Security News

Cybersecurity news aggregator

HIGH Updates Dark Reading

Microsoft Issues Emergency Fixes After Massive Patch Tuesday

Microsoft issued emergency out-of-band updates to address unintended side effects from its September 2026 Patch Tuesday, including instability in Remote Desktop Services (RDS) causing connection failures and server hangs, as well as issues affecting Hyper-V virtual machines and USB audio devices. The article does not specify a particular vulnerability or CVE, nor does it provide CVSS scores, affected version ranges, fixed version numbers, or workarounds for these patch-induced problems.
Read Full Article →

Informa TechTarget | Cybersecurity Dive InformationWeek Channel Dive TechTarget: Cybersecurity Explore our brands Dark Reading Resource Library Black Hat News Omdia Cybersecurity Advertise NEWSLETTER SIGN-UP Cybersecurity Topics World The Edge DR Technology Events Resources APPLICATION SECURITY CYBER RISK VULNERABILITIES & THREATS CYBERSECURITY OPERATIONS NEWS Microsoft Issues Emergency Fixes After Massive Patch Tuesday You can't make an omelet without breaking a few eggs, and you can't patch nearly 1,000 CVEs without a few glitches. Rob Wright,Senior News Director,Dark Reading September 15, 2026 3 Min Read SOURCE: DA-KUK VIA GETTY IMAGES Microsoft on Monday issued out-of-band updates to address several issues caused by this month's massive, record-setting Patch Tuesday. The emergency patches fix problems with Remote Desktop Services (RDS) that came to light last week, as well as unintended side effects for Hyper-V virtual machines and USB audio devices following the historic update last week. September's Patch Tuesday addressed a whopping 974 unique CVEs, smashing the previous record set earlier this year; by comparison, Microsoft patched 909 CVEs in all of 2023. The release clearly illustrates how AI has supercharged vulnerability reporting and led to an alarming number of CVEs. And it may also indicate that faulty patches could become more common with increasingly large updates for software vendors. "I think we should expect this risk to increase as patch volumes continue to grow, but the relationship is not simply that more patches automatically mean more broken systems," Ensar Seker, chief information security officer (CISO) at threat intelligence vendor SOCRadar, tells Dark Reading. Related:Mythos Vulnerability Firehose Hits a Human Bottleneck The bigger issue, Seker says, is the complexity of the modern technology landscape, with increasingly interconnected operating systems, cloud services, virtualization platforms, drivers, identity components, and legacy technologies. "Every additional dependency and supported configuration expands the testing matrix, and it becomes extremely difficult to reproduce every enterprise environment before a patch is released," he says. Fixing September Patch Tuesday Issues LOADING... Microsoft flagged the RDS issues on Friday, noting that some organizations may experience issues after installing the Patch Tuesday update. "In some environments, RDS might become unstable, resulting in RDP connections failing after several minutes, sign-in issues, or servers hanging at 'Please wait for the Remote Desktop Configuration,'" Microsoft said in a health status update. "Related tools, including Microsoft Management Console (MMC), RDS Licensing Diagnoser, and File Explorer might also become unresponsive." Microsoft also said the Windows Update page may stop responding and continuously display a loading indicator. Additionally, September's Patch Tuesday created issues for Hyper-V, as some host folder shares were suddenly unavailable in Hyper-V-based Linux VMs, as well as some USB audio devices in multichannel mode, which either failed to start or produce any sound. Seker notes that with the increasingly rapid exploitation of vulnerabilities, organizations are under enormous pressure to patch faster, which creates "an unavoidable tension between security urgency and regression testing." Related:US Government Accuses Chinese AI Firms of Distilling Frontier Models "What happened with Remote Desktop Services and Hyper-V is a good example of why patch management has effectively become part of operational resilience," he says. "Delaying patches can leave organizations exposed to active exploitation, but deploying a problematic update directly into production can disrupt critical services." The best approach, Seker says, is not to deploy everything immediately and instead apply risk-based patching, using staged deployment rings, representative test environments, rollback capabilities, and enhanced