Microsoft released its September 2026 security update, addressing 972 vulnerabilities, with 112 rated critical, the highest number in its history. This follows a previous record of 570 vulnerabilities patched in the same timeframe last year.
Microsoft reported 972 vulnerabilities fixed in the latest update, with 997 when including fixes for Chromium browser porting. Of these, 112 are critical, and the rest are important. This marks more than double the number of vulnerabilities fixed compared to the same period last year.
The update includes notable vulnerabilities such as two zero-days, CVE-2026-81963 and CVE-2026-85880, in the Windows update service and Windows Advanced Local Procedure, respectively. Other critical flaws include CVE-2026-55007 in Exchange Server, allowing remote code execution via a malicious Visio attachment, and CVE-2026-80097, a local privilege escalation in Microsoft Authenticator.
"On the one hand, congrats to the security gnomes at Microsoft for being able to patch bugs at this rate," said Dustin Childs, a researcher at the Zero Day Initiative. "On the other, AI-assisted vulnerability discovery shows no signs of slowing down. However, we have not seen a correlating spike in active exploits—yet."
The industry is responding to a growing threat of AI-enabled attacks, with companies like Google, OpenAI, and Amazon Web Services publishing open letters warning of an impending surge in exploit attempts. Critics remain skeptical about the effectiveness of AI-assisted vulnerability hunting, citing high costs and false positives.
Microsoft did not specify the exact number of wormable vulnerabilities found, but the researcher noted he stopped counting at 20. These flaws can spread autonomously, posing a significant risk if not addressed promptly.
Source: arstechnica