Microsoft Patches Over 950 Vulnerabilities, Aided by AI

Microsoft’s September 2026 patch addressed over 950 vulnerabilities, bringing the year’s total to 2,750—more than double its previous annual record. This surge is largely attributed to AI-assisted security research, though organizations may struggle to keep pace with evaluating, prioritizing, and deploying patches.
AI Tools Drive Record Patch Numbers
Security expert Brian Krebs notes that Microsoft is not alone in releasing large patch bundles, as many companies credit AI tools for their increased success. This month, Microsoft fixed two actively exploited “zero-day” flaws: CVE-2026-81963 and CVE-2026-85880, both allowing attackers to raise privileges on Windows systems. Researchers from Volexity, Proofpoint, Airbus Helicopters, and the Microsoft Threat Intelligence Center discovered these vulnerabilities.
Of the patched vulnerabilities, 113 were classified as “critical”, meaning they could be exploited with minimal user interaction. Remote code execution and elevation of privilege vulnerabilities accounted for 258 and 438 of the fixes, respectively.
Read Also: Microsoft Unveils .NET 11 RC1 with New Language Features
Industry Concerns Over Patch Volume
The surge in patches follows an open letter from tech giants, including OpenAI, Anthropic, and Microsoft, warning of more sophisticated AI-enabled cyberattacks. Dan Goodin of Ars Technica observed that the industry is now releasing an unprecedented number of patches.
For organizations, the challenge lies not just in applying patches but in prioritizing them. Jack Bicer, Director of Vulnerability Research at Action1, emphasized the need to distinguish between vulnerabilities requiring immediate action and those that can follow a normal deployment cycle. Marva Bailer, CEO of Qualaix, added that understanding exposure, testing patches, and deploying them across interconnected systems transform a technical issue into a business challenge.
The Pressure of Faster Discovery
While AI helps defenders identify vulnerabilities sooner, it also compresses the time between discovery, testing, and deployment. The sheer volume of patches raises questions about how organizations can adapt their processes to handle such rapid changes.
