Microsoft has released its September patch, addressing a record 972 vulnerabilities, with 112 classified as critical. This marks a significant increase from previous months, where the company patched 570 vulnerabilities two months ago and 620 last month. The surge in vulnerabilities is part of a broader trend, as major tech companies, including Google, have also reported record numbers of vulnerabilities recently. An open letter from OpenAI, Anthropic, Amazon Web Services, Google, Microsoft, and over 100 other organizations highlighted the urgent need for patching vulnerabilities in light of anticipated AI-enabled attacks that could exploit these weaknesses.
Industry Response to Rising Threats
Dustin Childs, a researcher at the Zero Day Initiative, described the current situation as the “new normal,” emphasizing that while the number of patches is impressive, the potential damage from AI-assisted attacks remains a serious concern. He noted, “On the one hand, congrats to the security gnomes at Microsoft for being able to patch bugs at this rate. On the other hand, AI-assisted vulnerability discovery shows no signs of slowing down.” Despite the increase in vulnerabilities, there has not yet been a corresponding rise in active exploits.
Counting vulnerabilities in Microsoft’s monthly patches can be complex, as some issues may have been previously addressed or pertain to non-Microsoft products. This month’s release includes 972 vulnerabilities, or 997 if counting fixes for the Chromium browser in Edge. So far this year, Microsoft has resolved 2,760 vulnerabilities, more than double the total from last year. At this pace, the company is on track to fix more vulnerabilities in 2026 than in the combined total of 2023, 2024, and 2025.
For more details, visit Ars Technica.
Follow Cyber Warriors Middle East for further global cybersecurity developments.