monitoring. "As patch volumes and software complexity increase," he says, "organizations need to become better at safely deploying patches rather than assuming vendors will be able to eliminate every unintended side effect before release." Tyler Reguly, associate director of security R&D at Fortra, agrees and says security teams need to even more diligent about verifying patches before wide-scale deployment, because there are no independent bodies or regulatory agencies that will do that for them. "This lack of external safeguards is why testing patches as they roll out is so critical and why we should never let ourselves get to the point of immediately pushing updates without proper testing," Reguly says. Related:AI's Vulnerability Surge May Be More Manageable Than First Feared About the Author Rob Wright Senior News Director, Dark Reading Rob Wright is a longtime reporter with more than 25 years of experience as a technology journalist. Prior to joining Dark Reading as senior news director, he spent more than a decade at TechTarget's SearchSecurity in various roles, including senior news director, executive editor and editorial director. Before that, he worked for several years at CRN, Tom's Hardware Guide, and VARBusiness Magazine covering a variety of technology beats and trends. Prior to becoming a technology journalist in 2000, he worked as a weekly and daily newspaper reporter in Virginia, where he won three Virginia Press Association awards in 1998 and 1999. At TechTarget and Dark Reading, he has won several Azbee awards, including the 2026 National Silver Award for a series on vibe coding. At Dark Reading, Rob currently covers security operations, cloud security, and Internet infrastructure. He has a keen interest in malvertising activity and the certificate authority industry, and has written extensively on both topics. He graduated from the University of Richmond in 1997 with a degree in journalism and English. A native of Massachusetts, he lives in the Boston area. Want more Dark Reading stories in your Google search results? ADD US NOW More Insights Industry Reports The State of Cloud Security: The Latest Challenges How Organizations Are Managing Incident Response How Enterprises Are Developing Secure Applications Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy Essential News & Insights from Black Hat USA 2025 Access More Research Webinars Cybersecurity Outlook 2027 Threat Exposure Analytics: Measuring and Communicating Security Risk Benchmark Scores Are a False Flag Building an Effective Red Team: Beyond Penetration Testing How to Leverage Threat Intelligence Without Drowning: The Zero Noise Approach More Webinars You May Also Like APPLICATION SECURITY Supply Chain Attack Secretly Installs OpenClaw for Cline Users by Rob Wright FEB 19, 2026 APPLICATION SECURITY Chinese Hackers Hijack Notepad++ Updates for 6 Months by Jai Vijayan FEB 02, 2026 APPLICATION SECURITY Trump Administration Rescinds Biden-Era Software Guidance by Alexander Culafi JAN 29, 2026 APPLICATION SECURITY Microsoft Fixes Exploited Zero Day in Light Patch Tuesday by Jai Vijayan DEC 09, 2025 Featured Check out the Black Hat USA 2026 Conference Guide for coverage and intel from — and about — the show! Editor's Choice CYBER RISK Anthropic CEO: Time to Shift From Improving to Controlling AI byElizabeth Montalbano SEP 14, 2026 6 MIN READ CYBER RISK Why AI Is So Good at Scamming Humans SEP 11, 2026 VULNERABILITIES & THREATS Patch Tuesday Sets Another Record With 974 CVEs byJai Vijayan SEP 8, 2026 5 MIN READ Want more Dark Reading stories in your Google search results? LOADING... HOW ORGANIZATIONS ARE MANAGING INCIDENT RESPONSE Nearly every organization faced a critical security incident last year, but most weren't equipped to contain it. Get the full findings in this free report. DOWNLOAD NOW NOVEMBER 12, 2026 | VIRTUAL What Every Enterprise Should Know About Securing Cloud Assets In the Age of AI SAVE YOUR SPOT Keep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox. SUBSCRIBE Discover More Black Hat Omdia Working With Us About Us Meet the Editors Advertise Reprints Join Us NEWSLETTER SIGN-UP Follow Us Copyright © 2026 TechTarget, Inc. d/b/a Informa TechTarget. This website is owned and operated by Informa TechTarget, part of a global network that informs, influences and connects the world’s technology buyers and sellers. All copyright resides with them. Informa PLC’s registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. TechTarget, Inc.’s registered office is 275 Grove St. Newton, MA 02466. Home| Cookie Policy| Privacy| Terms of Use Your Privacy Choices

Share this article