Microsoft patches record 972 vulnerabilities in September 2026
Original: Why this month's Microsoft patch release is a doozy
Why This Matters
Record patch volumes signal that AI-driven vulnerability discovery is fundamentally accelerating the software security lifecycle industry-wide.
Microsoft's September 2026 Patch Tuesday addresses a record 972 vulnerabilities, 112 rated critical. Two zero-days are actively exploited. The patch volume is driven by AI-assisted bug discovery, with Microsoft having fixed 2,760 vulnerabilities so far in 2026—more than double last year's total.
Microsoft's September 2026 Patch Tuesday release set a new record with approximately 972 vulnerabilities patched, 112 of which carry a critical severity rating. Including Chromium-based fixes ported into Edge, the total reaches 997. The release follows a rapid escalation: Microsoft patched roughly 570 vulnerabilities in July 2026 and 620 in August. Already in 2026, Microsoft has addressed 2,760 vulnerabilities—more than double the prior year's count. At the current pace, the annual total will exceed the combined figures for 2023, 2024, and 2025.
The surge coincides with growing concern over AI-assisted vulnerability discovery. Two weeks prior to the release, OpenAI, Anthropic, AWS, Google, Microsoft, and over 100 organizations co-signed an open letter warning of a narrowing window for patching before AI-enabled attacks begin actively exploiting flaws at scale.
Zero Day Initiative researcher Dustin Childs described the trend as the 'new normal,' noting that while AI-assisted discovery is accelerating, a corresponding spike in active exploits has not yet materialized. This month's release includes two actively exploited zero-days: CVE-2026-81963 in the Windows update service and CVE-2026-85880 in Windows Advanced Local Procedure Call. Other notable flaws include a remote code execution bug in Exchange Server triggered by a malicious Visio email attachment (CVE-2026-55007), a privilege escalation in Microsoft Authenticator (CVE-2026-80097), approximately 17 SharePoint RCE vulnerabilities, and 60 SQL Server privilege escalation bugs.