The Daily Commit · Section Edition Front Page PHP AI Dev EN DE FR ES

Independent. Nonpartisan. Untested in production.

Tuesday, September 8, 2026 ARS TECHNICA
Security!

Microsoft fixes record 972 vulnerabilities in September, 112 rated critical

Microsoft's September 2026 patch release fixes a record 972 vulnerabilities, 112 of them critical, including two exploited zero-days.

ARS TECHNICA — Researchers attribute the surge to AI-assisted bug discovery, with Microsoft already patching 2,760 flaws this year alone.

Microsoft's September 2026 security update fixes a record 972 vulnerabilities, 112 of them rated critical. Counting ported Chromium fixes included in Edge, the total reaches 997, according to Dustin Childs of the Zero Day Initiative.

The record follows a rapid escalation. Two months earlier Microsoft patched 570 vulnerabilities, then 620 the month after. Google and other vendors have also published record numbers. Childs calls this spike the new normal and credits AI-assisted vulnerability discovery, while noting that a matching surge in active exploits has not appeared yet.

Two weeks before the release, OpenAI, Anthropic, Amazon Web Services, Google, Microsoft and around 100 other organizations published an open letter warning that the window for patching is narrowing ahead of an expected wave of AI-enabled attacks.

So far in 2026 Microsoft has fixed 2,760 vulnerabilities, more than double the figure from the previous year. At the current pace it will exceed the combined totals of 2023, 2024 and 2025.

Notable fixes include two zero-days: CVE-2026-81963 in the Windows Update service and CVE-2026-85880 in Windows Advanced Local Procedure Call. Both are under active exploitation. No public details about the attackers exist. Other highlights Childs flagged: CVE-2026-55007, an unauthenticated remote code execution in Exchange Server triggered by an email carrying a malicious Visio attachment; CVE-2026-80097, a privilege escalation in Microsoft Authenticator; CVE-2026-69465, covering roughly 17 remote code execution flaws in SharePoint; CVE-2026-65669, one of 60 SQL Server privilege escalations, exploitable through SQL Copilot; and CVE-2026-69525, a Remote Desktop Services RCE rated 9.8. Childs counted more than 20 wormable flaws before stopping.

Whether AI-assisted hunting is worth the cost remains disputed. Critics point to false positives and question the motives of companies recouping AI investments. Mozilla offered a counterpoint in May, reporting that its researchers using the Mythos tool found a record 271 vulnerabilities with almost no false positives.

Read the original source ↗

Rate this article: 0

Readers’ Forum

No contributions yet — open the debate.

◀ Briefs — Page D1

All stories real, just louder · The Daily Commit · Screen edition · Imprint · Privacy Policy