. It released corrective updates on 14 September 2026. Microsoft’s issue notice
What has gone wrong?
Remote Desktop Services, often called RDS or Terminal Server, lets staff use desktops and applications running on a shared server in the office or a data centre. Many people simply know it as “logging into the server”. Because everyone shares the same system, a fault can cut off several people at once.
Microsoft describes connection and sign-in failures, servers hanging at “Please wait for the Remote Desktop Configuration”, and related management tools freezing. Citrix also reports new connections stuck at “Connecting…” and users unable to log off, often several hours after a restart. Citrix’s advisory The fault can affect Windows Server 2012 (with ESU) through 2025 and some Windows desktop versions, but not every system running these versions will experience it.
Has Microsoft fixed it?
Yes. Microsoft issued out-of-band updates on 14 September, outside its normal monthly schedule. They resolve the RDS issue and keep the protections from earlier security updates. Some of these updates, including the Server 2025 fix, are published through the Microsoft Update Catalog. Businesses therefore shouldn’t assume their usual automatic updates have already installed them. IT teams that applied Microsoft’s temporary Group Policy mitigation don’t need to remove it first.
Uninstalling the September update is not a sensible routine fix. It restores remote desktop access, but it also removes security fixes, including fixes for critical Remote Desktop vulnerabilities.
What should businesses do?
Staff should report the exact message they see and when it happened. They should save work regularly and follow IT’s instructions about reconnecting. They should also resist moving files to personal email or cloud storage to work around the problem.
Managers should ask their IT team three things: whether the symptoms match this issue, which servers are affected, and whether the corrective update has been installed. A frozen login alone doesn’t prove the cause, so the answer should be based on the update history and logs, not assumption.
Technical reference
| Windows Server | Update associated with the issue | Corrective update |
|---|---|---|
| 2016 | KB5123099 | KB5129239 |
| 2019 | KB5122876 | KB5129238 |
| 2022 | KB5122882 | KB5129237 |
| 2025 | KB5122871 | KB5129235 |
Useful diagnostic clues include TerminalServices-RemoteConnectionManager Event 20498, Winlogon Event 6005 referring to SessionEnv, and TermService stuck in StopPending.
Our view
At Trichromic, we install Microsoft’s updates within two weeks of release, and usually sooner. Installation takes place on a Saturday evening, with servers restarting in the early hours of Sunday to keep disruption to a minimum. Some of our clients’ servers therefore received September’s updates before Microsoft had acknowledged the fault, and several have since been hanging intermittently. We’re now downloading and installing the corrective updates, starting with the servers most affected, and will work through the rest as quickly as we can. Skipping or removing security updates would have left those systems exposed to serious vulnerabilities, so we still believe prompt patching is the right approach, even when Microsoft occasionally gets it wrong.