Microsoft just patched 979 software flaws. AI attacks are why that number keeps climbing.

September's security update from Microsoft is the largest on record. Researchers say the surge reflects a race against AI tools that can find and weaponise software weaknesses faster than ever.

AI2Day Newsdesk3 min read
A large, modern data center with rows of servers, blue and green LED indicators, and a focus on security measures
Share

Key points

  • Microsoft fixed roughly 979 security vulnerabilities (flaws in software that attackers can exploit) in its September 2025 patch release, a new all-time record.
  • 112 of those flaws reached the "critical" severity threshold, meaning attackers could use them to take control of a device or steal data with little effort from the victim.
  • Just two months earlier, Microsoft's then-record patch had covered 570 vulnerabilities.
  • OpenAI, Anthropic, Google, Amazon Web Services, Microsoft and around 100 other organisations co-signed an open letter warning that AI tools will soon let attackers find and exploit flaws before companies can fix them.
  • Security researcher Dustin Childs at the Zero Day Initiative describes the rising patch counts as "the new normal."

What actually happened this month?

Microsoft's September security update, released as part of the company's regular monthly "Patch Tuesday" cycle, fixed roughly 979 separate vulnerabilities. That beats the previous record, set just two months ago in July, of 570 fixes.

Of this month's flaws, 112 were rated critical. A critical vulnerability is one that an attacker can exploit remotely, often without the victim doing anything beyond having the software installed.

The scale is striking. For context, a patch of 100 vulnerabilities used to be considered a heavy month.

Why is the number so high?

The short answer: AI tools are getting very good at hunting for software flaws, and everyone, defenders and attackers alike, is using them.

Security teams at Microsoft and elsewhere now use AI to scan their own code, which surfaces far more weaknesses than manual review ever could. That is good. Fixing more flaws is better than leaving them hidden. But the same AI capabilities are available to attackers, who can use them to find flaws that companies have not yet discovered or disclosed.

Two weeks before Microsoft's release, as first reported by Ars Technica, OpenAI, Anthropic, Google, Amazon Web Services, Microsoft and roughly 100 other companies and organisations signed an open letter. The letter warned of a "narrowing window" for patching: AI is expected to start actively exploiting vulnerabilities faster than the industry can push out fixes.

Google has also reported record-breaking patch numbers in recent months, which suggests this is an industry-wide shift rather than a Microsoft-specific issue.

Should ordinary users be worried?

Yes, but the action is simple. Install the update.

If you use a Windows PC, go to Settings, then Windows Update, and check that September's patches have been applied. Most home users have automatic updates turned on and may not need to do anything.

Dustin Childs, a vulnerability researcher at the Zero Day Initiative (a programme that tracks and discloses security flaws), says these record counts are "the new normal" and warns that the damage from AI-assisted attacks "could eventually be substantial." He is not predicting immediate catastrophe, but the direction is clear.

What happens next?

Patch counts will almost certainly keep rising. The industry is effectively in a race: find and fix flaws before attackers find and exploit them. AI accelerates both sides.

For home users, the advice does not change. Update promptly, enable automatic updates, and be cautious about unsolicited emails or links. Businesses running large networks of Windows devices should treat Patch Tuesday as a priority deadline, not a suggestion.

Common questions

Do I need to do anything right now?

If you use Windows, open Settings and check Windows Update to confirm September's patches are installed. Automatic updates handle this for most home users, but it is worth verifying.

Is Microsoft's software less secure than competitors'?

Not necessarily. The high patch count reflects aggressive internal scanning, partly AI-assisted, which surfaces more flaws. Finding and fixing a flaw is safer than leaving it undiscovered.

© 2026 AI2Day