The September 2026 Patch Tuesday represents an unprecedented surge in vulnerability fixes, with roughly 112 of the flaws rated as critical severity. Microsoft's release coincides with a broader industry trend: only two months ago the company patched 570 vulnerabilities, and last month it fixed 620. Google and other firms have also reported record numbers in recent months.
Two weeks ago, OpenAI, Anthropic, Amazon Web Services, Google, Microsoft, and more than 100 organisations published an open letter warning that the window for patching vulnerabilities is narrowing ahead of an expected wave of AI-enabled attacks that will actively exploit them first. The industry is responding by accelerating patch cycles.
“This is the new normal,” said Dustin Childs, a researcher at the Zero Day Initiative, in comments to Ars Technica. Childs cautioned that despite the record volume of fixes, substantial damage from AI-assisted attacks may still be coming.
For Windows 10 users enrolled in the Extended Security Update (ESU) program or running Enterprise LTSC 2021, the KB5122878 update is now available through Windows Update and brings the system to build 19045.7725 or 19044.7725. Microsoft is no longer releasing new features for Windows 10, so the update is focused on security fixes and bug patches.
Notable fixes in KB5122878 include updates to Secure Boot certificate deployment, adjustment of Morocco Standard Time to permanent UTC+00:00 as of September 20, 2026, improved logging in the OMA DM protocol component, better application compatibility during Windows certificate authority rotation, a Remote Desktop audio redirection issue, and a BitLocker Group Policy known issue concerning required recovery key entry. Microsoft reports no known issues with this update.