AI News Feed
Market watch
Cybersecurity

Microsoft Releases Record September 2026 Patch Tuesday With 974 Fixes, Two Exploited Zero-Days

Microsoft's September 2026 Patch Tuesday fixed 974 vulnerabilities, its largest ever, including two actively exploited zero-days and 114 critical flaws, as AI-assisted discovery pushes CVE counts higher.

The update covered products across Microsoft's stack. Windows accounted for 723 of the vulnerabilities, while Office had 111. Microsoft described CVE-2026-85880 and CVE-2026-81963 as especially important because both were under active exploitation, and it urged customers to install the update.

Dustin Childs, writing in a blog post cited by TechRadar, said the release could mark a "new normal." He counted 2,760 CVEs patched by Microsoft so far in 2026, more than double any prior year. The total was 1,139 in all of 2025 and 492 in 2016, according to his figures.

TechRadar reported that AI-assisted discovery tools likely helped Microsoft find more vulnerabilities that might otherwise have gone undetected. The article also linked AI to both increased CVE discovery and intensifying attacks. The 114 Critical flaws represented more than one in 10 of the September fixes.

Microsoft was not alone in handling more bugs. Childs highlighted high activity from Adobe, and TechRadar reported that several browser developers, including Google, Mozilla, Brave and Microsoft, have moved to a two-week release cycle to deliver fixes faster.

Beyond security flaws, Microsoft used the September update to address known issues, including Teams and Outlook crashes on Arm64 PCs, and to upgrade Copilot+ AI components.