Why this month's Microsoft patch release is a doozy
Microsoft’s September security update addresses a record surge in vulnerabilities, with researcher counts putting fixes at about 972 items and 112 rated critical. The release follows two months of unusually high patch volumes and comes amid industry warnings about a narrowing window to fix bugs before AI-assisted attacks accelerate.

Why It Matters
Security teams across major tech firms are accelerating patching because several industry players warned that AI-enabled attacks could rapidly find and exploit vulnerabilities. The scale of this month’s fixes signals how seriously vendors are treating that threat.
Key Facts
- september-patches-count: Approximately 972 vulnerabilities fixed (997 when including Chromium ported fixes for Edge)
- critical-vulnerabilities: 112 of the September fixes are rated critical
- previous-months: Two months ago Microsoft patched ~570 vulnerabilities; last month it patched ~620
- year-to-date-total: Microsoft has fixed 2,760 vulnerabilities so far this year
- industry-open-letter: OpenAI, Anthropic, Amazon Web Services, Google, Microsoft and about 100 other companies and organizations published an open letter warning of a narrowing window to patch before AI-enabled attacks
Microsoft’s September security update is unusually large: researcher tallies put the number of patched issues at roughly 972, and 112 of those are rated critical. Including fixes brought into Microsoft’s Edge browser via the Chromium project raises the total to about 997, underscoring the scale of this month’s release. The September surge follows similarly elevated totals in recent months — roughly 570 vulnerabilities were patched two months ago and about 620 last month — and mirrors record vulnerability counts reported by Google and other vendors. Security teams and industry groups say these spikes are linked to increased automated vulnerability discovery, including tools accelerated by advances in AI. Two weeks ago a coalition of major AI and cloud companies, including OpenAI, Anthropic, Amazon Web Services, Google and Microsoft, joined roughly 100 other organizations in an open letter warning that the window to patch known issues is narrowing as AI-powered attacks become more capable. In response, vendors appear to be accelerating release cadence and the number of fixes pushed to users. Zero Day Initiative researcher Dustin Childs characterized the pattern as a new normal: he praised Microsoft’s ability to ship fixes at this pace but cautioned that AI-assisted discovery of vulnerabilities is continuing and could lead to substantial damage if active exploitation rises. Counting exact patch totals is not always straightforward, since some fixes relate to non-Microsoft products or duplicate earlier work, but the year-to-date count of 2,760 vulnerabilities represents more than double last year’s total. At the current pace, Microsoft is on track to finish the year having remediated more bugs than it did in 2023, 2024 and 2025 combined.
Keep Reading

Apple’s foldable ‘iPhone Duo’ will reportedly start at $2,000

Moonshot’s Kimi rattled markets. U.S. agencies now say it was trained on American models

Update to Google’s AI weather model improves forecast accuracy
