Microsoft patches a record 972 vulnerabilities, 112 critical

Microsoft patches a record 972 vulnerabilities, 112 critical

Microsoft's monthly security update for September 2026 fixed a record 972 vulnerabilities, according to Ars Technica, with 112 rated critical severity and the rest rated important. Counting the porting of fixes for the Chromium browser built into Edge, the total climbs to 997.

This is the third month running that Microsoft has broken its own record: it patched a then-record 570 vulnerabilities two months earlier, then some 620 last month, before September's 972. Already this year, Microsoft has fixed 2,760 vulnerabilities, more than double the number over the same period last year, putting the company on pace to fix more bugs in 2026 alone than in 2023, 2024 and 2025 combined. Google and other companies have also published record vulnerability counts in recent months, though the article gives no figures for them.

The spike follows an open letter published two weeks earlier by OpenAI, Anthropic, Amazon Web Services, Google, Microsoft and 100 other companies and organizations, warning that the window for patching vulnerabilities is narrowing ahead of an expected wave of AI-enabled attacks that exploit them first.

Dustin Childs, a researcher at the Zero Day Initiative, called the pattern the "new normal." He credited Microsoft's team for keeping pace: "On the one hand, congrats to the security gnomes at Microsoft for being able to patch bugs at this rate." He also warned that AI-assisted vulnerability discovery shows no sign of slowing, though the industry has not yet seen a corresponding spike in active exploitation, and that the eventual damage from AI-assisted attacks could still be substantial.

The article notes that counting vulnerabilities in a Microsoft patch release precisely is never exact science: some bugs were previously addressed or affect non-Microsoft products, which is why the total is reported as Childs's own count, 972, or 997 including the ported Chromium fixes.

Key facts

  • Microsoft's September 2026 patch release fixed a record 972 vulnerabilities, 112 of them rated critical (997 counting ported Chromium fixes for Edge).
  • It is the third consecutive record month: 570 vulnerabilities two months earlier, then 620 the month after that, then 972 in September.
  • Microsoft has fixed 2,760 vulnerabilities so far in 2026, more than double last year's pace, putting it on track to exceed 2023, 2024 and 2025 combined.
  • Two weeks earlier, OpenAI, Anthropic, Amazon Web Services, Google, Microsoft and 100 other companies and organizations signed an open letter warning that the window to patch vulnerabilities before AI-enabled attackers exploit them is narrowing.
  • Zero Day Initiative researcher Dustin Childs called the surge the "new normal," saying AI-assisted vulnerability discovery keeps accelerating even though a matching spike in active exploitation has not shown up yet.

Why it matters

September's count is the highest Microsoft has ever recorded in a single month and the third consecutive record, matching a broader pattern that a coalition including OpenAI, Anthropic, AWS, Google and Microsoft flagged two weeks earlier: the time available to patch a flaw before AI-enabled attackers exploit it is shrinking. The trend suggests AI is reshaping the pace of vulnerability discovery itself, not just how attacks unfold once a flaw is known.

Who it affects

Anyone running Windows or other Microsoft products is directly affected, since IT and security teams face an unusually large patch batch to review and deploy this month. The pattern extends beyond Microsoft: the article notes Google and other companies have also published record vulnerability counts recently, though it gives no numbers for them. The open letter's signatories, over 100 companies and organizations including OpenAI, Anthropic, AWS, Google and Microsoft, treat this as an industry-wide operational problem rather than one company's issue.

How to use it

For security and IT teams, the practical takeaway is to prioritize the 112 critical-rated fixes in this release first, since the remaining important-rated bugs can generally follow a standard patch-cycle timeline. Given the industry's own warning about a narrowing window before AI-enabled exploitation, delaying deployment of the critical patches carries more risk this month than usual.

How solid is it

The reporting comes from Ars Technica, and the vulnerability count is attributed to Dustin Childs of the Zero Day Initiative, a group that independently tracks Microsoft's monthly patches. The article itself cautions that an exact count is never fully precise, since some listed bugs were already addressed elsewhere or affect non-Microsoft products, which is why the figure is given as roughly 972 by Childs's count, or 997 including the ported Chromium fixes for Edge.

Risks and caveats

The source gives no calendar dates for the events it describes, only relative markers such as "two months ago" and "Tuesday." It names no specific vulnerabilities or CVE identifiers and does not explain the mechanism by which AI is supposedly speeding up discovery beyond Childs's general assertion. Childs himself notes that despite the surge in patches, there has been no corresponding spike in active exploitation yet, an important qualifier since the open letter's warning is about vulnerability, not confirmed attacks. The article also does not list the full roster of the 100 companies behind the open letter or what it specifically asks for.

“On the one hand, congrats to the security gnomes at Microsoft for being able to patch bugs at this rate.”

— Dustin Childs, Zero Day Initiative