A major issue affecting Windows Server Update Services (WSUS) servers has prompted Microsoft to share manual mitigations for IT administrators. A known problem with WSUS synchronization is causing Windows Update scans to fail or time out, leaving organizations unable to deploy the latest security patches and updates.
The affected platforms include both client-side (Windows 10, version 1607 and later) and server-side (Windows Server 2012 and later) systems. On impacted WSUS servers, administrators are struggling to deploy Windows updates via WSUS or Configuration Manager due to increased synchronization times or sync operation timeouts caused by a buildup of publishing metadata.
Microsoft has already rolled out a service-side mitigation on July 16th for newly installed or rebuilt WSUS servers, which resolved the issue for these systems. However, some organizations with existing WSUS server installations are still experiencing sync operation issues and timeouts. To address this, Microsoft has shared manual steps to help administrators clean up unneeded metadata.
The process involves backing up each SUSDB database, running a cleanup query from SQL Management Studio against all SUSDB databases (including WSUS replicas), and updating the MaxXMLPerRequest value to its default setting. After completing these steps, the first Windows Update scan may take longer than usual, but subsequent scans should return to normal timing.
Microsoft also recommends reindexing the SUSDB database, running the WSUS Server Cleanup Wizard, and then restarting IIS or recycling the WsusPool application pool to clear cached catalog state. This manual fix is essential for organizations that need to get their WSUS servers back online quickly.
It’s worth noting that Microsoft has encountered similar issues with WSUS in the past, including in May 2025, July 2025, and August 2025. These problems highlight the importance of having robust WSUS infrastructure in place to ensure timely deployment of security patches and updates.
So what can you do to prevent or mitigate such issues in the future? First, make sure to regularly review and update your WSUS configuration to ensure it is aligned with Microsoft’s recommended best practices. Additionally, consider implementing a robust monitoring and alerting system to detect any potential synchronization issues before they become critical. By taking proactive steps, you can minimize downtime and keep your organization’s systems secure.
Finally, don’t forget to test every layer of your security infrastructure regularly using breach and attack simulation tools to identify vulnerabilities and strengthen your defenses. This will help you stay ahead of attackers who are constantly evolving their tactics to evade detection.
Source: Bleeping Computer — 2026-07-21