Skip to content
TECH CEO Daily

Microsoft Patch Tuesday sets 974-flaw record as researchers cite AI-assisted bug hunting

September's release came close to Microsoft's entire 2025 total. Researchers credit AI-assisted bug hunting, and say the job now is choosing which fixes matter first.

By · Editor

· 3 min read · Fact-checked

The 60-second brief

  • 1Microsoft fixed 974 vulnerabilities on September 8, its largest Patch Tuesday, including two Windows zero-days already exploited.
  • 2Researchers tie the surge to AI-assisted vulnerability discovery; Tenable, as cited by The Register, put Microsoft's 2025 total at 1,130 CVEs.
  • 3Security teams should triage by active exploitation and exposure, and prepare budgets for sustained higher patch volumes.

The news

Microsoft (MSFT) released fixes for a record 974 vulnerabilities on its September 8 Patch Tuesday, including two Windows zero-days already under attack, SecurityWeek reported. The Microsoft Patch Tuesday total approaches the 1,130 CVEs Microsoft issued in all of 2025, according to Tenable figures cited by The Register.

The two exploited flaws both let an attacker who already has a foothold gain SYSTEM, the highest Windows privilege. CVE-2026-85880 is a heap buffer overflow in Windows Advanced Local Procedure Call that can be used to escape a sandbox, and CVE-2026-81963 is a link-following flaw in the Windows Update Stack. The Hacker News reported that Volexity and Proofpoint reported the first, and a researcher at Airbus Helicopters and Microsoft's threat intelligence center reported the second. CISA added both to its exploited-vulnerabilities catalog on September 8 with a September 22 deadline for federal agencies.

Windows accounted for 723 of the fixes and SQL Server for 62, according to SecurityWeek. Malwarebytes counted 964 flaws that require customer action, excluding cloud issues Microsoft fixed itself, with 104 rated critical. SecurityWeek said Dustin Childs of the Zero Day Initiative (ZDI) highlighted 20 potentially wormable bugs, meaning they could spread between machines without user interaction. Security Affairs reported they sit in components such as DNS Server, Active Directory and Netlogon.

The jump is recent. The Register reported that Microsoft fixed 622 flaws in July and 421 in August. Researchers point to AI-assisted vulnerability discovery. AI-assisted discovery is “creating larger haystacks, but it isn't finding more needles,” Satnam Narang of Tenable said, according to SecurityWeek. He said organizations should prioritize the flaws that actually apply to them and are reachable and exploitable.

Microsoft was not alone on September 8. CISA also added an exploited Adobe Commerce and Magento template-engine flaw and an N-able N-central flaw to its catalog that day, and The Register reported the Adobe bug had been exploited since September 4.

The numbers

CVEs fixed September 8
974
Microsoft CVEs in all of 2025 (Tenable, via The Register)
1,130
Exploited zero-days
2
Potentially wormable flaws
20
July / August totals (The Register)
622 / 421

Why CEOs should care

For CISOs, the headline count is the wrong metric. Rank fixes by three filters in order: flaws with confirmed exploitation, such as the two Windows zero-days and anything on CISA's catalog; flaws in internet-facing or identity infrastructure, such as DNS, Remote Desktop, Exchange and Active Directory; and the wormable bugs that could spread internally. Childs singled out an Exchange Server flaw, CVE-2026-55007, and advised scheduling downtime to update quickly. Security Affairs counted 58 flaws Microsoft rated more likely to be exploited, a useful second tier. Everything else can follow normal cycles, provided those cycles are measured and reported.

For CFOs, higher volume is a cost that does not go away. If AI keeps accelerating discovery, testing and deploying patches will consume more staff time and maintenance windows. Budget for automation in patch testing and deployment, and ask whether the IT team measures time-to-patch for critical systems or just the percentage of patches applied.

For boards, ask for a simple dashboard: how many actively exploited flaws are open on company systems, how old the oldest one is, and which business owners have accepted risk on unpatched systems. That turns a record-breaking number into a governance question with names attached.

The bigger picture

The Hacker News, citing the Zero Day Initiative, reported Microsoft has patched 2,760 vulnerabilities in 2026 through the September release. If discovery keeps outpacing exploitation, defenders gain time, but only if they can separate the dangerous few from the noise quickly. Vendors that publish clear exploitability ratings and exposure guidance will make that easier; those that do not will push more triage work onto customers.

Volume is also concentrated where businesses feel it most. Windows alone accounted for 723 of September's fixes, touching every desktop and many servers. Companies that freeze changes over year-end trading or reporting periods should decide in advance which categories of fix are exempt, rather than debating exceptions after an exploit appears.

What’s next

Watch the October 13 Patch Tuesday for whether volumes stay near this level, and for exploitation of any of the 20 wormable flaws. Also watch whether Microsoft changes how it groups or rates fixes to help customers cope with larger releases, and whether other large vendors report similar jumps as they apply AI tools to their own code.

What “Fact-checked” means

Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.

What we checked
Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
How
A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
Who
The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, . A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
If something is wrong
“Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error

How we fact-check →

Companies in this story

MicrosoftPatch managementAIVulnerabilities

Earlier coverage of Microsoft

All Microsoft coverage →

Written by

Editor · Technology & Business Writer

Hussein is a writer and business technology enthusiast focused on the intersection of technology, entrepreneurship, finance, artificial intelligence, and digital innovation.

CoversAICybersecurityBig TechSaaSStartupsFintech

About this story. Researched from primary sources whenever they are available and fact-checked before publication.

Published by Tech CEO Daily, an independent publication. Masthead · Editorial standards

Follow Tech CEO Daily on Facebook for the day’s top stories in your feed.

Free newsletters

The technology briefing for people running businesses.

Daily, weekly, bi-weekly or monthly. You choose.

How often

The Daily Brief · Monday to Saturday, 7 a.m. ET

Free forever. One click to unsubscribe. We never sell your email.