Microsoft Patches Record 972 Vulnerabilities
Microsoft's September patch release fixes a record 972 vulnerabilities, 112 rated critical, as AI-assisted bug hunting drives unprecedented patch volumes.
Microsoft patched 972 vulnerabilities this September. That's a record. Security researchers are reaching for new adjectives, because the company's monthly security update, released Tuesday, fixed roughly 972 flaws, with 112 of them rated critical, the highest severity tier, and that is the largest single-month haul in Microsoft's history. But it didn't arrive out of nowhere.
Two months ago, the company patched what was then a record 570 vulnerabilities. Last month, it fixed around 620. The trend line is vertical. And Microsoft is not alone in it. Google and other major software vendors, who've been watching this same curve climb month after month across their own products and platforms, have also published record numbers of vulnerabilities in recent months. Something has changed. It's in the economics of finding bugs, and the patch numbers are the most visible symptom.
A Record That Keeps Breaking Itself
Counting flaws in a monthly release isn't precise. It's messy. Some bugs were fixed before, or they're not even yours. They affect products made by other companies. Dustin Childs, a researcher at the Zero Day Initiative, puts Tuesday's total at 972 vulnerabilities, a number that rises to 997 when you add the fixes ported for the Chromium browser inside Edge, which makes the whole tally even harder to pin down. Of the new flaws, 112 carry the critical rating and the rest are classified as important.
The year-to-date picture is starker still. Microsoft has already fixed 2,760 vulnerabilities in 2026. That's more than double last year's total. At the current pace, the company will close the year having patched more bugs than 2023, 2024, and 2025 combined, a tally that keeps climbing even as the industry struggles to explain why the volume won't slow. Childs calls the spikes the "new normal." It's a phrase that captures both the scale and the strange calm settling over the security industry.
"On the one hand, congrats to the security gnomes at Microsoft for being able to patch bugs at this rate," Childs wrote Tuesday. Meanwhile, AI-assisted vulnerability discovery shows no signs of slowing down. However, we have not seen a correlating spike in active exploits,yet."
The Bugs That Matter Most
Among the 972, a handful stand out. Two zero-days, CVE-2026-81963 and CVE-2026-85880, affect the Windows update service and the Windows Advanced Local Procedure respectively. There is no public information about who is exploiting them or how widely. Other notable entries include CVE-2026-55007 in Exchange Server, where a remote, unauthenticated attacker could achieve code execution simply by sending an email with a malicious Visio attachment.

Then there is CVE-2026-80097, a local privilege escalation in Microsoft Authenticator. Childs did not mince words. "This is the worst type of privilege escalation as it uses a bug in the authentication system itself," he said. Rounding out the list: roughly 17 distinct remote code execution flaws in Microsoft Office SharePoint, one of 60 SQL Server privilege escalation bugs this month that triggers when a user submits instructions through SQL Copilot, and a remote code execution flaw in Remote Desktop Services rated 9.8 for severity.
Childs stopped counting wormable vulnerabilities at 20. These flaws need no user interaction to spread from machine to machine, which means a single compromised host can ignite a chain reaction that is difficult to contain.
Why the Numbers Keep Climbing
The engine behind this surge is AI-assisted vulnerability hunting, and it is not without controversy. Critics question the expense and the volume of false positives produced by large language models. They also question the motives of companies trying to recoup the billions they have poured into developing the very AI engines now finding and patching flaws. The results themselves are hard to dismiss.
Mozilla said in May that its researchers, using Mythos, found a record 271 vulnerabilities with almost none of them being false positives. Two weeks ago, OpenAI, Anthropic, Amazon Web Services, Google, Microsoft, and more than 100 other companies and organizations published an open letter warning of a narrowing window for patching vulnerabilities ahead of an expected tsunami of AI-enabled attacks that exploit flaws first. The industry is responding by pumping out unprecedented numbers of patches.
We don't know yet. The long-term effectiveness of AI-assisted bug hunting, whether it actually delivers over the horizon or quietly fades once the novelty wears off, will not be known for a year or more. But this much is clear now. Vulnerability discovery has entered a new and unprecedented phase, and the skeptics who discount that possibility, who insist it's all hype and nothing more, do so at their own peril.
What Comes Next
For anyone running Microsoft software, the immediate task is familiar: apply the September updates. The volume of critical flaws makes delay a genuine risk. Beyond that, the industry is watching for the other shoe to drop. Childs noted that active exploits have not yet spiked in proportion to the patches. "Yet" is the operative word. If AI-assisted discovery keeps accelerating while attackers begin leveraging the same tools, the gap between finding flaws and exploiting them may close faster than defenders can respond.
No one expected this headline. Microsoft Patches Record 972 Vulnerabilities is a sentence that, when you really stop and think about what it means for the thousands of companies and millions of users relying on that software every single day, is not one anyone expected to write this month. And it's also unlikely to be the last time the record falls. We've seen this before. They're patching faster than ever, but the flaws keep coming, and so the number keeps climbing, which means that this record, as staggering as it looks right now, probably won't hold for long.
Frequently Asked Questions
How many vulnerabilities did Microsoft patch in September, and how does that compare to the previous two months?
Microsoft patched a record 972 vulnerabilities in September, with 112 rated critical. Two months ago the company patched what was then a record 570 vulnerabilities, and last month it fixed around 620.
Which specific zero-day flaws were highlighted among the September patches, and what do we know about their exploitation?
Two zero-days, CVE-2026-81963 and CVE-2026-85880, affect the Windows update service and the Windows Advanced Local Procedure respectively. There is no public information about who is exploiting them or how widely.
What is driving the surge in vulnerability discoveries, and what evidence does the article cite to support this?
The engine behind the surge is AI-assisted vulnerability hunting, and Mozilla said in May that its researchers, using Mythos, found a record 271 vulnerabilities with almost none being false positives. Additionally, more than 100 companies and organizations published an open letter warning of a narrowing window for patching ahead of an expected tsunami of AI-enabled attacks.
What immediate action does the article recommend for anyone running Microsoft software?
For anyone running Microsoft software, the immediate task is familiar: apply the September updates. The volume of critical flaws makes delay a genuine risk.
What notable non-zero-day vulnerabilities were mentioned in the September patch release, and why is one described as the worst type of privilege escalation?
Notable entries include CVE-2026-55007 in Exchange Server, where a remote, unauthenticated attacker could achieve code execution via a malicious Visio attachment, and CVE-2026-80097, a local privilege escalation in Microsoft Authenticator. Childs described the latter as the worst type of privilege escalation because it uses a bug in the authentication system itself.
๐ฌ Comments (0)
No comments yet. Be the first!













