Microsoft’s September 2026 security update fixes a record 972 vulnerabilities, including 112 flaws classified as critical or high severity. The unusually large release highlights the growing challenge of addressing software vulnerabilities before they are exploited by attackers.
Microsoft patched a record 570 vulnerabilities just two months ago, followed by approximately 620 fixes last month. Google and other technology companies have also reported record-breaking numbers of vulnerabilities in recent months.
Two weeks ago, OpenAI, Anthropic, Amazon Web Services, Google, Microsoft, and more than 100 other companies and organizations issued an open letter warning that the window for patching vulnerabilities is shrinking. The groups cautioned that a surge of AI-powered cyberattacks could lead to vulnerabilities being exploited more quickly than ever before.
As the cybersecurity industry prepares for increasingly capable AI-assisted attacks, software companies are releasing an unprecedented volume of security updates to protect users and infrastructure.
Microsoft’s record patch release may be the new normal
Dustin Childs, a researcher at the Zero Day Initiative, described the sharp increase in security fixes as the “new normal.” However, he also warned that AI-assisted attacks could cause significant damage if attackers begin using artificial intelligence to discover and exploit vulnerabilities at scale.
“On the other hand, congratulations to the security gurus at Microsoft for being able to patch bugs at this pace,” Childs wrote in his September 2026 security update review. “Meanwhile, AI-powered vulnerability discovery shows no signs of slowing down. However, we have yet to see a spike in active exploits related to this.”
Determining the exact number of vulnerabilities addressed in Microsoft’s monthly security updates is not always straightforward. Some flaws may have been fixed previously, while others may affect third-party components or products integrated into Microsoft software.
According to Childs’ tally, Microsoft’s September release addresses 972 vulnerabilities. The total rises to 997 when fixes for the Chromium browser engine included in Microsoft Edge are counted. Of the newly addressed vulnerabilities, 112 are rated critical, while the remainder are classified as important.
Microsoft has now fixed approximately 2,760 vulnerabilities in 2026—more than twice the number addressed last year. If the current pace continues, the company could finish the year having patched more vulnerabilities than it did in 2023, 2024, and 2025 combined.
Source: arstechnica.com


