Why this month’s Microsoft patch release is a doozy





LLM-DRIVEN BUG DISCOVERY

Why this month’s Microsoft patch release is a doozy

Security gnomes are pumping out patches ahead of an expected onslaught of AI-assisted attacks.


Dan Goodin




|

27





Credit:

Getty Images


Credit:

Getty Images




Story text








Microsoft’s patch for September is a doozy, with a record number of roughly 972 vulnerabilities fixed and 112 of them meeting the high critical-severity threshold.

It was only two months ago that Microsoft patched a then-record 570 vulnerabilities. Then, last month, Microsoft patched some 620 of them. Google and other companies have also published record numbers of vulnerabilities in recent months. Two weeks ago, OpenAI, Anthropic, Amazon Web Services, Google, Microsoft, and 100 companies and organizations published an open letter warning of a narrowing window for patching vulnerabilities ahead of an expected tsunami of AI-enabled attacks that actively exploit them first. The industry is taking the threat seriously by pumping out unprecedented numbers of patches in their software.

Welcome to the new normal

Dustin Childs, a researcher at the Zero Day Initiative, calls the spikes the “new normal” and also cautions that despite them, the damage that’s likely to result from AI-assisted attacks could eventually be substantial.

“On the one hand, congrats to the security gnomes at Microsoft for being able to patch bugs at this rate,” Childs wrote Tuesday. “On the other hand, AI-assisted vulnerability discovery shows no signs of slowing down. However, we have not seen a correlating spike in active exploits—yet.”

Counting the precise number of vulnerabilities fixed in a monthly patch release for Microsoft is never an exact science. In some cases, the bugs were previously addressed or affected non-Microsoft products. By Childs’s count, Tuesday’s release patches 972 vulnerabilities, and 997 when counting the porting of fixes for the Chromium browser incorporated into Edge. Of the new vulnerabilities, 112 of them are rated critical, with the remainder carrying the important designation. Already this year, Microsoft has fixed 2,760 vulnerabilities, more than double the number from last year. At this rate, Microsoft will complete the year having fixed more bugs than all of 2023, 2024, and 2025 combined.




Credit:

Microsoft

Notable vulnerabilities in this month’s release include two zero-days, CVE-2026-81963 and CVE-2026-85880 in the Windows update service and the Windows Advanced Local Procedure, respectively. There’s no public information about who is exploiting them or how broadly. Other notable vulnerabilities Childs called out are:

  • CVE-2026-55007 in Exchange Server. A remote, unauthenticated attacker could get code execution on an affected Exchange server by doing nothing more than sending an email with a malicious Visio attachment.
  • CVE-2026-80097: A local privilege escalation in Microsoft Authenticator. “This is the worst type of privilege escalation as it uses a bug in the authentication system itself,” Childs said.
  • CVE-2026-69465: Roughly 17 distinct vulnerabilities in Microsoft Office SharePoint allowing remote code execution.
  • CVE-2026-65669: One of 60 SQL Server privilege escalation vulnerabilities this month. This particular one is exploited when a user submits instructions through SQL Copilot.
  • CVE-2026-69525: A remote code execution flaw in Remote Desktop Services with a 9.8 severity rating.

The researcher said he found so many of Tuesday’s vulnerabilities that were wormable that he stopped counting at 20. These vulnerabilities don’t require any user interaction to be exploited and hence can spread from machine to machine on their own, triggering a possible chain reaction that’s difficult to stop.

The effectiveness of AI-assisted vulnerability hunting is filled with controversy. Critics question the expense and number of false positives when using LLMs. They also question the motives of companies trying to recoup the billions of dollars they’re pouring into developing the very AI engines being used to find and patch the flaws.

The counterargument is that the results—AI-assisted hunting finding record numbers of severe bugs across the industry—speak for themselves. Mozilla, for instance, said in May that its researchers using Mythos found a record 271 vulnerabilities, with almost none of them being false positives.

The true, long-term effectiveness of AI-assisted bug hunting won’t be known for a time that will likely be measured in a year or more. What’s clear now is that critics should maintain curiosity and remain open to the possibility that vulnerability discovery has entered a new and unprecedented phase. Skeptics who discount the possibility do so at their own peril.

Photo of Dan Goodin


Dan Goodin

Senior Security Editor
Dan Goodin is Senior Security Editor at Ars Technica, where he oversees coverage of malware, computer espionage, botnets, hardware hacking, encryption, and passwords. In his spare time, he enjoys gardening, cooking, and following the independent music scene. Dan is based in San Francisco. Follow him at here on Mastodon and here on Bluesky. Contact him on Signal at DanArs.82.


27 Comments

Leer artículo original en Ars Technica