Microsoft Fixes Record 972 Vulnerabilities in Mass Patch Update

Microsoft patched nearly 1,000 security vulnerabilities in a single month as AI tools reshape cybersecurity.

Sep 8, 2026

7 cards · 1 min · tap to begin

From · · 1 min

Microsoft Fixes Record 972 Vulnerabilities in Mass Patch Update

Microsoft patched nearly 1,000 security vulnerabilities in a single month as AI tools reshape cybersecurity.

In brief

Microsoft patched nearly 1,000 security vulnerabilities in a single month as AI tools reshape cybersecurity. Accelerating AI vulnerability discovery means organizations must prioritize rapid, automated patch management to stay ahead of automated exploits. Originally reported by Ars Technica.

Microsoft issues record patch release

Microsoft issues record patch release

September brought a massive security update fixing roughly 972 vulnerabilities, including 112 critical flaws. This shattered previous company records for a single monthly release.

Microsoft’s patch for September is a doozy, with a record number of roughly 972 vulnerabilities fixed and 112 of them meeting the high critical-severity threshold.

AI triggers race against exploits

Tech leaders recently warned of an impending tsunami of AI-driven cyberattacks. Software creators are rushing to patch code before automated tools expose and exploit flaws first.

warning of a narrowing window for patching vulnerabilities ahead of an expected tsunami of AI-enabled attacks that actively exploit them first.

Bug fixes reach unprecedented volume

Bug fixes reach unprecedented volume

Microsoft has patched 2,760 bugs so far this year, doubling its previous annual total. The company is on track to patch more vulnerabilities in 2026 than in the last three years combined.

At this rate, Microsoft will complete the year having fixed more bugs than all of 2023, 2024, and 2025 combined.

Severe flaws threaten key services

The patch addresses two active zero-days alongside critical flaws in Exchange Server, SharePoint, and Microsoft Authenticator that allow remote code execution or privilege escalation.

This is the worst type of privilege escalation as it uses a bug in the authentication system itself

Dozens of wormable bugs identified

Researchers counted at least 20 wormable vulnerabilities in this release alone. These flaws require zero user interaction and can spread autonomously across interconnected machines.

These vulnerabilities don’t require any user interaction to be exploited and hence can spread from machine to machine on their own

AI vulnerability hunting sparks debate

Photo of Dan Goodin

Skeptics argue AI bug hunting generates costly false positives, but supporters note that tools like Mozilla's Mythos are uncovering record numbers of genuine flaws.

The counterargument is that the results—AI-assisted hunting finding record numbers of severe bugs across the industry—speak for themselves.

Cybersecurity enters a new era

Rapid, AI-powered vulnerability discovery is officially the new normal. Organizations that dismiss AI's impact on software security risk falling behind aggressive automated threats.

In short

Accelerating AI vulnerability discovery means organizations must prioritize rapid, automated patch management to stay ahead of automated exploits.

Read the original on Ars Technica

React

Sign in to react and comment.

Comments (0)

Life is short. Keep it sweet. Respect others' opinions and be kind!

    Recommended next

    More decks on cybersecurity and related topics.