Microsoft Patches Record 972 Vulnerabilities in September
Microsoft issued a record 972 security patches this month, highlighting a dramatic surge in vulnerability discovery driven by artificial intelligence tools.

Microsoft's September patch release fixed approximately 972 vulnerabilities, with 112 classified as critical. Counting Chromium fixes ported to the Edge browser, the total reaches 997. This massive update follows 570 patches in July and 620 in August, bringing Microsoft's yearly total to 2,760 fixes—more than double last year's count. Security experts attribute this spike to AI-assisted vulnerability discovery, which Dustin Childs of the Zero Day Initiative describes as the "new normal" for the industry.
The release addresses two active zero-day exploits: CVE-2026-81963 in the Windows update service and CVE-2026-85880 in the Windows Advanced Local Procedure. Other severe flaws include CVE-2026-55007 in Exchange Server, which allows remote code execution via malicious Visio attachments, and CVE-2026-80097, a privilege escalation bug in Microsoft Authenticator. Additionally, the patch resolves 17 SharePoint vulnerabilities under CVE-2026-69465, a 9.8-rated Remote Desktop Services flaw (CVE-2026-69525), and CVE-2026-65669, which is one of 60 SQL Server privilege escalation bugs fixed this month and involves SQL Copilot.
For IT administrators and security practitioners, this release demands immediate triage. Childs noted he stopped counting wormable vulnerabilities—which spread automatically without user action—after finding more than 20. This surge in discoverable bugs is fueled by automated tools like Mozilla's Mythos, which identified 271 flaws in May. While critics debate the high costs and potential false positives of using large language models for security, the sheer volume of patches demonstrates that AI-assisted hunting is rapidly accelerating. Practitioners must brace for a continuous stream of high-volume updates as both defenders and attackers leverage AI tools.
This is our own summary of reporting by Ars Technica AI



