Microsoft breaks monthly record with nearly a thousand vulnerabilities fixed in single patch release
Microsoft’s September Patch Tuesday arrived with numbers that would have sounded implausible not long ago: 972 vulnerabilities fixed in one release, 112 of them rated Critical. For comparison, July patched 570 — itself a record at the time — and August climbed to 620. The pace isn’t slowing, and it isn’t unique to Microsoft; Google and others have also been publishing unprecedented patch volumes in recent months.
The dwarfs are working overtime
Dustin Childs, a researcher at the Zero Day Initiative, calls the surge “the new normal.” Microsoft’s security teams are managing to keep up with the release cadence, he says, but AI-assisted vulnerability discovery shows no sign of letting up. For now, Childs notes, there hasn’t been a corresponding rise in active exploitation of these flaws — but the operative word is “yet.”
The count is never exact
The official figure is never definitive. Some vulnerabilities were already addressed previously; others affect non-Microsoft products. By Childs’ tally, the current wave includes 972 new vulnerabilities, rising to 997 when Chromium fixes that flowed into Edge are added. Of those, 112 are Critical; the rest are rated Important. Year to date, 2,760 vulnerabilities have been patched — more than double last year’s total. At this rate, 2026 will close with more fixes than 2023, 2024 and 2025 combined.
Open letter and a dark forecast
Two weeks ago, OpenAI, Anthropic, AWS, Google, Microsoft and roughly a hundred other organizations published an open letter warning of a rapidly narrowing window to patch vulnerabilities before what they describe as a tsunami of AI-driven attacks that will exploit them first. The industry is taking the threat seriously and pushing out patches in unprecedented volume, but the question of whether remediation speed can match discovery speed remains open.
The new normal is already here
Childs concludes that even without a current spike in real-world exploitation, the potential damage from AI-driven attacks could become significant down the line. Organizations that deploy updates quickly buy themselves breathing room; those that don’t may find the window closes faster than they expected.