← All stories
● Covered by 3 sources · 3 reportsMedium impact3 neutral

Microsoft sets new Patch Tuesday record with over 650 security fixes for Windows

🔄 Updated 3h ago — new reporting from The Hacker News
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • September Patch Tuesday included over 650 Windows security fixes.
  • This is Microsoft's third record-breaking Patch Tuesday in recent months.
  • New AI models are accelerating vulnerability discovery.
  • The volume of patches creates pressure for IT administrators.
  • September Patch Tuesday addressed 972 vulnerabilities.
  • 112 vulnerabilities were rated as critical severity.
  • Microsoft patched 570 vulnerabilities two months ago.
  • Microsoft patched 620 vulnerabilities last month.
  • Dustin Childs of Zero Day Initiative calls the spikes the ‘new normal’.
  • Microsoft patched 974 vulnerabilities.
  • Two actively exploited zero-day flaws in Windows were patched.
  • 723 flaws were in Windows.
  • 111 flaws were in Office and Office 2016.
  • 62 flaws were in SQL.
  • 22 flaws were in Developer Tools.
  • Over 110 shortcomings were critical severity.
  • Privilege escalation, remote code execution, and information disclosure account for nearly 90% of flaws.
  • Microsoft fixed 25 non-Microsoft CVEs, bringing the total to 999.
  • Microsoft patched 457 vulnerabilities in August.
  • Microsoft patched 663 vulnerabilities in July.
  • Microsoft patched 220 vulnerabilities in June.
  • Microsoft patched 161 vulnerabilities in May.

Record-Breaking Patch Tuesday

Microsoft's September Patch Tuesday included over 650 security fixes for Windows, establishing a new record for the company. This follows previous record-setting months in June and July, where Microsoft patched around 200 and 570 vulnerabilities respectively, and nearly 400 in August.

Impact of AI Models on Vulnerability Discovery

The surge in discovered vulnerabilities is linked to the emergence of new AI models designed for cybersecurity. Anthropic's Mythos model, released in April, identified security flaws across major operating systems and web browsers. OpenAI also released a cybersecurity-focused model to partners, both of which have contributed to the increased rate of vulnerability detection.

Industry Implications

Microsoft is actively using security-focused AI models to find software vulnerabilities, leading to a continuous increase in the number of flaws requiring patches. This proactive approach aims to address weaknesses in Windows, Azure, and other software before malicious actors can exploit them using advanced AI techniques. The high volume of fixes also places pressure on businesses to promptly apply these patches.

Updates

🕒 2026-09-09 · new reporting from The Hacker News
  • Microsoft patched 974 vulnerabilities.
  • Two actively exploited zero-day flaws in Windows were patched.
  • 723 flaws were in Windows.
  • 111 flaws were in Office and Office 2016.
  • 62 flaws were in SQL.
  • 22 flaws were in Developer Tools.
  • Over 110 shortcomings were critical severity.
  • Privilege escalation, remote code execution, and information disclosure account for nearly 90% of flaws.
  • Microsoft fixed 25 non-Microsoft CVEs, bringing the total to 999.
  • Microsoft patched 457 vulnerabilities in August.
  • Microsoft patched 663 vulnerabilities in July.
  • Microsoft patched 220 vulnerabilities in June.
  • Microsoft patched 161 vulnerabilities in May.
🕒 2026-09-09 · new reporting from Ars Technica
  • September Patch Tuesday addressed 972 vulnerabilities.
  • 112 vulnerabilities were rated as critical severity.
  • Microsoft patched 570 vulnerabilities two months ago.
  • Microsoft patched 620 vulnerabilities last month.
  • Dustin Childs of Zero Day Initiative calls the spikes the ‘new normal’.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~8 min · 6 stories · Sep 08

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

Microsoft released a record-setting Patch Tuesday update, addressing 974 vulnerabilities across its software portfolio, including two actively exploited zero-day flaws in Windows. This large volume of patches requires IT and security teams to prioritize immediate actions for critical vulnerabilities, especially the exploited ones.

Microsoft released a record-setting September patch addressing 972 vulnerabilities, with 112 rated as critical severity. This release reflects an industry-wide increase in patches, driven by concerns over AI-assisted vulnerability discovery and potential future exploits.

Microsoft released over 650 security fixes for Windows in its September Patch Tuesday, setting a new record. This increase in patched vulnerabilities is attributed to new AI models, like Anthropic's Mythos and OpenAI's cybersecurity model, which are discovering software flaws at a rapid pace.