Privilege escalation · Microsoft · Google · OpenAI · Anthropic · Ars Technica
Why this month's Microsoft patch release is a doozy
Compiled by KHAO Editorial — aggregated from 1 source. See llms.txt for citation guidance.
◌ Single Source
Microsoft’s patch for September is a doozy, with a record number of roughly 972 vulnerabilities fixed and 112 of them meeting the high critical-severity threshold.
Key facts
- Notable vulnerabilities in this month’s release include two zero-days, CVE-2026-81963 and CVE-2026-85880 in the Windows update service and the Windows Advanced Local Procedure, respectively
- At this rate, Microsoft will complete the year having fixed more bugs than all of 2023, 2024, and 2025 combined
- By Childs’s count, Tuesday’s release patches 972 vulnerabilities, and 997 when counting the porting of fixes for the Chromium browser incorporated into Edge
- Microsoft’s patch for September is a doozy, with a record number of roughly 972 vulnerabilities fixed and 112 of them meeting the high critical-severity threshold
Summary
It was only two months ago that Microsoft patched a then-record 570 vulnerabilities. Two weeks ago, OpenAI, Anthropic, Amazon Web Services, Google, Microsoft, and 100 companies and organizations published an open letter warning of a narrowing window for patching vulnerabilities ahead of an expected tsunami of AI-enabled attacks that actively exploit them first. Dustin Childs, a researcher at the Zero Day Initiative, calls the spikes the “new normal” and also cautions that despite them, the damage that’s likely to result from AI-assisted attacks could eventually be substantial. “On the one hand, congrats to the security gnomes at Microsoft for being able to patch bugs at this rate,” Childs wrote Tuesday. Counting the precise number of vulnerabilities fixed in a monthly patch release for Microsoft is never an exact science.