Microsoft fixes record 972 vulnerabilities in September patch

Microsoft's September Patch Tuesday shatters records with 972 vulnerability fixes, 112 critical, as AI-driven discovery accelerates.

By Central
Highlights
  • Microsoft fixed 972 vulnerabilities in September 2026, more than in entire years in the past.
  • 112 of the vulnerabilities were rated critical, indicating remote code execution risk without user interaction.
  • AI-assisted vulnerability discovery is driving the record number of patches, according to industry researchers.

Microsoft’s September 2026 Patch Tuesday shattered every previous record, with the company addressing approximately 972 vulnerabilities in a single monthly release — a staggering figure that dwarfs the 570 bugs fixed just two months ago and the 620 patched last month. Of those, 112 were rated critical, the highest severity classification in Microsoft’s assessment framework. The sheer scale of this release marks an inflection point in software security, one that industry researchers say is being driven by the accelerating use of artificial intelligence to discover vulnerabilities before defenders can close them.

The record-breaking September patch: 972 vulnerabilities and counting

Counting the precise number of vulnerabilities fixed in any given Microsoft patch release is rarely an exact science, as some bugs may have been previously addressed or affect non-Microsoft products. Dustin Childs, a researcher at the Zero Day Initiative, placed the count at 972 vulnerabilities in Tuesday’s release, with the figure rising to 997 when including fixes ported from the Chromium browser engine into Microsoft Edge. Of the new vulnerabilities addressed, 112 carry the critical rating, while the remainder are designated as important. The September release alone accounts for more vulnerabilities than many entire years in the recent past.

Microsoft has now fixed 2,760 vulnerabilities across all its products so far in 2026 — more than double the number from the same period last year. At this pace, the company will close the year having patched more bugs than it did in 2023, 2024, and 2025 combined. That trajectory signals a fundamental shift in both the discovery rate of software flaws and the industry’s capacity to respond.

What makes a vulnerability critical and why it matters

Microsoft assigns severity ratings to vulnerabilities based on the potential impact if exploited. A critical rating typically indicates that the flaw could allow remote code execution without user interaction or authentication — the most dangerous class of bug because it enables an attacker to take full control of a system from across the internet. The 112 critical vulnerabilities patched in September represent 112 distinct opportunities for catastrophic compromise if left unaddressed. For comparison, a typical Patch Tuesday in past years might include between 10 and 30 critical fixes. The September total is unprecedented.

Why patch volumes are spiking: AI-assisted vulnerability discovery

The dramatic increase in patched vulnerabilities is not happening in isolation across the software industry. Google and other major technology companies have also published record numbers of vulnerability fixes in recent months. The common thread, according to multiple researchers, is the growing use of artificial intelligence to automate and accelerate the discovery of software flaws.

Two weeks before Microsoft’s September release, an open letter signed by OpenAI, Anthropic, Amazon Web Services, Google, Microsoft, and more than 100 companies and organizations warned of a narrowing window for patching vulnerabilities ahead of an expected wave of AI-enabled attacks. The letter, published at openai.com/collective-cyberdefense, described a future in which attackers use AI to discover and exploit vulnerabilities at machine speed, overwhelming traditional human-driven security processes. The industry’s response, as reflected in these record patch volumes, is to invest heavily in automated vulnerability discovery and remediation — but the letter cautioned that the defensive side may still be losing ground.

AI-assisted vulnerability discovery works by training machine learning models on large datasets of known vulnerabilities, exploit code, and source code patterns. These models can then scan software for potential flaws far faster than human auditors, identifying candidate bugs that are then verified and patched by human engineers. The same technology, however, is equally available to malicious actors, who can use it to find exploitable vulnerabilities before they are discovered and fixed by vendors.

Dustin Childs and the Zero Day Initiative: This is the new normal

Dustin Childs, a well-known researcher at the Zero Day Initiative, has been tracking Microsoft’s Patch Tuesday releases for years. In his analysis of the September 2026 update, published September 8, he described the ongoing surge in vulnerability counts as the “new normal” — a phrase that carries significant weight coming from someone who has observed the industry’s patch cycles through multiple eras of change.

“On the one hand, congrats to the security gnomes at Microsoft for being able to patch bugs at this rate,” Childs wrote. “On the other hand, AI-assisted vulnerability discovery shows no signs of slowing down. However, we have not seen a correlating spike in active exploits — yet.”

That “yet” is the operative word. Childs’ analysis suggests that while defenders are working furiously to close vulnerabilities, the absence of a corresponding increase in active exploitation may be temporary. The infrastructure for automated exploit generation is still maturing, but the trajectory is clear: attackers are learning to weaponize AI, and when they do, the pressure on organizations to patch quickly will become existential.

