Microsoft's September 2026 Patch Tuesday has become its largest security release on record, fixing 974 vulnerabilities across Windows, Office, and other products. The record-breaking update includes two actively exploited zero-days and 114 critical flaws, with AI-assisted discovery tools playing a key role in identifying the unprecedented number of security issues.

Microsoft Delivers Record-Breaking Patch Tuesday with 974 Security Fixes

Microsoft's September 2026 Patch Tuesday has shattered all previous records, addressing 974 security vulnerabilities across its entire product stack

1

2

. This marks the company's largest security release to date, with Windows 10 and Windows 11 accounting for 723 of the patched flaws

3

. Microsoft Office received 111 fixes, while SQL Server saw 62 vulnerabilities resolved

3

. The update also addressed issues across Azure, Exchange Server, SharePoint Server, Skype for Business, and developer tools.

Source: PC Gamer

Source: PC Gamer

Two Actively Exploited Zero-Days Demand Immediate Attention

Among the 974 security vulnerabilities, two actively exploited zero-days pose immediate threats to enterprise and consumer systems. CVE-2026-85880 and CVE-2026-81963 were both being leveraged by attackers before Microsoft issued fixes

1

2

. CVE-2026-81963 affects Windows Update and allows privilege escalation, while CVE-2026-85880 targets the Windows Advanced Local Procedure Call subsystem

3

. Microsoft confirmed both vulnerabilities were being exploited in the wild but withheld technical details about the attacks to prevent further exploitation.

AI in Cybersecurity Drives Unprecedented Vulnerability Discovery

The record-breaking Patch Tuesday stems largely from Microsoft's deployment of AI vulnerability detection systems introduced in July. AI-assisted discovery tools have dramatically increased the company's ability to identify security flaws that might otherwise slip through traditional review processes

1

. Microsoft has patched 2,760 CVEs this year to date—more than double the 1,139 CVEs addressed in all of 2025, according to Dustin Childs

1

. A decade ago in 2016, the company patched just 492 vulnerabilities for the entire year. Microsoft's AI systems detect potential bugs before security specialists and other software tools review the findings, with only high-confidence results reaching engineering teams for bug-fixing

3

.

Critical Vulnerabilities Represent Growing Security Challenges

Of the 974 flaws addressed, 114 were classified as critical vulnerabilities—more than one in 10 of the total

1

. The breakdown reveals 438 elevation of privilege vulnerabilities, 258 remote code execution vulnerabilities, and 19 security feature bypass vulnerabilities

2

. This distribution underscores the diverse attack vectors threatening Windows systems and Microsoft products. Administrators should review individual severity ratings, affected product versions, and restart requirements before deploying updates across managed systems

3

.

The New Normal for Microsoft Patch Tuesday Updates

Dustin Childs described this development as potentially the "new normal" for Microsoft's security release cycle

1

. The company isn't alone in addressing higher volumes of security issues—Adobe has shown similarly high activity, while browser developers including Google, Mozilla, Brave, and Microsoft have doubled their release cycles to two weeks to deliver fixes more quickly

1

. The broader cybersecurity industry has witnessed AI's dual role, with tools like Claude Mythos finding 271 security vulnerabilities in Firefox and Anthropic reporting thousands of high-severity vulnerabilities discovered across major operating systems and web browsers

2

.

Source: TechRadar

Source: TechRadar

Installation Details and Additional Fixes

Windows 11 users running versions 24H2 and 25H2 should install KB5124008, while Windows 10 systems enrolled in the Extended Security Updates programme receive KB5122878

3

. Beyond addressing exploitable bugs, Microsoft used this update to fix known issues including Teams and Outlook crashes on Arm64 PCs and to upgrade Copilot+ AI components

1

. The September release follows July's record-breaking Patch Tuesday, which stamped out 622 security vulnerabilities

2

. Watch for continued increases in monthly patch volumes as AI-assisted analysis becomes more sophisticated and identifies vulnerabilities at scales previously impossible with manual review processes alone.

Today's Top Stories

© 2026 TheOutpost.AI All rights reserved