LIVE · cybersecurity feed
Live wire
Acronis warns of actively exploited flaw in its cPanel backup pluginOracle September 2026 Critical Security Patch Update addresses 672 CVEsCVE-2026-76461 · U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalogHackers target WordPress sites via third-party WooCommerce pluginCVE-2026-51990 · Hackers exploit Tencent app flaw to deploy GrayRabbit malwareCVE-2026-42016 · CISA Adds 5 Exploited Flaws in Artifactory, ScreenConnect, RouterOS to KEVCVE-2026-85102 · Dutch NCSC: Critical Check Point VPN flaws exploitation is imminentAI Enables Mass Generation of Personalized Fraud EmailsCVE-2026-85706 · Critical GitLab Vulnerability Exploited in Internet-Wide ProbesCVE-2025-66516 · Metasploit Wrap Up: This One Goes to Sixteen!
patch

September Windows Server updates break Remote Desktop Services

Windows admins report that the September 2026 security updates are causing Remote Desktop Services (RDS) failures on Windows Server 2019, 2022, and 2025 servers, preventing users from connecting and, in some cases, requiring a hard reset to restore functionality. [...]

zeroday.news ·

Microsoft's September 2026 cumulative updates are reportedly causing widespread failures in Remote Desktop Services (RDS) across various Windows Server versions, preventing users from connecting to servers and, in some cases, necessitating hard reboots to restore functionality. The issues have been observed on Windows Server 2019, 2022, and 2025 systems following the installation of the monthly Patch Tuesday updates.

Administrators have reported that RDS servers initially function normally for a few hours after the updates are applied. However, connections subsequently begin to fail, with existing Remote Desktop sessions unable to disconnect or log off properly. New connection attempts often hang during the process before ultimately failing.

The problem appears to affect all current Windows Server releases. Specifically, administrators have linked the issues to update KB5122876 for Server 2019, KB5122882 for Server 2022, and KB5122871 for Server 2025.

Several reports indicate that once a server begins to experience these failures, a simple restart may not resolve the problem. Some administrators have found that the only effective solution is to perform a hard reset. Others have noted that rolling back the September updates completely restores Remote Desktop functionality.

One administrator investigating a Server 2022 system reported that the RDP service becomes unresponsive when users log out. Debugging suggested a potential deadlock between Remote Desktop and the Local Session Manager, with the service hanging at `RDPSERVERBASE!WDLIB_Close` due to what appeared to be an unset timeout. However, Microsoft has not confirmed this as the underlying cause.

While rolling back the updates resolves the RDS issues, it also removes the security fixes included in the September Patch Tuesday release, leaving systems potentially vulnerable. Microsoft has not yet issued a statement or provided a fix or mitigation for the reported problems.

patch
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

The vulnpocalypse rains iBugs down on Apple with record-setting number of patches

September Patch Tuesday part 2?

vulnerabilitycritical

Oracle September 2026 Critical Security Patch Update addresses 672 CVEs

Oracle addresses 672 CVEs in its September 2026 Critical Security Patch Update with 673 patches, including 104 critical updates. Key Takeaways The September 2026 Critical Security Patch Update (CSPU) contains fixes for 672 unique CVEs in 673 security updates 104 issues (15.5% of all patches) were assigned a critical severity rating Oracle E-Business Suite received the highest number of patches at

patch

Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites

Malicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to more than 200 customers after a threat actor compromised the maintainer's website and pushed updates that created a hidden user account. [...]

vulnerabilityhigh

Acronis warns of actively exploited flaw in its cPanel backup plugin

Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. [...]

CVE-2026-76461critical

U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Cisco Secure Email Gateway flaw, tracked as CVE-2026-76461 (CVSS score of 9,8), to its Known Exploited Vulnerabilities (KEV) catalog. Cisco disclosed a critical zero-day CVE-2026-76

ai

Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow?

Microsoft agreed to adopt guardrails and privacy standards for its AI in schools, as negotiated with the American Federation of Teachers. The post Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow? appeared first on SecurityWeek.