Windows administrators worldwide are facing a disruptive Remote Desktop Services (RDS) bug that surfaced shortly after Microsoft released its September 2026 Patch Tuesday cumulative updates This article explores rds bug surfaced. . Session hosts running Windows Server 2019, 2022, and 2025 have begun freezing hours after boot, leaving RDP connections stuck at "Connecting…" and preventing logged-in users from disconnecting or logging off cleanly.
Reports first appeared on Reddit’s r/sysadmin community, where multiple administrators independently described the same failure pattern across unrelated environments, indicating a systemic issue rather than a single configuration problem.
Winlogon logs Event 6005, warning that “SessionEnv is taking a long time to handle the notification event (Disconnect).” Administrators report that independent kernel-level debugging reveals a deadlock inside the RDP server base library, specifically in a routine called RDPSERVERBASE!WDLIB_Close, which is invoked during session teardown. The September Patch Tuesday addressed nearly 973 vulnerabilities across Microsoft’s ecosystem, including two zero-days currently being exploited, CVE-2026-81963 in the Windows Update stack and CVE-2026-85880 in Windows Advanced Local Procedure Call, both now listed in CISA’s Known Exploited Vulnerabilities catalog.
Given the scale of reports across Server 2019, 2022, and 2025, security teams managing RDS collections should pilot the September updates on non-critical hosts, monitor for Event 20498 and Winlogon 6005 after logoff cycles, and maintain a rollback plan until Microsoft officially acknowledges the issue or releases an out-of-band fix.












