Microsoft’s September 2026 Patch Tuesday release has introduced a critical issue for organisations running Windows Server 2025 Remote Desktop Services (RDS).
After installing the September 2026 Windows security update (KB5122871), some organisations are experiencing issues with Remote Desktop Services (RDS)
, causing widespread disruption to terminal server environments across UK SMEs that depend on RDP infrastructure for remote working and application delivery.
For Kent businesses running Windows Server 2025 in production, this issue requires immediate attention. Here’s what you need to know and do now.
What Is Broken in Windows Server 2025 KB5122871
In some environments, RDS might become unstable, resulting in RDP connections failing after several minutes, sign-in issues, or servers hanging at “Please wait for the Remote Desktop Configuration”
. The symptoms are particularly disruptive for SMEs using Remote Desktop Services for:
- Remote worker access to corporate desktops and applications
- Terminal server environments hosting line-of-business applications
- Published RemoteApp programmes delivered to end users
- Multi-session Windows Server deployments for cost-effective desktop delivery
Related tools, including Microsoft Management Console (MMC), RDS Licensing Diagnoser, and File Explorer might also become unresponsive
, compounding the operational impact on IT teams attempting to diagnose and resolve the issue.
September 2026 Patch Tuesday: Record Vulnerabilities Drive Update Urgency
The deployment urgency for this month’s patches cannot be understated.
Microsoft has addressed 972 vulnerabilities in its September 2026 security update release, over double the number of CVEs released in August, and a new Patch Tuesday record
. This unprecedented volume includes two actively exploited zero-day vulnerabilities that pose immediate risk to unpatched systems.
This release ships two zero-days that are already being exploited: CVE-2026-81963 in the Windows Update Stack and CVE-2026-85880 in Windows Advanced Local Procedure Call, both elevation of privilege bugs with a CVSS of 7.8
. As we detailed in our recent analysis of Microsoft September 2026 Patch Tuesday fixes, these vulnerabilities are being actively exploited in the wild and require immediate patching.
The challenge for Kent SMEs is clear: delaying the September 2026 security updates leaves systems vulnerable to active exploitation, but deploying KB5122871 on Windows Server 2025 RDS infrastructure may cause immediate service disruption.
Critical VPN Vulnerability Compounds Risk
Beyond the two actively exploited zero-days,
CVE-2026-73009 is a Critical RCE vulnerability in the Windows Secure Socket Tunneling Protocol (SSTP) service and has a CVSS score of 9.8. An unauthenticated attacker can send a specially crafted packet to the SSTP listener and execute code on the target system
.
Organizations that offer SSTP-based remote-access VPN typically expose the vulnerable service directly to the internet on TCP/443, which means exploitation does not require prior network access or credential theft
. For UK SMEs still operating on-premises VPN infrastructure rather than modern cloud authentication methods, this represents an immediate perimeter breach risk.
What Kent SMEs Running Windows Server 2025 RDS Must Do Now
If your organisation is running Windows Server 2025 with Remote Desktop Services deployed, follow this staged remediation approach:
Immediate Actions (This Week)
- Do not deploy KB5122871 to production RDS infrastructure yet – Monitor Microsoft’s official known issues page for resolution guidance before patching RDS hosts
- Patch non-RDS Windows Server 2025 systems immediately – Deploy KB5122871 to member servers, file servers, and other non-RDS workloads to address the two actively exploited zero-days
- Review VPN infrastructure urgently – If you operate Windows Server SSTP VPN endpoints exposed to the internet, implement network-level controls or alternative access methods whilst planning emergency patching
- Test in isolated environment – Deploy KB5122871 to a non-production RDS server to confirm whether your specific environment experiences the documented failures
Organisations Running Windows Server 2022 or 2019
The RDS failure issue is specific to Windows Server 2025.
The cumulative update for Windows Server 2022 (KB5122882) includes the latest security fixes and improvements
, and Microsoft has not reported similar RDS disruption on Server 2022 or 2019 platforms.
Kent SMEs still running older server platforms approaching end of support should prioritise September security updates on these systems without the same RDS-specific concerns affecting Server 2025 deployments.
Why This Highlights the Risk of Rapid Platform Adoption
Windows Server 2025 represents Microsoft’s newest server platform, and this month’s RDS failure illustrates a recurring pattern: organisations adopting the newest platform releases immediately often encounter stability issues that affect production workloads before broader testing surfaces problems.
For UK SMEs without extensive test infrastructure, a measured approach to platform migration delivers better operational outcomes than early adoption. The long-term support lifecycle of Windows Server 2022 (mainstream support until 14 October 2031) provides stability and security without the risk profile of newest-release deployment.
The Broader Pattern: AI-Driven Vulnerability Discovery Increases Patch Volumes
This month’s record-breaking patch volume reflects an ongoing trend we’ve documented: AI-powered vulnerability discovery is driving unprecedented patch volumes in 2026.
Microsoft has already fixed 2,760 vulnerabilities this year, which is more than double the number from 2025
.
The operational challenge for Kent SMEs is that higher patch volumes increase the statistical likelihood of update-induced failures whilst simultaneously reducing the window available for testing before deployment. Microsoft’s recommendation to deploy Windows updates within 3 days creates genuine tension with the testing cadence required to identify issues like this month’s RDS failures before production impact.
Long-Term Infrastructure Strategy for Kent SMEs
This incident should prompt strategic infrastructure review for organisations heavily dependent on Remote Desktop Services:
- Azure Virtual Desktop eliminates RDS patching risk – Microsoft-managed infrastructure moves RDS update responsibility to the cloud provider whilst retaining the multi-session Windows experience
- Windows 365 Cloud PC delivers individual desktops – For organisations requiring persistent user desktops rather than session-based access, Cloud PC removes on-premises server management entirely
- Hybrid approaches for gradual migration – Organisations with significant RDS investment can migrate user cohorts progressively whilst maintaining on-premises infrastructure for legacy applications
The increasing frequency of update-induced failures in complex on-premises server roles strengthens the case for cloud-native alternatives that separate security updates from your operational responsibility. As we explored in our analysis following the Azure East US outage in September 2026, cloud services carry their own availability risks, but patch-induced service disruption moves from your responsibility to the provider’s SLA commitment.
Get Expert Help with Windows Server 2025 RDS Issues in Kent
If your Kent business is experiencing Remote Desktop Services failures after deploying KB5122871, or you need guidance on patch deployment strategy that balances security urgency against operational stability, Meridian Micro Limited provides specialist Windows Server support across Kent and the South East.
Our team can assess your specific RDS configuration, test updates in isolated environments, and implement either remediation for current failures or migration paths to cloud-native remote access infrastructure that eliminates these operational risks entirely.
Call our Saltwood office on 01303 883111 to speak with a Windows Server specialist about your RDS infrastructure, security update strategy, or cloud migration planning.
