SecurityDeveloping

Microsoft September 2026 Patch Tuesday Breaks Records with Nearly 1,000 Vulnerabilities Fixed

Windows 10 ESU update KB5122878 included as two zero-days under active exploitation

edit
By LineZotpaper
Published
Updated
Read Time2 min
Sources2 outlets
Microsoft released a record-breaking September 2026 Patch Tuesday, fixing approximately 972 vulnerabilities across its product line — including two actively exploited zero-days. The patch haul, which Ars Technica reports as roughly 972 flaws and BleepingComputer puts at 966, dwarfs the previous record of 620 set just last month. The update is bundled with the Windows 10 extended security update KB5122878 for ESU subscribers and enterprise LTSC users.

The September 2026 Patch Tuesday represents an unprecedented surge in vulnerability fixes, with roughly 112 of the flaws rated as critical severity. Microsoft's release coincides with a broader industry trend: only two months ago the company patched 570 vulnerabilities, and last month it fixed 620. Google and other firms have also reported record numbers in recent months.

Two weeks ago, OpenAI, Anthropic, Amazon Web Services, Google, Microsoft, and more than 100 organisations published an open letter warning that the window for patching vulnerabilities is narrowing ahead of an expected wave of AI-enabled attacks that will actively exploit them first. The industry is responding by accelerating patch cycles.

“This is the new normal,” said Dustin Childs, a researcher at the Zero Day Initiative, in comments to Ars Technica. Childs cautioned that despite the record volume of fixes, substantial damage from AI-assisted attacks may still be coming.

For Windows 10 users enrolled in the Extended Security Update (ESU) program or running Enterprise LTSC 2021, the KB5122878 update is now available through Windows Update and brings the system to build 19045.7725 or 19044.7725. Microsoft is no longer releasing new features for Windows 10, so the update is focused on security fixes and bug patches.

Notable fixes in KB5122878 include updates to Secure Boot certificate deployment, adjustment of Morocco Standard Time to permanent UTC+00:00 as of September 20, 2026, improved logging in the OMA DM protocol component, better application compatibility during Windows certificate authority rotation, a Remote Desktop audio redirection issue, and a BitLocker Group Policy known issue concerning required recovery key entry. Microsoft reports no known issues with this update.

§

Analysis

Why This Matters

  • The record patch volume reflects an escalating vulnerability landscape, with attackers expected to increasingly use AI to automate exploitation.
  • Windows 10 users on ESU are relying on these updates for continued security; any gap could leave millions of legacy systems exposed.
  • The industry-wide trend suggests organisations must accelerate their patch management cycles or risk falling behind.

Background

Microsoft's September 2026 Patch Tuesday is part of a broader surge in software patching across the tech industry. In the past three months, Microsoft's monthly vulnerability count has more than doubled, from 570 in July to around 972 now. The open letter from 100+ companies, published two weeks ago, flagged the danger of AI-driven attacks that find and exploit flaws faster than vendors can patch them. Microsoft has also been winding down Windows 10 support, offering paid ESU for enterprise and education customers.

Key Perspectives

[Microsoft]: The company is keeping legacy platforms secure through extended updates and setting records for vulnerability fixes, positioning itself as proactive against emerging threats. [Security Researchers (Dustin Childs/Zero Day Initiative)]: They acknowledge the record patches as a "new normal" but warn that the sheer volume may not be enough; the real danger is from AI-assisted exploitation that outpaces human-driven patching. [Industry Coalitions]: The open letter signatories argue that coordinated disclosure and rapid patching are essential, but also that vendors must build more secure software from the outset to reduce the attack surface.

What to Watch

  • Whether Microsoft's October Patch Tuesday continues the upward trend or shows a plateau.
  • Emergence of real-world AI-assisted exploits that specifically target these recently patched vulnerabilities.
  • Adoption rate of Windows 10 ESU among enterprises, which indicates how many systems remain reliant on these monthly updates.

Sources

newspaper

Zotpaper

Articles published under the Zotpaper byline are synthesized from multiple source publications by our AI editor and reviewed by our editorial process. Each story combines reporting from credible outlets to give readers a balanced, comprehensive view.