Security Update

Microsoft Patches a Record 972 Vulnerabilities in September 2026

Microsoft's September 2026 patch fixes a record 972 vulnerabilities, 112 of them critical. Here's what's driving the spike and why AI-enabled attacks are the real concern.

LUMIEN4 min read
Microsoft Patches a Record 972 Vulnerabilities in September 2026

Microsoft's September 2026 Patch Tuesday fixed 972 vulnerabilities, the highest single-month total on record, with 112 rated critical. The number is striking on its own, but it comes after two consecutive months of record-breaking patches: roughly 570 in June and 620 in July. The industry-wide surge in patching volume is not accidental. It is a direct response to warnings from a coalition of more than 100 companies that AI-assisted attacks are about to start exploiting vulnerabilities faster than defenders can respond.

What happened

Month Vulnerabilities patched
June 2026 ~570 (then a record)
July 2026 ~620
September 2026 972 (current record)
Critical-severity (September) 112

Microsoft’s September Patch Tuesday dropped 972 fixes in a single release. Of those, 112 cleared the bar for critical severity, meaning they could be exploited remotely or without user interaction. Google and other major software vendors have also been shipping record patch volumes over the same period.

Two weeks before the September release, a coalition that included OpenAI, Anthropic, Amazon Web Services, Google, Microsoft, and more than 100 other companies and organizations published an open letter. The letter warned that the window for patching vulnerabilities before attackers exploit them is getting narrower, and that AI-enabled attacks are expected to accelerate that timeline considerably. You can find our earlier coverage of that AI security warning in our news section.

Why it matters

Dustin Childs, a researcher at the Zero Day Initiative (a program that acquires and discloses software vulnerabilities), told Ars Technica he considers this elevated patch volume the “new normal.” He also cautions that it may not be enough. Even with unprecedented patching activity, the damage from AI-assisted attacks could still be substantial over time.

The concern is straightforward: AI tools can help attackers find and weaponize vulnerabilities faster than security teams can write and deploy patches. When 112 critical flaws land in a single month, defenders face a triage problem. Not every organization can test and apply nearly a thousand patches quickly, which means exposure windows stay open longer than they should.

For businesses running Microsoft software (which covers most of the web), this is not a background concern. It is an active operational risk. The open letter from 100-plus companies was a public acknowledgment that the industry knows a more hostile environment is coming and is trying to get ahead of it.

Is this spike permanent or temporary?

The three consecutive record months suggest a structural shift rather than a one-off spike. Childs’ “new normal” framing aligns with that reading. Security teams and IT managers should plan for high patch volumes to continue rather than waiting for the cadence to slow down.

For businesses relying on automated workflows or AI integrations built on Microsoft infrastructure, unpatched systems create a real liability. If your stack touches Microsoft services and you are not applying patches on a regular tested cycle, the risk calculus has changed. Our AI integration work for clients always factors in patch management dependencies for exactly this reason.

Our take

972 vulnerabilities in one month is a number that deserves more than a shrug. The industry’s response, shipping more patches faster, is the right instinct, but it creates its own pressure. Smaller teams without dedicated IT staff are the ones most likely to fall behind on a 972-item list.

The AI-enabled attack angle is worth taking seriously. It is not a hypothetical cooked up to sell security software. When 100-plus companies including direct competitors co-sign an open letter about it, that is a signal. The practical implication for most business owners is less about tracking every CVE (Common Vulnerability and Exposure identifier) and more about making sure auto-update policies are active and patch cycles are documented.

If you are running a web presence or SaaS stack built on Microsoft services, now is a good time to review your update and monitoring setup. Our Care Plan covers exactly this kind of ongoing maintenance so it does not fall through the cracks.

What to do about it

  1. Enable automatic updates on all Windows and Microsoft 365 systems if you have not already.
  2. Prioritize the 112 critical-rated patches first. Your IT team or vendor can filter by CVSS score in Windows Update or WSUS.
  3. Document your patch cycle so you have a record of what was applied and when. Auditors and insurers increasingly ask for this.
  4. Review any third-party software that also shipped record patch volumes this cycle (Google and others are in the same position).
  5. If your team lacks the bandwidth to keep up, consider a managed maintenance plan rather than letting patches queue up.

The practical takeaway: a 972-vulnerability patch release is not something to file away. Set your update policy to automatic, triage by severity, and document the process before the next record-breaking month arrives.

Source: Ars Technica · AI

Frequently asked questions

How many vulnerabilities did Microsoft patch in September 2026?

Microsoft patched 972 vulnerabilities in September 2026, a new all-time record. Of those, 112 were rated critical severity.

Why is Microsoft releasing so many patches all of a sudden?

The industry is accelerating patch releases in response to warnings about AI-enabled attacks that can find and exploit vulnerabilities faster. A coalition of more than 100 companies including Microsoft, OpenAI, Google, and Anthropic published an open letter about the narrowing window for patching before attackers strike.

What did the Zero Day Initiative say about the Microsoft patch spike?

Dustin Childs, a researcher at the Zero Day Initiative, called the elevated patch volumes the 'new normal' and warned that AI-assisted attacks could still cause substantial damage even with unprecedented patching activity.

Should businesses be worried about the rise in Microsoft vulnerabilities?

Yes, particularly smaller teams without dedicated IT staff. With 112 critical patches in a single month, maintaining a tested patch cycle and enabling automatic updates is more important than ever.

More from AI