Welcome to Microsoft Q&A!
Thank you for providing the detailed information.
Based on the information provided, your update mapping is correct:
- Windows Server 2025: KB5122871 → KB5129235
- Windows Server 2022: KB5122882 → KB5129237
- Windows Server 2019: KB5122876 → KB5129238
- Windows Server 2016: KB5123099 → KB5129239
The original September 8, 2026 security updates were associated with a known Remote Desktop Services (RDS) issue. In affected environments, administrators could experience:
- RDP connection or sign-in failures
- RDS becoming unstable or unresponsive
- Servers hanging at "Please wait for the Remote Desktop Configuration"
- Microsoft Management Console (MMC), RDS Licensing Diagnoser, File Explorer, or the Windows Update page becoming unresponsive
The corresponding Out-of-Band (OOB) updates listed above and documented that these updates resolve the RDS-related issue.
Are there any serious known issues with the OOB updates?
Based on the information currently published by Microsoft, the KB512923x updates are the corrective releases for the September 2026 RDS regression. These OOB updates are cumulative, meaning they include both the original security fixes and the RDS correction. As a result, the original September updates do not need to be uninstalled before installing the matching OOB update.
At this time, Microsoft has not documented any additional Windows Server-wide issue of similar severity that would require removal of the KB512923x updates. However, there are a few considerations to keep in mind:
1. WSUS synchronization reporting
For Windows Server 2022 and Windows Server 2025, WSUS may not display synchronization error details correctly after installing the applicable updates. While this does not impact update installation itself, it may limit troubleshooting visibility within WSUS.
2. Windows Server 2016 servicing prerequisites
Before installing KB5129239, ensure the latest Servicing Stack Update (SSU) is installed. Please notes that the OOB update may not be offered if the required SSU is missing.
3. OOB update availability
In some environments, the OOB updates may not appear through normal WSUS synchronization. If required, administrators may need to import the updates from the Microsoft Update Catalog.
4. Environment-specific issues
If RDP, RD Licensing, RD Gateway, Connection Broker, authentication, profile, printing, or other application-specific issues persist after the OOB update is installed and the server is restarted, those issues should be investigated separately rather than assumed to be related to the resolved RDS issue.
I would like to recommend actions for servers that are already updated.
Please verify that each server has the correct OOB update installed for its operating system version:
- KB5129235 for Windows Server 2025
- KB5129237 for Windows Server 2022
- KB5129238 for Windows Server 2019
- KB5129239 for Windows Server 2016
If the appropriate OOB update is already installed:
- There is generally no need to uninstall it, even if the original September update also appears in the update history.
- Restart the server if a reboot is pending.
- Validate normal RDS functionality, including sign-in, session creation, reconnection, RD Licensing, RD Gateway, Connection Broker, and related management tools.
- Continue monitoring event logs and application behavior during normal production operations.
- If a temporary Known Issue Rollback (KIR) policy was previously implemented, review whether it is still required after the permanent fix has been applied.
- Continue installing future cumulative updates, as subsequent updates also contain the RDS correction.
If only the original September security update is installed, it is a recommendation installing the corresponding OOB update or a later cumulative update that includes the fix. Removing the original security update is generally not recommended because doing so would also remove the associated security protections.
Should deployment continue?
Yes. Based on the currently available information, deployment can continue. However, systems should receive the matching OOB update or a later cumulative update containing the fix, rather than deploying only the original September 2026 security update. As a best practice, consider a controlled rollout:
- Verify the Windows Server version and corresponding KB.
- Test the update on representative RDS hosts and supporting infrastructure.
- Ensure an alternative management method is available should RDP become unavailable.
- Reboot and validate RDS functionality.
- Continue deployment after successful validation and monitoring.
I hope this helps clarify the current status of these updates.
References: Windows Server 2025 known issues and notifications | Microsoft Learn
Windows Server 2022 known issues and notifications | Microsoft Learn
Windows 10, version 1809 and Windows Server 2019 known issues and notifications | Microsoft Learn
Windows 10, version 1607 and Windows Server 2016 known issues and notifications | Microsoft Learn
Windows Server release information | Microsoft Learn
September 14, 2026—KB5129237 (OS Build 20348.5631) Out-of-band | Microsoft Support
September 14, 2026—KB5129235 (OS Build 26100.33451) Out-of-band | Microsoft Support
September 14, 2026, 2026—KB5129239 (OS Build 14393.9514) Out-of-band | Microsoft Support
September 14, 2026—KB5129242 (OS Build 22631.7584) Out-of-band | Microsoft Support
If you find it useful, please click Accept Answer.
Thank you for choosing Microsoft Q&A.