MICROSOFT patched 972 vulnerabilities in its September 2026 release, including 112 critical-severity flaws and two zero-days: CVE-2026-81963 in the Windows update service and CVE-2026-85880 in the Windows Advanced Local Procedure Call.
The surge follows an open letter from OpenAI, Anthropic, Amazon Web Services, Google, Microsoft and 100 other companies warning that a narrowing window for patches would precede a rise in AI-enabled attacks that exploit flaws faster than previously possible.
Dustin Childs, researcher at the Zero Day Initiative, said the current spike in discoveries represents the "new normal." He noted finding over 20 wormable vulnerabilities in Microsoft's latest release—flaws requiring no user interaction and capable of spreading autonomously between machines.
"Despite the rapid patching, the potential damage from AI-assisted attacks could become substantial," Childs said.
Industry observers remain split on AI-assisted vulnerability hunting's return on investment. Critics point to high false positive rates and question whether companies are merely recouping their multi-billion-dollar AI infrastructure spending through inflated discovery metrics. Defenders counter that the record number of severe vulnerabilities found demonstrates tangible security value regardless of cost or noise.
Childs noted that AI-assisted discovery continues accelerating while active exploits of these vulnerabilities have not yet spiked—a gap that underscores the race between discovery velocity and exploitation velocity.
For enterprise security leaders, the arithmetic is unforgiving: expanding threat surface, compressed patch windows and uncertainty about exploit timelines force higher spending on detection and response infrastructure.