TECHNOLOGY · VERIFIED DEVELOPMENT
Microsoft Releases Record‑Breaking Patch Fixing 972 Vulnerabilities
WHY IT MATTERS
The unprecedented volume of patches signals a growing threat landscape, urging organizations to prioritize timely updates to defend against AI‑driven exploitation.
What happened
Microsoft’s September security update set a new record by addressing 972 vulnerabilities, including 112 that were classified as high‑critical. The company’s patch count has climbed steadily, from 570 two months ago to 620 last month, and now tops the previous peak.
The surge mirrors similar releases from Google and other major vendors, all of whom have recently published record numbers of fixes. Two weeks earlier, a coalition of 100 companies—including OpenAI, Anthropic, Amazon Web Services, Google, and Microsoft—issued an open letter warning that the window for patching is narrowing ahead of a projected wave of AI‑enabled attacks that could exploit these weaknesses first.
Researchers at the Zero Day Initiative describe the current spike in patch activity as the “new normal” and caution that AI‑assisted attacks may ultimately cause substantial damage.
DEVELOPING STORY
Story timeline
PRIMARY SOURCES
Why this month's Microsoft patch release is a doozy
Ars Technica · Dan Goodin · Discovery only; Condé Nast copyright terms apply