Windows Server update time delays in 2026 turned a routine patch cycle into a seven-hour ordeal for one dormant Windows 11 laptop. Separately, September's Patch Tuesday broke Remote Desktop Services on servers running 2019 through 2025 — a reminder that patching friction is compounding across the estate. For UK operators, the real question is what a stalled patching window costs once you calculate your infrastructure downtime costs.
View the data behind this chart
| Lower estimate | Upper estimate | |
|---|---|---|
| Direct revenue loss | £m650 | £m1000 |
A seven-hour wake-up call for dormant machines
The Register's own hands-on test told a simple but uncomfortable story: an ordinary x64 Windows 11 laptop, which had been up to date less than a year ago, took roughly seven hours to come back into compliance after a few months switched off. The process involved a series of component updates, firmware and driver revisions, what the reviewer described as an insistence on moving to a newer OS version, and repeated restarts.
Anyone who has watched a Windows update progress bar knows the frustration described by the writer: "Yeah, so I'm going to stick at 65 percent for about an hour and then jump to 98 percent in 30 seconds before hanging there for another hour." It's a throwaway line, but it captures a real operational risk — the progress indicator gives no honest signal of how long recovery will actually take.
For a single laptop, that's an afternoon lost. For a UK data centre bringing a cold-standby host, a rarely booted test server, or an idle branch appliance back online, the same pattern scales into a genuine capacity and scheduling problem.
September's Patch Tuesday made a bad problem worse
According to BleepingComputer's reporting, September 2026's Patch Tuesday was unusually large, addressing 966 flaws across Microsoft's own products and 999 vulnerabilities in total once non-Microsoft CVEs are included — with 105 Critical bugs, 81 of them remote code execution flaws, and two zero-days already being exploited in the wild.
Microsoft's own support documentation confirmed the September cumulative updates could break Remote Desktop Services on Windows Server 2012 and later, with affected releases including Server 2019, 2022 and 2025. Admins reported servers hanging at the "Please wait for the Remote Desktop Configuration" screen, failed RDP connections, sign-in failures, and in some cases needing hard resets to recover service.
Microsoft's own guidance — stop and restart the affected virtual machine, or roll back the update — puts operators in an unenviable spot, since rolling back also strips out that month's security fixes. According to Microsoft's advisory, emergency out-of-band patches followed on 14 September 2026: KB5129238 for Server 2019, KB5129237 for Server 2022, and KB5129235 for Server 2025, targeting problems introduced by KB5122871 (Server 2025) and KB5122882 (Server 2022), all distributed via the Microsoft Update Catalog. A separate WSUS sync issue, causing update scans to fail or time out, added yet another layer of friction for admins that same month.
Why dormancy is expensive for UK operators
None of this is abstract for UK buyers. Separate analysis from the UK Cyber Monitoring Centre estimates that a 24-hour outage hitting a major AWS or Microsoft Azure region serving the UK, Ireland, Europe or the eastern US could cause direct revenue losses of between £650 million and £1 billion — and that figure excludes downstream supply-chain effects, which could push the real cost considerably higher.
The Register's own coverage of Britain's cloud concentration risk cited similarly stark figures, underlining that when infrastructure goes dark — whether through an outage or an extended patch-and-recovery window — the meter is running at a national economic scale, not just a departmental one.
A seven-hour recovery window on a single machine is a nuisance. The same dynamic multiplied across a fleet of servers that have sat idle over a quiet trading period, a decommissioned project, or a disaster-recovery site that's rarely exercised, is a resourcing headache that can eat into a maintenance window meant for something else entirely. Operators carrying older or lightly-maintained estate may find it worth reviewing whether they should explore third-party maintenance options rather than absorbing that recovery time internally.

Rebuilding the patching window for 2026 realities
The scale of September's release — nearly a thousand flaws, plus two exploited zero-days — makes it hard to justify indefinite deferral. Critical RCE bugs need attention quickly. But the RDS breakage on Server 2019, 2022 and 2025 is a reminder that deploying at speed without validation carries its own operational cost, particularly for teams reliant on Remote Desktop Services for day-to-day administration.
This is exactly the tension that a structured approach to patch cadence is meant to resolve: staged rings, representative test hosts, and realistic time budgets that account for firmware and driver backlogs, not just the OS-level cumulative update. Buyers reassessing their approach may find it useful to understand patch management strategies that build in recovery-time assumptions for infrequently booted hosts, not just always-on production servers.
Zombie workloads and the cost of avoiding reboots
There's a broader efficiency story sitting behind this. Industry analysis points to "zombie workloads" — idle or lightly used capacity kept running rather than properly decommissioned — as a meaningful contributor to wasted power and delayed capacity planning.
That backdrop helps explain why operators are reluctant to reboot or refresh systems more than strictly necessary. But it also means that when those dormant systems finally do get touched — for a security patch, a migration, or a hardware refresh — the accumulated update backlog is worse, not better, than it would have been with a steadier cadence.
View the data behind this chart
| Layer | Detail |
|---|---|
| 999 total vulnerabilities | Microsoft plus non-Microsoft CVEs disclosed that month |
| 966 Microsoft flaws | Vulnerabilities across Microsoft's own product range |
| 105 Critical bugs | Highest-severity issues in the release |
| 81 RCE flaws | Critical bugs allowing remote code execution |
| 2 active zero-days | Already being exploited before patches shipped |
What UK buyers should do now
September's combination of a record-sized Patch Tuesday and a Server-breaking RDS bug is a useful prompt to audit assumptions about patching windows before the next quiet period ends. Ageing estate approaching end of support adds another layer of exposure, since vendors stop shipping the out-of-band fixes that resolved this month's RDS problem — buyers in that position may want to estimate Windows Server EOL costs against the price of a planned refresh, and to find new server hardware where replacement makes more sense than another year of patch triage.
- •Test the September out-of-band KBs (KB5129238, KB5129237, KB5129235) on representative hosts before wide deployment
- •Audit dormant, cold-standby and rarely booted servers and rebuild realistic patch-recovery time budgets
- •Model outage and delayed-recovery exposure against UK Cyber Monitoring Centre cost estimates
- •Weigh third-party maintenance or hardware refresh for estate that can't sustain lengthy update cycles
- 01The Register — How Windows turned months of inactivity into a 7-hour update hostage situation · 20 September 2026
- 02BleepingComputer — September Windows Server updates break Remote Desktop Services · 11 September 2026
- 03BleepingComputer — Microsoft releases emergency Windows updates to fix RDS failures · 14 September 2026
- 04BleepingComputer — Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days · 8 September 2026
- 05The Register — Britain's cloud habit has become a billion pound risk · 9 July 2026
- 06Computer Weekly — UK's largest businesses dangerously exposed to cloud outages · 9 July 2026
- 07bleepingcomputer.com
- 08thehackernews.com