What the Zero Day Initiative’s count tells us about the real scope

Childs’ count of 972 vulnerabilities is considered authoritative because the Zero Day Initiative runs one of the largest bug bounty programs in the world and has deep visibility into the vulnerability disclosure ecosystem. The slight discrepancy between Microsoft’s official count and third-party counts is normal and stems from differences in methodology. Some bugs may be counted by researchers but not appear in Microsoft’s own tally because they affect third-party components or were previously addressed. The important number is the trend: regardless of the exact count, the September release represents an order-of-magnitude increase over what was considered normal even two years ago.

Historical context: From record to record in record time

To understand how extraordinary the current moment is, consider the timeline. In July 2026, Microsoft patched 570 vulnerabilities — which itself was a record at the time. The previous all-time high had been set just months earlier, and before that, the record had stood for years. Then in August, Microsoft patched roughly 620 vulnerabilities, breaking the July record. Now September arrives with nearly 1,000 fixes. The acceleration is nonlinear and shows no signs of leveling off.

If we extend the view backward, the contrast becomes even starker. In all of 2023, Microsoft patched approximately 1,200 vulnerabilities across all its products. In 2024, that number rose to around 1,500. In 2025, it was roughly 1,800. In 2026 alone, the company is on track to patch more than 3,500 — a total that exceeds the three prior years combined. The compound growth rate is staggering.

What changed? The answer is a combination of factors: the maturation of AI-powered vulnerability discovery tools, increased investment in security research by Microsoft and other vendors, a growing bug bounty ecosystem that incentivizes researchers to find and report flaws, and a regulatory and reputational environment that punishes slow responses to security issues. But the single most important driver is AI. Both defenders and attackers are racing to harness the same technology, and the result is a flood of vulnerabilities being discovered on both sides.

The open letter: A coordinated warning from the industry’s largest players

The open letter published two weeks before the September patch was notable not just for its content but for its signatories. OpenAI, Anthropic, Amazon Web Services, Google, and Microsoft — companies that compete fiercely in the AI market — came together to issue a joint warning about the threat landscape. The letter’s central argument was that the window for patching vulnerabilities is shrinking, and that AI-enabled attacks will exploit flaws faster than human teams can respond.

The letter did not mince words. It described a future in which attackers use AI to scan for vulnerabilities, generate exploit code, and deploy attacks automatically — all within minutes or hours of a vulnerability being disclosed. In that environment, traditional patch cycles of 30, 60, or 90 days become untenable. Organizations must either patch within hours or risk being compromised. The letter called for collective action, including better vulnerability disclosure practices, shared threat intelligence, and investment in automated patching technologies.

The fact that Microsoft patched 972 vulnerabilities just two weeks after signing that letter is not a contradiction — it is evidence that the company is taking the warning seriously. The scale of the September release reflects an aggressive effort to get ahead of the AI-driven threat wave before it fully arrives.

What the Microsoft September 2026 patch means for organizations

For IT and security teams responsible for deploying patches, the September release presents both an opportunity and a challenge. The opportunity is that nearly 1,000 known vulnerabilities are now closed — assuming patches are applied promptly. The challenge is that deploying that many patches at scale is a massive operational undertaking, especially for organizations with complex environments, legacy systems, or compliance requirements that mandate testing before deployment.

Prioritization becomes critical. Not all 972 vulnerabilities pose equal risk. Organizations should focus first on the 112 critical-rated flaws, particularly those that affect internet-facing systems or that have known exploit code in the wild. Within the critical set, priority should go to vulnerabilities that enable remote code execution without authentication, as these represent the most direct threat. The remaining important-rated vulnerabilities should be addressed according to organizational risk tolerance and patch management capacity.

Automated patch management tools are no longer optional for enterprises operating at scale. The era of manually evaluating and testing every patch before deployment is ending, simply because the volume of patches has overwhelmed the human capacity to process them. Organizations that have not already invested in automated patch deployment, vulnerability scanning, and risk-based prioritization should do so now. The September patch is a preview of the new normal, and the pace will only accelerate.

How to handle the critical vulnerabilities in Microsoft‘s September release

The 112 critical vulnerabilities fixed in September span multiple product families, including Windows, Office, Exchange, SharePoint, and Azure services. Microsoft‘s security advisory pages provide detailed information about each vulnerability, including its Common Vulnerabilities and Exposures (CVE) identifier, severity score, and affected software versions. Security teams should cross-reference these advisories against their asset inventory to identify which systems require attention. For organizations using Microsoft’s own vulnerability management tools, the September update should already be reflected in their risk dashboards. For those relying on third-party tools, manual review of the advisory list is necessary.

The window for safe patching is not indefinite. History shows that once a large patch batch is released, attackers reverse-engineer the fixes to identify the underlying vulnerabilities and develop exploits. Organizations that delay deployment beyond a few weeks significantly increase their risk of compromise. The goal should be to patch all critical vulnerabilities within 48 hours of release, with important vulnerabilities addressed within two weeks. That cadence is aggressive but increasingly necessary.

