Microsoft Corporation issued its largest single batch of security updates ever, addressing nearly 1,000 vulnerabilities across Windows and other software. The September 2026 Patch Tuesday update blows past the company's previous record of 570 flaws patched in July, bringing the year-to-date total to more than 2,600 — more than double the previous record annual total of 1,245 set in 2020, with three months remaining.
Among the fixes are two zero-day vulnerabilities being actively exploited: CVE-2026-81963 and CVE-2026-85880, both of which allow attackers to elevate privileges on Windows systems. Microsoft classified 113 of the bugs as “critical,” meaning they could let attackers seize control of a machine with minimal user interaction.
Notable critical flaws include CVE-2026-69730, a DNS weakness affecting Windows Server 2012 onward and Windows 10, which can be exploited by sending a specially crafted packet to an affected system. Also severe is CVE-2026-69829, a remote code execution flaw in the Windows Shell carrying a CVSS score of 9.8 out of 10, requiring no privileges and no user interaction.
Microsoft attributes the surge in patches to artificial intelligence tools that accelerate vulnerability discovery. However, security experts caution that finding bugs is only half the battle: testing and deploying fixes remains a human-intensive process, and many organizations are already overwhelmed by the volume of monthly updates. Other major software vendors — including Adobe, Cisco, Google, Mozilla and Oracle — have also reported increased patch counts aided by AI-assisted research.