HeadlinesBriefing favicon HeadlinesBriefing.com

Microsoft patches 972 vulnerabilities in September release

Ars Technica •
×

Microsoft’s September patch release fixes a record roughly 972 vulnerabilities, including 112 rated critical. Microsoft had recently patched 570 vulnerabilities, then some 620 the following month, while Google and other companies have also reported record vulnerability counts.

Two weeks ago, Open AI, Anthropic, Amazon Web Services, Google, Microsoft, and 100 companies and organizations published an open letter warning that the window for patching vulnerabilities is narrowing ahead of an expected wave of AI-enabled attacks that exploit them first.

Dustin Childs, a researcher at the Zero Day Initiative, calls the spike the “new normal.” He praised Microsoft’s patching rate but cautioned that AI-assisted vulnerability discovery shows no signs of slowing and that substantial damage from AI-assisted attacks could still result.

The exact count is not precise because some bugs were previously addressed or affected non-Microsoft products. Childs counted 997 fixes when including Chromium ported to Edge. Microsoft has already fixed 2,760 vulnerabilities this year, more than double last year’s total, and could surpass all of 2023, 2024, and 2025 combined.