With its latest September 2026 Patch, which addresses more than 950 vulnerabilities, Microsoft has patched about 2,750 vulnerabilities so far this year, more than double its previous annual record of about 1,250 in 2020. While many attribute this surge to AI-assisted security research, organizations may struggle to keep pace and fully benefit from these advances, particularly when it comes to evaluating, prioritizing, and deploying patches.
According to security expert Brian Krebs, Microsoft is not the only major software company "shipping monster patch bundles lately". Krebs notes that many companies attribute the growing success of their efforts to using AI tools. In his analysis, he highlights two major risks:
There are two “zero-day” flaws fixed this month that are being actively exploited: both CVE-2026-81963 and CVE-2026-85880 allow an attacker to elevate their privileges on Windows system.
CVE-2026-85880 was discovered by researchers at security companies Volexity and Proofpoint, while CVE-2026-81963 was independently reported by researchers at Airbus Helicopters and the Microsoft Threat Intelligence Center.
Additionally, Krebs says, 113 of the fixed vulnerabilities were classified by Microsoft as "critical", meaning they could be exploited with little or no user interaction. BleepingComputer provides an exhaustive classification and list of all patched security vulnerabilities, including 258 remote code execution, 438 elevation of privilege, and others.
Reporting for Ars Technica, Dan Goodin observed that the "industry is [...] pumping out unprecedented numbers of patches in their software" following an open letter from OpenAI, Anthropic, AWS, Google, Microsoft, and other companies warning that "AI-enabled cyber attacks will become far more widespread and sophisticated" in the near future.
The security update prompted several reactions from the software security community, including concerns about the sheer volume of patches that organizations must evaluate. Jack Bicer, Director of Vulnerability Research at Action1, highlighted the challenge of prioritizing vulnerabilities:
At this scale, the challenge is not simply getting through the patch list. It is knowing what needs attention first. With hundreds of updates landing at once, IT and security teams need to quickly separate the vulnerabilities that demand immediate action from those that can follow the normal deployment cycle.
Marva Bailer, founding CEO at Qualaix, observed that:
Finding the problem is one step. Organizations still have to understand their exposure, test the patch, determine what else it might affect and then deploy it across potentially thousands of devices and interconnected systems. That is where a "software patch" becomes a business story.
She also warned that AI, while helping defenders find weaknesses sooner, also puts greater pressure on the time between discovery, testing and deployment.
As a final comment, Tyler Reguly, security R&D associate director at Fortra, noted that "as long as Microsoft is playing catch-up on patching vulnerabilities, numbers have lost all meaning". However, he says, it is important to acknowledge the "our current normal" and consider how people and processes are dealing with such high numbers of patches, which must be vetted and tested before deployment.