The September 2026 Patch Tuesday has set a new security record for Microsoft, addressing between 972 and 995 vulnerabilities depending on the counting method. This surge follows a trend of increasing patch volumes seen throughout the year, with Microsoft already fixing 2,760 flaws in 2026—more than double the total from last year. This acceleration is widely viewed as a response to the rising threat of AI-enabled vulnerability discovery, which industry experts warn is narrowing the window for patching before exploits emerge.
Critical vulnerabilities and zero-days
The update addresses 112 to 121 critical-severity flaws, including two zero-days that were already being exploited in the wild. These are tracked as CVE-2026-81963 in the Windows Update Stack and CVE-2026-85880 in the Windows Advanced Local Procedure Call (ALPC). Both are elevation-of-privilege vulnerabilities, and Microsoft has confirmed that no practical workarounds exist, making the update the only viable defense.
Interface flexibility and security hardening
Beyond security, the update (delivered via KB5124008 and KB512280) restores the highly requested ability to move the taskbar, a feature previously limited to experimental builds and briefly introduced in KB5120998.
The release also introduces Administrator Protection, a security layer that uses just-in-time elevation and profile separation to secure administrative privileges. Other technical additions include process isolation for Microsoft Execution Containers, agentic process tagging, and standalone ML-KEM support for post-quantum TLS. Conversely, the update marks a cleanup phase: WMIC is now removed from Windows 11 versions 24H2 and 25H2, though WMI remains supported.
The AI-driven security race
The unprecedented volume of patches reflects a broader industry shift. A recent open letter signed by OpenAI, Anthropic, and Google warned of an impending "tsunami" of AI-assisted attacks. While researchers from the Zero Day Initiative note that there hasn't been a correlating spike in active exploits yet, they describe this high frequency of patching as the "new normal" to counter AI's ability to find bugs faster than human developers can manually audit code.

No comments yet. Be the first!