
Microsoft Patches Nearly 1,000 Bugs in September as AI-Powered Attacks Loom
Key takeaways
- Microsoft patches 972 vulnerabilities in September, including 112 critical flaws and at least 20 wormable bugs
- Industry racing to patch before AI-assisted attacks exploit flaws at scale, per joint letter from 100+ organizations
- Microsoft on pace to fix 2,760 flaws in 2026, exceeding combined totals of previous three years
Microsoft shipped patches for approximately 972 vulnerabilities this month, with 112 rated as critical severity—the highest monthly total on record. The previous benchmark, set just two months earlier, was 570 vulnerabilities. This acceleration follows a June release addressing 620 flaws, and mirrors similar spikes across Google, Amazon Web Services, and other major vendors.
The unprecedented pace reflects industry anxiety over AI-assisted vulnerability hunting and exploitation. Two weeks ago, Microsoft, OpenAI, Anthropic, Google, AWS, and roughly 100 other organizations published a joint letter warning of a shrinking window to patch flaws before attackers deploy AI tools to weaponize them. Researcher Dustin Childs from the Zero Day Initiative noted that at least 20 vulnerabilities in this month's release are wormable—meaning they can spread automatically without user interaction.
Microsoft has already fixed 2,760 vulnerabilities in 2026, more than double last year's total and potentially exceeding the combined output of 2023, 2024, and 2025.
The bigger picture
The patch volume appears genuine and reflects real progress, not marketing theater. Mozilla's May report documented 271 vulnerabilities discovered via AI tools with minimal false positives, lending credibility to the effectiveness claim. However, skepticism remains warranted: the gap between record patches and record active exploits hasn't yet closed. If attackers outpace defenders in the next 12 months, these historic patch numbers will prove insufficient.
We're tracking this because the numbers are genuinely staggering and the stakes are concrete—wormable vulnerabilities that auto-propagate matter to every connected device. This isn't hype; it's the security industry essentially admitting the threat model has shifted. We'll be watching whether exploit counts spike to match patch counts by year-end.
As an Amazon Associate, LagPing earns from qualifying purchases. Product links are affiliate links.
You might also like
News Outlets Turn on AI Backers: Seattle Times, Newsday Sue OpenAI and Microsoft
Sep 6

Lambda bets $1B debt gamble on rapid GPU deployment to Microsoft
Aug 29

Amazon's Nvidia GPU spending nearly doubles as AI chip demand reshapes cloud infrastructure
Aug 27

Double Fine Reclaims Full Rights to Its Back Catalog After Parting Ways With Microsoft
Aug 22