Microsoft's September 2026 security update patched more than 950 vulnerabilities, bringing the company's total for the year to roughly 2,750, more than double its previous annual record of about 1,250 set in 2020. The numbers reflect a broader trend across the software industry, where AI-assisted security research is uncovering flaws faster than organizations can deploy fixes.

Two zero-days actively exploited in the wild

Among the fixes are two zero-day vulnerabilities that attackers are already using. CVE-2026-81963 and CVE-2026-85880 both allow an attacker to elevate privileges on Windows systems, a critical capability that lets malware or intruders gain administrative control after initial access. CVE-2026-85880 was discovered by researchers at Volexity and Proofpoint. CVE-2026-81963 was independently reported by researchers at Airbus Helicopters and the Microsoft Threat Intelligence Center.

The September update also classified 113 vulnerabilities as critical, meaning they can be exploited with little or no user interaction. BleepingComputer cataloged the full scope: 258 remote code execution flaws, 438 elevation of privilege vulnerabilities, and hundreds of others across various categories.

AI is finding bugs faster than teams can patch them

Security journalist Brian Krebs noted that Microsoft is not alone in shipping massive patch bundles. Many major software companies attribute the growing volume of discoveries to AI tools that can analyze code at scale, identify vulnerability patterns, and generate proof-of-concept exploits far faster than human researchers working alone. The result is an unprecedented flow of disclosed flaws heading toward organizations that must evaluate, prioritize, and deploy each fix.

Krebs highlighted two distinct risks in this dynamic. First, the sheer volume of patches creates triage challenges that most security teams are not staffed to handle. Second, AI does not just help defenders find weaknesses. The same tools help attackers discover and weaponize vulnerabilities, compressing the window between disclosure and exploitation.

The concern is not hypothetical. OpenAI, Anthropic, AWS, Google, Microsoft, and other companies recently published an open warning that AI-enabled cyber attacks will become far more widespread and sophisticated in the near future. The industry is simultaneously building the tools that accelerate both sides of the security equation.

The patch deployment bottleneck

The discovery problem is only part of the story. Organizations must still understand their exposure, test each patch, determine what else it might break, and deploy it across potentially thousands of devices and interconnected systems. At the scale Microsoft is now producing, that process becomes a business problem, not just a technical one.

Jack Bicer, Director of Vulnerability Research at Action1, pointed out that the challenge at this volume is not getting through the patch list. It is knowing what needs attention first. With hundreds of updates landing simultaneously, IT and security teams must separate the vulnerabilities that demand immediate action from those that can follow a normal deployment cycle.

Marva Bailer, founding CEO at Qualaix, pushed the point further. Finding the vulnerability is one step. Understanding how it affects your specific environment, testing that the patch does not introduce new problems, and rolling it out across a complex infrastructure is where a software patch becomes an operational crisis. She warned that AI, while helping defenders find weaknesses sooner, also puts greater pressure on the time between discovery, testing, and deployment.

What the numbers actually mean

Tyler Reguly, security R&D associate director at Fortra, offered a blunt assessment. As long as Microsoft is playing catch-up on patching vulnerabilities, the numbers have lost all meaning. The important question is not how many flaws exist but how organizations handle the reality of patch volumes that will likely continue growing.

The September update makes clear that the security industry has entered a new phase. AI tools have fundamentally changed the economics of vulnerability discovery, making it cheaper and faster to find flaws at scale. The bottleneck has shifted downstream, to the teams that must decide which of hundreds of patches to deploy first, test them against production systems, and push them out before attackers exploit the gaps. That workflow, not the discovery itself, is now the hard problem in software security.