Key facts
- Microsoft's September patch addresses a record 972 vulnerabilities.
- 112 of the patched vulnerabilities are rated critical.
- Two zero-day vulnerabilities affecting Windows update services were included.
- The high volume of patches is attributed to the increasing threat of AI-enabled cyberattacks.
- Microsoft has fixed 2,760 vulnerabilities this year, more than double last year's total.
Microsoft has released its September security update, addressing an unprecedented 972 vulnerabilities, with 112 of them classified as critical. This marks a significant increase from previous patch cycles, with the company having already fixed 2,760 vulnerabilities this year, more than double the number from the previous year.
This surge in patched bugs is seen as a response to the growing threat of AI-enabled cyberattacks. Industry leaders, including OpenAI, Anthropic, Amazon Web Services, Google, and Microsoft, recently published an open letter warning of a narrowing window to patch vulnerabilities ahead of an expected wave of AI-driven exploits. Dustin Childs, a researcher at the Zero Day Initiative, described the high volume of patches as the 'new normal' in cybersecurity, while cautioning that the potential damage from AI-assisted attacks could still be substantial.
Among the notable vulnerabilities addressed are two zero-days: CVE-2026-81963 in the Windows update service and CVE-2026-85880 in the Windows Advanced Local Procedure. While there is no public information on their exploitation, their inclusion highlights the ongoing efforts to secure software against emerging threats.
