Microsoft Patches Record 974 Security Flaws in Largest Windows Update Ever
- Microsoft released updates to fix at least 974 security vulnerabilities across its Windows operating systems and other software, marking the largest single patch batch in the company's history.
- This month’s massive bundle far exceeds the previous record set in July, when Microsoft issued updates for at least 570 security flaws.
- Major technology firms including Adobe, Cisco, Google, Mozilla, and Oracle have recently credited AI-assisted research with increasing both their patch volume and release frequency, with Google announcing plans...
Microsoft released updates to fix at least 974 security vulnerabilities across its Windows operating systems and other software, marking the largest single patch batch in the company’s history. According to the software giant, artificial intelligence is helping accelerate the discovery of these security holes, but security experts warn that organizations face growing strain in testing and deploying such a massive volume of fixes each month.
Record-Breaking Volume and Zero-Day Flaws
This month’s massive bundle far exceeds the previous record set in July, when Microsoft issued updates for at least 570 security flaws. September’s Patch Tuesday pushes the total number of vulnerabilities addressed this year past 2,600, more than doubling the previous annual record of 1,245 set in 2020 with three months still remaining in the year.
Among the fixes are two zero-day vulnerabilities currently under active exploitation in the wild, designated as CVE-2026-81963 and CVE-2026-85880. Both flaws permit an attacker to elevate their privileges on a target Windows system. Overall, 113 of the addressed bugs carry Microsoft’s critical rating, indicating they can be leveraged by malware or malicious actors to seize control of a vulnerable machine with minimal or no user interaction.
Critical issues in this month’s release include CVE-2026-69730, a DNS weakness affecting Windows Server 2012 onward and Windows 10. Microsoft cautioned that an unauthenticated attacker could exploit this flaw simply by sending a specially crafted packet to an affected system, and noted that exploitation is likely. Another severe vulnerability, CVE-2026-69829, is a remote code execution flaw in the Windows Shell carrying a CVSS base score of 9.8 out of 10. This bug requires low attack complexity, no privileges, and no user interaction to exploit.
Industry-Wide Patch Cadence and Enterprise Strain
Microsoft is not alone in pushing larger software updates. Major technology firms including Adobe, Cisco, Google, Mozilla, and Oracle have recently credited AI-assisted research with increasing both their patch volume and release frequency, with Google announcing plans to ship security updates every two weeks.
Tyler Reguly, associate director of security research and development at Fortra, pointed out that the primary hurdle for IT departments lies in thoroughly testing updates before rolling them out across an enterprise environment, as third-party applications can fail when underlying operating systems change.
It’s time to put our CISOs and CSOs on notice. How are you helping your teams through these difficult times? Are your teams instructed to deploy updates during off-hours and weekends so that normal business operations remain uninterrupted? Do you reward them for that effort? Budgeting funds to feed your staff who come in on Saturday to push out patches ahead of the user base returning on Monday is a necessary step.
Tyler Reguly, Fortra
While the sheer volume of patches is climbing, Satnam Narang, senior staff research engineer at Tenable, observed that the actual number of vulnerabilities impacting most organizations remains relatively small.
AI-assisted vulnerability discovery in 2026 is creating larger haystacks, but it isn’t finding more needles. Enterprises must pinpoint which specific flaws genuinely affect their operations, assess whether those weaknesses are reachable and actively exploitable, and then structure their fix strategy around that specific risk environment.
Satnam Narang, Tenable

Remediation Guidance for Administrators
While consumer Windows users simply need to pull updates through Windows Update or respond to pending notifications, enterprise administrators face a more complex testing cycle. Enterprise Windows admins are encouraged to monitor tracking resources like askwoody.com for reports of problematic updates, while consulting the SANS Internet Storm Center for structured breakdowns ordered by severity and urgency before beginning broad deployments.

