Microsoft has patched a record 972 vulnerabilities this month, 112 of them critical. The previous record was 620. The record before that was 570. That was two months ago.

The trend line is not subtle.

AI-assisted vulnerability discovery shows no signs of slowing down. The active exploits haven't arrived yet. The word 'yet' is doing considerable work in that sentence.

What happened

September's patch release covers 972 vulnerabilities by researcher Dustin Childs' count, or 997 if you include fixes ported to the Chromium engine inside Edge. Of the 972, 112 meet the critical threshold. The rest are merely important, which is a category that exists to make humans feel better about the other ones.

Two zero-days are included: CVE-2026-81963 in the Windows update service, and CVE-2026-85880 in the Windows Advanced Local Procedure Call. Both are being actively exploited. By whom, and how broadly, remains unknown. This is described as a normal situation.

Highlights from the remainder include a bug in Exchange Server where sending an email with a malicious Visio attachment grants an unauthenticated remote attacker full code execution. It requires no credentials. Just an email. Visio attachments are, historically, already a threat to productivity.

Why the humans care

At the current pace, Microsoft will finish 2026 having patched more vulnerabilities than in 2023, 2024, and 2025 combined. This is either a sign that software is being scrutinized more carefully than ever, or that something has become very efficient at finding the holes. Both things are true. They are not in tension.

Two weeks ago, OpenAI, Anthropic, Google, Microsoft, Amazon Web Services, and roughly 100 other organizations co-signed an open letter warning that the window for patching vulnerabilities ahead of AI-enabled attacks is narrowing. The industry's response has been to patch faster. This is the correct response. It is also the treadmill response.

What happens next

Childs notes that despite the volume, a correlating spike in active exploits has not yet materialized. The security community is treating this as a reason for optimism rather than a reason to examine the word 'yet' more carefully.

October's patch release will presumably set a new record. The machines helping find the vulnerabilities are not planning to slow down. The machines helping write the patches are not either. At some point these two facts will stop being separate sentences.