On 8 September 2026, Microsoft issued updates to plug at least 974 security holes across Windows and other products — by far its biggest single Patch Tuesday batch. The release tops the company's previous high from July, when it shipped fixes for at least 570 vulnerabilities. Microsoft says artificial intelligence is helping speed vulnerability discovery. Security researchers warn that many organizations are already struggling with the slower work of testing and deploying so many fixes each month.
Confirmed
The counts and severity labels come from Microsoft's September 2026 security updates, published through the Microsoft Security Response Center (MSRC) Security Update Guide. Two flaws fixed this month are zero-days Microsoft says are being actively exploited: CVE-2026-81963 (Windows Update Stack elevation of privilege) and CVE-2026-85880 (Windows Advanced Local Procedure Call / ALPC elevation of privilege). Both can let an attacker raise privileges on a Windows system.
Fully 113 of the bugs addressed earned Microsoft's "critical" rating. Among the more serious is CVE-2026-69730, a DNS weakness present in Windows Server 2012 onward and on Windows 10. Microsoft warns an unauthenticated attacker could exploit it by sending a specially crafted packet, and says the flaw is likely to be exploited.
Also notable is CVE-2026-69829, a critical remote code execution flaw in the Windows Shell. It carries a CVSS base score of 9.8, and Microsoft says it can be exploited with low attack complexity, no privileges, and no user interaction.
September's Patch Tuesday brings this year's Microsoft total to more than 2,600 vulnerabilities — more than twice the company's previous record-setting patch year in 2020, which closed at 1,245 — with three months still remaining. Microsoft is not alone: Adobe, Cisco, Google, Mozilla, and Oracle have all recently credited AI-assisted research with increasing patch cadence and volume. Google said on 8 September that it will now ship security updates every two weeks.
Unknown
Microsoft has not said how many of this month's ~974 fixes came from AI-assisted discovery, nor published a clear breakdown of which flaws affect which supported product lines in a typical estate. Its claim that CVE-2026-69730 is "likely to be exploited" is an assessment, not a confirmed campaign.
There is also no independent tally of how many of the 974 vulnerabilities are reachable and exploitable in a typical enterprise environment. That distinction matters more than the headline count, and it is the part of the story nobody has measured publicly.
Our take
The interesting shift is not the record number but who absorbs the cost. AI has compressed the discovery side of the pipeline into something that scales cheaply; testing, compatibility checks, and after-hours deployment windows have not. Satnam Narang of Tenable put the practical point cleanly: larger haystacks do not automatically mean more needles that matter for a given network. Until reachability data for a typical estate is public, the 974 figure will keep driving anxiety faster than it drives better prioritization.