Microsoft has confirmed that Windows Server Update Services synchronisation has been broken for over a week, leaving UK admins unable to push the latest Windows updates via WSUS or Configuration Manager. A partial fix landed on 18 July, but previously affected servers still need manual remediation.
View the data behind this chart
| Phase | Starts (week) | Duration (weeks) |
|---|---|---|
| Sync degradation begins | 0 | 1 |
| Heightened impact from 13… | 1 | 1 |
| Mitigation for new/rebuilt… | 2 | 1 |
What's actually broken in WSUS right now
Microsoft has confirmed a known issue affecting Windows Server Update Services synchronisation, with impact intensifying sharply from 13 July 2026 onwards. On affected servers, sync operations either take far longer than usual or time out completely, which means the latest Windows update metadata never reaches the local WSUS server — and therefore never reaches the endpoints downstream of it.
The scope is broad by design flaw rather than by targeted attack: both client platforms from Windows 10 version 1607 onward and server platforms from Windows Server 2012 onward are affected. For any UK organisation still running WSUS as its central patch distribution point, that covers almost the entire fleet.
Root cause: a metadata burden Microsoft didn't anticipate
The underlying trigger is a problematic update revision sitting in the WSUS storage layer, which chokes synchronisation with Microsoft Update. Rather than a network outage or credentials problem, this is a data-integrity issue baked into the metadata WSUS servers pull down daily. That distinction matters for UK admins troubleshooting the symptom in isolation — restarting services or re-checking proxy settings will not resolve it, because the fault sits upstream in what WSUS is being asked to store and process.
What this means for patch deployment cycles
For any business running scheduled patch windows, this is a direct hit on remediation timelines. If your WSUS server can't sync, it can't stage the latest cumulative updates, security fixes or driver packages for approval and deployment — meaning your Patch Tuesday cadence, or whatever internal cycle you run, effectively stalls until the metadata problem clears. Organisations relying on Configuration Manager integration with WSUS are equally exposed, since ConfigMgr pulls its update catalogue from the same broken sync pipeline.
Teams working to strict compliance or audit deadlines should treat this as a genuine risk to their remediation SLAs, not a minor inconvenience. If your patch management programme assumes a same-week deployment window for critical fixes, that assumption no longer holds for affected WSUS environments. This is exactly the kind of gap where understanding effective patch management practices — including fallback distribution methods — earns its keep.

Microsoft's fix status: what's resolved and what isn't
Microsoft rolled out mitigation on Saturday, 18 July 2026, but the fix only covers newly installed or rebuilt WSUS servers, where synchronisation is now described as restored and operating normally. Previously affected servers are a separate problem: Microsoft says it is still working on steps to help customers safely remove the affected metadata from those environments, and at the time of writing no workaround exists for them.
Microsoft's own words on the dashboard update were direct:
"Organizations might experience increased synchronization times or sync operation timeouts on WSUS servers."
That statement, alongside the confirmation that heightened impact began on 13 July, gives admins a concrete window to check logs against when auditing which servers were hit.
WSUS has form — this isn't a one-off
This is not the first time WSUS synchronisation has broken down. A similar issue disrupted Windows 11 22H2/23H2 updates roughly a year earlier, in May, and Microsoft resolved another sync-blocking bug in July 2025, followed by a separate fix a month later for August 2025 security updates that WSUS couldn't deliver. Earlier in 2026, Microsoft also had to ship emergency out-of-band patches, including KB5070884 for Server 2022, to close a critical WSUS remote code execution flaw with public proof-of-concept code circulating.
Microsoft also reversed a planned deprecation of WSUS driver sync after customer pushback, underlining that despite being nearly two decades old, WSUS remains load-bearing infrastructure that Microsoft can't simply retire on schedule. For UK buyers, the pattern is now well established: recurring sync failures, occasional critical vulnerabilities, and infrastructure decisions reversed under pressure from enterprise dependency.
What UK Windows Server admins should do now
Check the affected status of each WSUS server against the 13 July heightened-impact date and monitor Microsoft's health dashboard for the metadata-removal guidance still in progress. Where WSUS availability is uncertain, consider whether critical security updates can be pushed via alternative channels in the interim, and build slack into remediation deadlines that assume WSUS will behave normally.
This episode is also a useful prompt to review broader server resilience. Organisations already planning for Windows Server end-of-life or weighing strategies for migrating EOL servers should factor patch-infrastructure fragility into the timeline, since legacy estates on ageing hardware compound the risk when central update mechanisms falter. Firms without in-house capacity to chase Microsoft's fix schedule may find value in exploring third-party maintenance options or comprehensive IT services support to keep patch cycles moving regardless of upstream disruption.
- 01BleepingComputer — Microsoft working to fix WSUS server sync delays and timeouts · 20 July 2026
- 02BleepingComputer — Microsoft confirms Windows Server Update Services (WSUS) sync is broken · 20 July 2026
- 03BleepingComputer — Microsoft releases Windows Server emergency updates for critical WSUS RCE flaw · 1 January 2026
- 04The Register — Windows Server Update Services live to patch another day · 8 April 2025
