In one of the most expansive security updates in corporate history, Microsoft has released its September 2026 Patch, fixing roughly 972 software vulnerabilities across its ecosystem. Among the resolved flaws, 112 carry the highest critical-severity classification. Just two months earlier, Microsoft addressed a then-unprecedented 570 flaws, followed by 620 fixes in August.
The update marks an acceleration in software remediation.
Why latest Windows update is significant
Childs tallied 972 direct Microsoft vulnerabilities in the latest update, rising to 997 when factoring in ported Chromium browser patches for Microsoft Edge. Microsoft has resolved 2,760 security flaws so far in 2026, more than twice the total recorded at this stage last year. At current release speeds, the tech giant will resolve more security bugs in 2026 than it did across 2023, 2024 and 2025 combined, the report added. The September release resolves two zero-day vulnerabilities: CVE-2026-81963 within the core Windows Update service and CVE-2026-85880 inside the Windows Advanced Local Procedure Call. The surge comes weeks after the heels of a joint open letter published two weeks ago by OpenAI, Microsoft, Google, Anthropic, Amazon Web Services and nearly 100 industry organisations.
Dustin Childs, a cybersecurity researcher with the Zero Day Initiative, described the flood of monthly security disclosures as the industry’s inevitable “new normal”, according to Bleeping Computer. Childs noted that so many of the disclosed flaws exhibited “wormable” properties, requiring zero user interaction and capable of jumping automatically across network-connected hardware. Public details regarding active exploitation campaigns or specific targets have not been disclosed. The coalition warned that the window to patch software weaknesses before bad actors launch automated, AI-driven cyber campaigns is rapidly shrinking, driving tech companies to issue patches at unprecedented volumes.