Why the exploit spike hasn’t arrived — and why that might change quickly

Dustin Childs noted in his analysis that despite the record number of patches, there has not yet been a correlating spike in active exploitation. That observation is important for two reasons. First, it suggests that the defensive side is currently keeping pace with the offensive side — at least for now. The AI-assisted vulnerability discovery tools being used by Microsoft and other vendors are finding flaws before attackers can weaponize them. Second, the absence of a spike should not be mistaken for safety. The infrastructure for AI-driven exploitation is being built, and when it reaches maturity, the lag between disclosure and exploitation will collapse.

The open letter from the 100-plus organizations was essentially a warning that this lag is the only thing protecting the industry, and that it is shrinking. The current state of affairs — record patches, low exploitation — is fragile. Any breakthrough in automated exploit generation could tip the balance decisively toward attackers. And because AI development is advancing rapidly across the board, such a breakthrough could come at any time from any of thousands of research labs, criminal enterprises, or state-sponsored groups working on the problem.

The broader industry context: Google and others face the same trend

Microsoft is not alone in experiencing surging vulnerability counts. Google has also published record numbers of security fixes across Chrome, Android, and its cloud services in recent months. The same AI-driven forces are at work across the entire software ecosystem. Every company that writes software at scale is seeing more vulnerabilities discovered, and every company is racing to patch them faster.

This shared experience has created an unusual degree of cooperation among competitors. The open letter is one example. Another is the proliferation of coordinated vulnerability disclosure programs, bug bounty platforms, and shared threat intelligence feeds. The security industry recognizes that the AI-driven threat is not a problem any single company can solve alone. The math simply does not work: a single attacker only needs to find one exploitable vulnerability in one system to cause damage, while defenders must protect every system against every possible vulnerability. AI narrows the gap by accelerating defensive discovery, but it also accelerates offensive discovery. The net effect is that both sides are moving faster, and the overall risk landscape is becoming more dynamic.

What the Microsoft September patch record tells us about the future of software security

The September 2026 Patch Tuesday is a milestone that deserves careful study, not because of the number itself — which will almost certainly be broken — but because of what it represents. Software security has entered a new phase characterized by machine-speed discovery, automated patching pipelines, and an arms race between AI-powered defenders and AI-powered attackers. The days when a monthly patch batch of 100 vulnerabilities was considered large are over. The new normal is measured in the hundreds, and soon it may be measured in the thousands.

The implications extend beyond Microsoft and its customers. Every organization that relies on software — which is to say, every organization — must adapt to this reality. Security strategies that were adequate two years ago are now insufficient. Patch management processes designed for a slower pace of discovery will buckle under the current load. And the skills required to operate in this environment are changing: manual analysis of individual vulnerabilities is giving way to automated triage, risk scoring, and deployment at scale.

The AI-assisted vulnerability discovery that drove the September record is not a temporary phenomenon. It is a permanent feature of the software landscape going forward. The tools will improve on both sides of the equation, and the volume of discovered vulnerabilities will continue to rise until it reaches equilibrium with the capacity to patch them — which may take years to achieve. In the meantime, organizations that invest in automation, prioritization, and rapid deployment will be better positioned to survive the transition. Those that rely on manual processes and slow decision-making will face increasing risk with each passing month.

How to approach the new patch reality: practical steps for security teams

For security teams looking to adapt to the new environment, several concrete steps are worth taking. First, evaluate your current patch management cycle and identify bottlenecks. How long does it take from patch release to deployment across your entire environment? If the answer is more than a few days for critical vulnerabilities, the process needs to be streamlined. Second, invest in vulnerability prioritization tools that go beyond severity ratings to incorporate contextual risk factors such as asset value, exposure, and existing controls. Third, build relationships with software vendors to gain early access to patch information and threat intelligence. Fourth, develop incident response playbooks specifically for scenarios where a critical vulnerability is being actively exploited before a patch can be deployed. And fifth, educate executive leadership about the changing threat landscape so that security budgeting reflects the new reality.

What is driving the record number of vulnerabilities in Microsoft’s September patch?

The primary driver is AI-assisted vulnerability discovery, which enables both defenders and attackers to find software flaws at unprecedented speed. Microsoft and other vendors are using machine learning models to scan their codebases for potential vulnerabilities, resulting in a dramatic increase in the number of bugs identified and patched. The same technology is being used by security researchers in bug bounty programs and by adversaries seeking exploitable flaws. The September 2026 release reflects this acceleration, with 972 vulnerabilities fixed — more than the total for many entire years in the recent past.

The trajectory is clear: patch volumes will continue to rise as AI tools improve, and the pressure on organizations to deploy fixes quickly will intensify. The September record is not an anomaly but a preview of the operating conditions that will define software security for the foreseeable future. Organizations that recognize this and adapt their processes accordingly will be best positioned to navigate the new landscape. Those that treat it as a one-time spike will find themselves caught in a cycle of ever-increasing risk, ever-shorter patching windows, and ever-greater exposure to the next generation of AI-powered attacks.

Share This Article