Why this month’s Microsoft patch release is a doozy

← Back to the feed

Why this month’s Microsoft patch release is a doozy

Ars Technica · 6 hours ago

Microsoft has released its September patch update fixing a record 972 vulnerabilities, 112 of them rated critical, as the tech industry races to shore up software defences ahead of an anticipated wave of AI-assisted cyberattacks. The scale of the release far exceeds prior "record" months this year, and reflects a broader trend across the industry, with security researchers warning that AI is being used both to discover flaws at unprecedented speed and, potentially soon, to exploit them.

The September figure dwarfs June's then-record 570 fixes and July's 620, and brings Microsoft's total for 2026 to 2,760 vulnerabilities patched, more than double last year's tally and already on course to exceed 2023, 2024 and 2025 combined. The release includes two actively significant zero-days (CVE-2026-81963 and CVE-2026-85880) and, according to researcher Dustin Childs of the Zero Day Initiative, more than 20 "wormable" flaws that could spread between machines without user interaction. The surge follows an open letter from OpenAI, Anthropic, Google, Microsoft, AWS and over 100 other organisations warning of a shrinking window to patch before AI-enabled attacks become widespread, though Childs notes no corresponding spike in active exploitation has yet been observed.

  • Microsoft patched a record 972 vulnerabilities in September, 112 critical.
  • Surge tied to fears of AI-assisted attacks and AI-aided bug discovery.
  • Release includes two zero-days and over 20 wormable flaws.

Software

Read the full article at the source →