Microsoft's September 2026 security update fixes a record 972 vulnerabilities, 112 of them rated critical. Counting ported Chromium fixes included in Edge, the total reaches 997, according to Dustin Childs of the Zero Day Initiative.
The record follows a rapid escalation. Two months earlier Microsoft patched 570 vulnerabilities, then 620 the month after. Google and other vendors have also published record numbers. Childs calls this spike the new normal and credits AI-assisted vulnerability discovery, while noting that a matching surge in active exploits has not appeared yet.
Two weeks before the release, OpenAI, Anthropic, Amazon Web Services, Google, Microsoft and around 100 other organizations published an open letter warning that the window for patching is narrowing ahead of an expected wave of AI-enabled attacks.
So far in 2026 Microsoft has fixed 2,760 vulnerabilities, more than double the figure from the previous year. At the current pace it will exceed the combined totals of 2023, 2024 and 2025.
Notable fixes include two zero-days: CVE-2026-81963 in the Windows Update service and CVE-2026-85880 in Windows Advanced Local Procedure Call. Both are under active exploitation. No public details about the attackers exist. Other highlights Childs flagged: CVE-2026-55007, an unauthenticated remote code execution in Exchange Server triggered by an email carrying a malicious Visio attachment; CVE-2026-80097, a privilege escalation in Microsoft Authenticator; CVE-2026-69465, covering roughly 17 remote code execution flaws in SharePoint; CVE-2026-65669, one of 60 SQL Server privilege escalations, exploitable through SQL Copilot; and CVE-2026-69525, a Remote Desktop Services RCE rated 9.8. Childs counted more than 20 wormable flaws before stopping.
Whether AI-assisted hunting is worth the cost remains disputed. Critics point to false positives and question the motives of companies recouping AI investments. Mozilla offered a counterpoint in May, reporting that its researchers using the Mythos tool found a record 271 vulnerabilities with almost no false positives.




Comments
No comments yet — be the first.
Open the discussion
No account or password needed — just enter your e-mail and we’ll send you a one-time sign-in link. First time here? You’re set up automatically.
Your rating will be applied automatically after you sign in.
Check your inbox
We’ve sent a sign-in link to …. Open it on this device — this tab will sign you in automatically.
Nothing arrived? Check your spam folder — and mark the mail as "Not spam" so it lands in your inbox next time.