
Microsoft’s September patch release is a heavy one by any measure: the company says it fixed roughly 972 vulnerabilities, including 112 rated critical, in what appears to be a new high-water mark for its monthly security updates. The scale is striking even by recent standards, following two other record-setting months and underscoring how quickly the patching burden is rising across the software industry.
Microsoft’s patch count keeps climbing
Just two months ago, Microsoft patched what was then a record 570 vulnerabilities. Last month, that figure climbed again to about 620. In September, the tally jumped sharply once more, and researcher Dustin Childs of the Zero Day Initiative said the pattern looks like a “new normal.”
Childs also noted that the rise in vulnerability disclosures and fixes comes as companies increasingly brace for AI-assisted attacks. Two weeks ago, OpenAI, Anthropic, Amazon Web Services, Google, Microsoft, and 100 other companies and organizations published an open letter warning about a narrowing window for patching vulnerabilities ahead of an expected wave of AI-enabled exploitation.
Why the Microsoft patch release is so large
Counting Microsoft vulnerabilities is not always straightforward. Some issues may have been previously addressed, while others can affect non-Microsoft components or show up in related products. Even so, Childs counted 972 vulnerabilities fixed in Tuesday’s release, or 997 if Chromium fixes ported into Edge are included.
Of those new vulnerabilities, 112 are rated critical and the rest are classified as important. Microsoft has already fixed 2,760 vulnerabilities this year, more than double the total it had patched at the same point last year.
At the current pace, Childs said Microsoft could end the year having fixed more bugs than it did in all of 2023, 2024 and 2025 combined.
Two zero-days stand out in this month’s Microsoft patch release
Among the most notable issues are two zero-days: CVE-2026-81963 in the Windows update service and CVE-2026-85880 in the Windows Advanced Local Procedure. Microsoft did not provide public information about who is exploiting them or how widely.
Zero-days are especially important because they are already known to attackers or being actively exploited before users have a chance to patch. That makes them a priority for defenders, especially when they land inside core Windows components.
Other vulnerabilities security researchers highlighted
Childs called out several additional bugs from the release as especially noteworthy:
- CVE-2026-55007 in Exchange Server — A remote, unauthenticated attacker could execute code on an affected Exchange server simply by sending an email with a malicious Visio attachment.
- CVE-2026-80097 in Microsoft Authenticator — A local privilege escalation flaw. Childs described this as “the worst type of privilege escalation as it uses a bug in the authentication system itself.”
- CVE-2026-69465 in Microsoft Office SharePoint — Roughly 17 distinct vulnerabilities allowing remote code execution.
- CVE-2026-65669 in SQL Server — One of 60 SQL Server privilege escalation vulnerabilities this month, triggered when a user submits instructions through SQL Copilot.
- CVE-2026-69525 in Remote Desktop Services — A remote code execution flaw rated 9.8 in severity.
Wormable bugs raise the stakes
Childs said he encountered so many wormable vulnerabilities in this release that he stopped counting after 20. Wormable flaws are especially dangerous because they do not require user interaction and can spread from machine to machine on their own, creating the possibility of a fast-moving chain reaction across networks.
That makes the September patch cycle more than just a large administrative burden for IT teams. For organizations with exposed Exchange servers, Remote Desktop Services, SharePoint deployments or Windows infrastructure, the patch list includes several issues that could have serious consequences if left open.
AI-assisted vulnerability hunting is changing the pace
The broader backdrop to Microsoft’s busy patch month is the growing use of artificial intelligence in vulnerability discovery. Supporters argue that AI tools are helping researchers find serious flaws faster than traditional methods, which can improve security if the resulting bugs are fixed quickly.
Critics, however, question the cost, the number of false positives and the possibility that vendors are using AI hype to justify enormous spending on the same models now being credited for bug discovery. The long-term value of AI-assisted hunting is still unsettled, and the debate is likely to continue.
Still, some recent results are hard to ignore. Mozilla said in May that its researchers using Mythos found a record 271 vulnerabilities, with almost none of them being false positives. That kind of outcome is part of why Childs argues the industry may have entered a genuinely new phase of security research.
What IT teams should take from this month’s release
The immediate takeaway is simple: this is a release that deserves attention, not delay. Any environment running Exchange Server, Remote Desktop Services, SQL Server, SharePoint, or affected Windows components should be reviewed quickly, especially where internet exposure or privileged access is involved.
The larger takeaway is that patch management is becoming more demanding at the same time attackers may be getting more capable. Whether AI-driven discovery is a temporary surge or the start of a lasting shift, the number of fixes Microsoft is shipping now is already changing the expectations for defenders.
Source: Original report
Was this helpful?
Explore more: Application Audit & Review More Cybersecurity Tech News
Last Modified: September 9, 2026 at 10:31 pm
0 views
