Skip to content
Tech News
← Back to articles

Why this month's Microsoft patch release is a doozy

read original get Yubico YubiKey 5 NFC Security Key → more articles
Why This Matters

Microsoft just patched a record ~972 vulnerabilities in a single month, with 112 rated critical — part of an industry-wide surge driven largely by AI-assisted bug discovery. It signals a 'new normal' where patch volumes far outpace historical levels, straining IT teams even though active exploitation hasn't yet spiked to match.

Key Takeaways
Worth a Look

Yubico YubiKey 5 NFC Security Key — When patch cycles balloon to hundreds of vulnerabilities a month, strong account security is one thing you fully control. The YubiKey 5 NFC adds hardware-backed two-factor and passkey login to Microsoft accounts, Google, and password managers via USB-A or a tap on your phone. It's a pocket-sized way to keep credential-stealing attacks from paying off while you wait on updates.

See Yubico YubiKey 5 NFC Security Key on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.

Microsoft’s patch for September is a doozy, with a record number of roughly 972 vulnerabilities fixed and 112 of them meeting the high critical-severity threshold.

It was only two months ago that Microsoft patched a then-record 570 vulnerabilities. Google and other companies have also published record numbers of vulnerabilities in recent months. Two weeks ago, OpenAI, Anthropic, Amazon Web Services, Google, Microsoft, and 100 companies and organizations published an open letter warning of a narrowing window for patching vulnerabilities ahead of an expected tsunami of AI-enabled attacks that actively exploit them first. The industry is taking the threat seriously by pumping out unprecedented numbers of bugs in their software.

Welcome to the new normal

Dustin Childs, a researcher at the Zero Day Initiative, calls the spikes the “new normal” and also cautions that despite them, the damage that’s likely to result from AI-assisted attacks could eventually be substantial.

“On the one hand, congrats to the security gnomes at Microsoft for being able to patch bugs at this rate,” Childs wrote Tuesday. “On the other hand, AI-assisted vulnerability discovery shows no signs of slowing down. However, we have not seen a correlating spike in active exploits—yet.”

Counting the precise number of vulnerabilities fixed in a monthly patch release for Microsoft is never an exact science. In some cases, the bugs were previously addressed or affected non-Microsoft products. By Childs’s count, Tuesday’s release patches 972 vulnerabilities, and 997 when counting the porting of fixes for the Chromium browser incorporated into Edge. Of the new vulnerabilities, 112 of them are rated critical, with the remainder carrying the important designation. Already this year, Microsoft has fixed 2,760 vulnerabilities, more than double the number from last year. At this rate, Microsoft will complete the year having fixed more bugs than all of 2023, 2024, and 2025 combined.

Credit: Microsoft Credit: Microsoft

Notable vulnerabilities in this month’s release include two zero-days, CVE-2026-81963 and CVE-2026-85880 in the Windows update service and the Windows Advanced Local Procedure, respectively. There’s no public information about who is exploiting them or how broadly. Other notable vulnerabilities Childs called out are: