3 Sources
[1]
Microsoft September 2026 Patch Tuesday fixes nearly a thousand flaws, including two major zero-days
* Microsoft has fixed no fewer than 974 vulnerabilities in its latest Patch Tuesday release * Two were already being exploited in the wild, 114 categorized as 'Critical' * AI is to blame for boosting CVE discovery and also intensifying attacks Microsoft's September 2026 Patch Tuesday has become
[2]
Microsoft's AI vulnerability detection results in record-breaking Patch Tuesday, addressing 974 security flaws
It's not always interesting, but it's important to stay on top of operating system updates. However, if you're on Windows, you're definitely gonna want to prick up your ears for Microsoft's September 2026 Patch Tuesday. This might be Microsoft's biggest Patch Tuesday to date, addressing a whopping
[3]
Microsoft Addresses 974 Vulnerabilities in Record-Breaking Patch Tuesday
Microsoft's September 2026 Patch Tuesday includes fixes for 974 vulnerabilities across Windows, Office, SQL Server, Azure, Exchange Server, SharePoint Server, Skype for Business, and developer tools. It is the largest number of vulnerabilities Microsoft has addressed in a single monthly security
Share
Copy Link
Microsoft's September 2026 Patch Tuesday has become its largest security release on record, fixing 974 vulnerabilities across Windows, Office, and other products. The record-breaking update includes two actively exploited zero-days and 114 critical flaws, with AI-assisted discovery tools playing a key role in identifying the unprecedented number of security issues.
Microsoft's September 2026 Patch Tuesday has shattered all previous records, addressing 974 security vulnerabilities across its entire product stack
1
2
. This marks the company's largest security release to date, with Windows 10 and Windows 11 accounting for 723 of the patched flaws3
. Microsoft Office received 111 fixes, while SQL Server saw 62 vulnerabilities resolved3
. The update also addressed issues across Azure, Exchange Server, SharePoint Server, Skype for Business, and developer tools.
Source: PC Gamer
Among the 974 security vulnerabilities, two actively exploited zero-days pose immediate threats to enterprise and consumer systems. CVE-2026-85880 and CVE-2026-81963 were both being leveraged by attackers before Microsoft issued fixes
1
2
. CVE-2026-81963 affects Windows Update and allows privilege escalation, while CVE-2026-85880 targets the Windows Advanced Local Procedure Call subsystem3
. Microsoft confirmed both vulnerabilities were being exploited in the wild but withheld technical details about the attacks to prevent further exploitation.The record-breaking Patch Tuesday stems largely from Microsoft's deployment of AI vulnerability detection systems introduced in July. AI-assisted discovery tools have dramatically increased the company's ability to identify security flaws that might otherwise slip through traditional review processes
1
. Microsoft has patched 2,760 CVEs this year to date—more than double the 1,139 CVEs addressed in all of 2025, according to Dustin Childs1
. A decade ago in 2016, the company patched just 492 vulnerabilities for the entire year. Microsoft's AI systems detect potential bugs before security specialists and other software tools review the findings, with only high-confidence results reaching engineering teams for bug-fixing3
.Of the 974 flaws addressed, 114 were classified as critical vulnerabilities—more than one in 10 of the total
1
. The breakdown reveals 438 elevation of privilege vulnerabilities, 258 remote code execution vulnerabilities, and 19 security feature bypass vulnerabilities2
. This distribution underscores the diverse attack vectors threatening Windows systems and Microsoft products. Administrators should review individual severity ratings, affected product versions, and restart requirements before deploying updates across managed systems3
.Related Stories
Dustin Childs described this development as potentially the "new normal" for Microsoft's security release cycle
1
. The company isn't alone in addressing higher volumes of security issues—Adobe has shown similarly high activity, while browser developers including Google, Mozilla, Brave, and Microsoft have doubled their release cycles to two weeks to deliver fixes more quickly1
. The broader cybersecurity industry has witnessed AI's dual role, with tools like Claude Mythos finding 271 security vulnerabilities in Firefox and Anthropic reporting thousands of high-severity vulnerabilities discovered across major operating systems and web browsers2
.
Source: TechRadar
Windows 11 users running versions 24H2 and 25H2 should install KB5124008, while Windows 10 systems enrolled in the Extended Security Updates programme receive KB5122878
3
. Beyond addressing exploitable bugs, Microsoft used this update to fix known issues including Teams and Outlook crashes on Arm64 PCs and to upgrade Copilot+ AI components1
. The September release follows July's record-breaking Patch Tuesday, which stamped out 622 security vulnerabilities2
. Watch for continued increases in monthly patch volumes as AI-assisted analysis becomes more sophisticated and identifies vulnerabilities at scales previously impossible with manual review processes alone.Summarized by
Navi
[1]
09 Jul 2026•Technology

10 Jun 2026•Technology

23 Jul 2025•Technology

1
Science and Research

2
Technology
3
Technology