Microsoft's September patch fixes record ~972 vulnerabilities, including 112 critical and two exploited zero-days
Microsoft released its September patch update fixing approximately 972 vulnerabilities, 112 rated critical, including two zero-days and dozens of other notable CVEs. This is the third consecutive record-breaking monthly release, following 570 patched in July and 620 in August; Microsoft has fixed 2,760 vulnerabilities year-to-date, more than double last year total.
Entities: Microsoft, Zero Day Initiative, Dustin Childs, Google, Mozilla, OpenAI
0 primary
What happened
Microsoft's September Patch Tuesday fixed roughly 972 vulnerabilities, 112 rated critical, including two zero-days that were already being exploited. This is the third record-breaking month in a row, after 570 fixes in July and 620 in August, taking Microsoft's year-to-date total to about 2,760, more than double the same point last year. The figures come from secondary reporting citing Microsoft's own release and a public count by a named Zero Day Initiative researcher, not from primary CVE data or Microsoft's advisory pages directly.
Why it matters
Anyone running Windows, Exchange, SharePoint or SQL Server has real, immediate patching work this month, and the two actively exploited zero-days make timely deployment an operational priority rather than a routine cycle. The sustained month-on-month growth in patch volume is a genuine planning signal for enterprise security and IT teams: patching cadence, testing windows and staffing may need to scale accordingly. Beyond the immediate patch cycle, the broader trend is a useful data point for anyone tracking software supply chain risk, though it does not by itself prove a structural shift in the threat landscape.
What is noise
The framing that AI-assisted vulnerability discovery is driving this specific spike is speculative and unproven in this reporting; no evidence ties the increase to AI tooling rather than growing codebase complexity, better detection, or reporting incentives. The "record month" framing is also doing some work it should not: this is the third consecutive record, so the trend itself is more notable than any single month's number, and coverage leaning on an open industry letter about a "narrowing window before AI-enabled attacks" adds fear-toned speculation without new evidence.
Watch next
- 01Whether Microsoft's October patch count continues the upward trend or reverts toward historical norms (typically 100-150 CVEs per month before 2026)
- 02Confirmed exploitation reports or breach disclosures tied specifically to the two September zero-days in the weeks following release
- 03Any Microsoft or independent security vendor data directly attributing the vulnerability discovery increase to AI-assisted tooling, rather than anecdotal industry commentary
Coverage
1 storyMore capability signals
Full feed →- AI systems outperform expert humans in persuasive communication22 Jun 202681
- WIRED investigation: Flock Safety's AI person-search tools let police run broad description-based surveillance, with weak guardrails against misuse3 Sept 202680
- Google DeepMind launches AlphaGenome Atlas, a free public database of predicted effects for 9 billion possible human genome variants8 Sept 202679
- Hcompany open-sources NeoMME, a from-scratch multimodal-native encoder family, and NeoMME-Retriever for visual document retrieval3 Sept 202679