Microsoft patch release fixes record 972 bugs
The record-breaking Microsoft patch release addresses 972 vulnerabilities, with 112 rated as high-severity critical bugs.
Microsoft patched a record number of bugs this month. Roughly 972 security vulnerabilities. That's an unprecedented scale, and it shows just how intense the company's patch release efforts have become across every product line they support. Of that massive collection, 112 meet the high critical severity threshold. The rest carry an important designation. And the sheer volume of fixes represents a steep climb in engineering activity, especially when you consider that just two months ago a then record of 570 vulnerabilities were patched, followed by some 620 fixes last month. This rapid escalation points to a broader industry shift where software creators are racing to close security gaps before malicious actors can exploit them, and they can't afford to slow down now.
Security teams across the tech sector are observing similar spikes. Google and other major technology firms have also published record numbers of vulnerabilities in recent months, which signals that the entire digital ecosystem, from small startups to global platforms, is now under intense scrutiny as never before. The sudden rush to patch software comes on the heels of an open letter published two weeks ago by OpenAI, Anthropic, Amazon Web Services, Google, Microsoft, and 100 other companies and organizations. That letter issued a stark warning. It's about a narrowing window to patch security flaws before an expected tsunami of artificial intelligence enabled attacks begins to actively exploit them. But software providers are taking this threat seriously. They're pumping out unprecedented numbers of updates. We've never seen anything quite like it. They don't want to be caught off guard.
A new normal for software security
This massive influx of security fixes is becoming a standard operating procedure. Security professionals are adjusting to a reality where triple digit monthly bug counts are no longer anomalies, and honestly, they're getting used to it. The sudden rise in discoveries is heavily driven by automated systems and artificial intelligence engines designed to scan code for weaknesses at speeds human analysts could never match, which changes everything about how quickly flaws get found and reported. But this automated efficiency has a double edged sword. It's fast. We can't ignore that.
Dustin Childs is a researcher at the Zero Day Initiative. He calls these recurring spikes the new normal. That's the new normal. He warns that the potential damage from future AI assisted attacks remains a major concern, even as defensive patching accelerates, and he says we can't afford to treat any of this as settled. Childs shared his thoughts on the current situation:
On the one hand, congrats to the security gnomes at Microsoft for being able to patch bugs at this rate. Meanwhile, AI-assisted vulnerability discovery shows no signs of slowing down. However, we have not seen a correlating spike in active exploits, yet.
Counting bugs is hard. It's rarely straightforward to measure the exact number of bugs addressed in any monthly update, because some vulnerabilities may have been previously addressed in other updates, while others affect third party technologies that integrate with core software, so the picture gets messy fast. The latest release covers 972 vulnerabilities. That rises to 997 when including ported fixes for the Chromium browser built into the Edge browser. So far this year, the total number of addressed security flaws has reached 2,760, which is more than double the count from last year. At the current pace, the total number of bugs fixed this year will exceed the combined totals of 2023, 2024, and 2025.
Critical zero days under the microscope
Two zero day vulnerabilities are live in the wild. Microsoft's current patch release addresses both of them. They're cataloged as CVE-2026-81963, located in the Windows update service, and CVE-2026-85880, found within the Windows Advanced Local Procedure, yet we don't have any public information detailing who is actively exploiting these zero days or how widely the attacks have spread. That lack of visibility makes immediate deployment urgent.

Wormable threats and remote code execution
Beyond the zero days, several high risk flaws stand out. Why? They can spread without user intervention. Security analysts found so many wormable vulnerabilities in this batch that they stopped counting after reaching 20 distinct bugs, a number that says plenty about what's inside. Wormable flaws are highly dangerous. They let malware hop from machine to machine across a network on its own. And that's the problem, because it's the kind of thing that can cause uncontrollable chain reactions, the sort of cascading failure that security teams can't easily stop once it starts.
Specific vulnerabilities targeted in this update
- CVE-2026-55007 (Exchange Server): Allows a remote, unauthenticated attacker to execute code on an affected server simply by sending an email containing a malicious Visio attachment.
- CVE-2026-80097 (Microsoft Authenticator): A local privilege escalation flaw that exploits a bug within the authentication system itself, representing a highly severe class of privilege escalation.
- CVE-2026-69465 (SharePoint): A collection of roughly 17 distinct vulnerabilities in Microsoft Office SharePoint that allow remote code execution.
- CVE-2026-65669 (SQL Server): One of 60 SQL Server privilege escalation vulnerabilities patched this month, which is triggered when a user submits instructions through SQL Copilot.
- CVE-2026-69525 (Remote Desktop Services): A remote code execution flaw carrying a near maximum severity rating of 9.8.
The debate over AI assisted bug hunting
It's still highly controversial. Using advanced language models to hunt for software flaws remains a hotly debated practice across the technology sector, and critics don't hold back. They point out the high financial costs. They also flag the frequent false positives. And they're raising questions about the underlying business motives, because technology companies are looking for ways to recoup the billions of dollars they've invested in building these artificial intelligence platforms. But the defensive results are hard to ignore.
Proponents of the technology point to actual bug discovery rates as proof of concept. That's the pitch. For example, researchers using an automated tool called Mythos successfully identified a record 271 vulnerabilities in May with almost zero false positives. While the long term impact of AI assisted defense will take a year or more to fully measure, the current volume of discoveries indicates that vulnerability hunting has entered an entirely new phase. But skeptics who dismiss these automated capabilities may find themselves unprepared for the speed of modern security threats. They're not ready.
Frequently Asked Questions
How many security vulnerabilities did the Microsoft patch release address this month, and how does that compare to recent months?
The Microsoft patch release fixed roughly 972 security vulnerabilities, with 112 meeting the high critical severity threshold and the rest carrying an important designation. This is a steep climb from just two months ago, when a then record of 570 vulnerabilities were patched, followed by some 620 fixes last month.
What prompted the sudden rush among software providers to release so many security updates?
The rush comes on the heels of an open letter published two weeks ago by OpenAI, Anthropic, Amazon Web Services, Google, Microsoft, and 100 other companies and organizations. That letter warned about a narrowing window to patch security flaws before an expected tsunami of artificial intelligence enabled attacks begins to actively exploit them.
Which specific zero day vulnerabilities does the current Microsoft patch release address, and what makes them urgent?
The release addresses two zero day vulnerabilities live in the wild: CVE-2026-81963 in the Windows update service and CVE-2026-85880 in the Windows Advanced Local Procedure. Because there is no public information detailing who is actively exploiting them or how widely the attacks have spread, immediate deployment is urgent for IT administrators.
Why are wormable flaws considered especially dangerous in this batch of fixes?
Wormable flaws are highly dangerous because they let malware hop from machine to machine across a network on its own without user intervention. Security analysts found so many wormable vulnerabilities in this batch that they stopped counting after reaching 20 distinct bugs, and such flaws can cause uncontrollable chain reactions that security teams cannot easily stop once started.
Who is Dustin Childs and what does he say about the recurring spikes in vulnerability discoveries?
Dustin Childs is a researcher at the Zero Day Initiative who calls these recurring spikes the new normal. He warns that the potential damage from future AI assisted attacks remains a major concern even as defensive patching accelerates, and he notes that a correlating spike in active exploits has not been seen yet.
๐ฌ Comments (0)
No comments yet. Be the first!













