The Update Was Supposed to Close the Door
Microsoft's September 2026 Patch Tuesday shipped a fix for CVE-2026-69525, a Remote Desktop Services flaw rated 9.8 out of 10 on the CVSS scale, the kind of score reserved for bugs a stranger on the internet can exploit without a password. A specially crafted packet sent to port 3389 could trigger a use-after-free error and run code with service-level privileges, no login required.
Administrators who applied the update on schedule, the responsible move by any normal standard, did exactly what security teams tell them to do every month.
Then Remote Desktop Started Dying on Its Own
Within hours of installing KB5122876 on Server 2019, KB5122882 on Server 2022 or KB5122871 on Server 2025, Remote Desktop Services began to fail. Connections that worked at boot stopped working a few hours later. Existing sessions could not log off cleanly. New connection attempts hung and eventually timed out, and in the worst cases the only fix was a hard reset of the server.
One administrator described the pattern plainly: it works initially, but after the first log-off, the service crashes and no further user can sign in. A researcher tracing the fault pointed to a deadlock between the Remote Desktop process and the Local Session Manager, a diagnosis Microsoft has not confirmed.
What Broke, Where
| Windows Server version | Update | Symptom |
|---|---|---|
| Server 2019 | KB5122876 | RDS fails hours after boot |
| Server 2022 | KB5122882 | Sessions hang on log-off |
| Server 2025 | KB5122871 | New connections time out |
Microsoft has confirmed only that it is aware of the reports and investigating. It has not confirmed the root cause, and it has not said when a fix is coming.
Why It Matters
Why it matters: This is not an abstract patch-management debate, it is a live choice facing any team running Windows Server with Remote Desktop exposed, which in European and UK operations covering remote staff, contractors or branch offices is most of them. Roll the update back, and a 9.8-severity flaw exploitable with no credentials is open again on the same servers. Leave it installed, and remote access itself, the thing those servers exist to provide, can stop working without warning.
Yes, But
Yes, but: Neither option is actually the only choice. Admins who cannot risk either full rollback or broken remote access are restricting RDP exposure at the network level instead, limiting port 3389 to a VPN or a jump host rather than the open internet, which keeps the patch installed, closes off the easiest path to the vulnerability it fixed, and buys time for an official fix without gambling on either failure mode.
The Bottom Line
The bottom line: "Patch everything immediately" and "wait a week to be safe" are both the wrong instinct here, because the actual decision is not about speed, it is about exposure. Test a cumulative update in a small canary group before it reaches every server, and restrict network access to anything the update might touch, so a bad patch degrades a handful of machines instead of every Remote Desktop session in the company at once.
Read next: Apple's 2011 CEO Shock Cost 12 Times More Than 2026's | Xbox's U-Turn Was on Marketing, Not the Games



