Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

The Record-Shattering Microsoft Patch Release: A New Era of AI-Assisted Vulnerability Discovery




Microsoft's September patch release has set a new benchmark for vulnerability discovery, with a staggering 972 vulnerabilities fixed and 112 of them meeting the high critical-severity threshold. This latest patch, released just two months ago, surpasses the previous record set by Microsoft in September 2026, with 570 vulnerabilities fixed. The company has been ramping up its patching efforts in recent months, with Google and other companies publishing record numbers of vulnerabilities in their software. Read on to learn more about the record-shattering Microsoft patch release and the implications of AI-assisted vulnerability hunting.

  • Microsoft has fixed 972 vulnerabilities in its September patch release, including 112 with high critical severity.
  • The company has surpassed its previous record of 570 vulnerabilities fixed in September 2026.
  • The rapid pace of vulnerability discovery is attributed to growing use of AI-assisted vulnerability hunting.
  • Critics have questioned the effectiveness of AI-assisted vulnerability hunting due to concerns over expense, false positives, and motives.
  • Despite concerns, AI-assisted hunting has resulted in record numbers of severe bugs across the industry.
  • Notable vulnerabilities include zero-days, remote code execution, and local privilege escalation in various Microsoft software.
  • AI-assisted hunting has identified 20 wormable vulnerabilities that can spread from machine to machine without user interaction.



  • Microsoft's September patch release has set a new benchmark for vulnerability discovery, with a staggering 972 vulnerabilities fixed and 112 of them meeting the high critical-severity threshold. This latest patch, released just two months ago, surpasses the previous record set by Microsoft in September 2026, with 570 vulnerabilities fixed. The company has been ramping up its patching efforts in recent months, with Google and other companies publishing record numbers of vulnerabilities in their software.

    The rapid pace of vulnerability discovery is largely attributed to the growing use of AI-assisted vulnerability hunting. This technology has been widely adopted by companies, including Microsoft, to identify and patch vulnerabilities in their software. However, the effectiveness of AI-assisted vulnerability hunting has been met with controversy, with critics questioning the expense, number of false positives, and motives of companies developing this technology.

    Despite these concerns, the results of AI-assisted hunting are undeniable. Researchers have found record numbers of severe bugs across the industry, with Mozilla's researchers using Mythos finding a record 271 vulnerabilities, almost none of which were false positives. The true long-term effectiveness of AI-assisted bug hunting will take time to be known, but it is clear that critics should maintain curiosity and remain open to the possibility that vulnerability discovery has entered a new and unprecedented phase.

    Notable vulnerabilities in this month's release include two zero-days, CVE-2026-81963 and CVE-2026-85880, in the Windows update service and the Windows Advanced Local Procedure, respectively. Other notable vulnerabilities include CVE-2026-55007 in Exchange Server, allowing remote code execution by sending a malicious Visio attachment, and CVE-2026-80097, a local privilege escalation in Microsoft Authenticator.

    The researcher, Dustin Childs, has found so many wormable vulnerabilities in this month's release that he stopped counting at 20. These vulnerabilities do not require any user interaction to be exploited and can spread from machine to machine on their own, triggering a possible chain reaction that is difficult to stop.

    The effectiveness of AI-assisted vulnerability hunting is filled with controversy, but the results speak for themselves. Companies are taking the threat seriously by pumping out unprecedented numbers of patches in their software. However, the true impact of AI-assisted vulnerability hunting will take time to be known, and critics should remain open to the possibility that vulnerability discovery has entered a new and unprecedented phase.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/The-Record-Shattering-Microsoft-Patch-Release-A-New-Era-of-AI-Assisted-Vulnerability-Discovery-ehn.shtml

  • https://arstechnica.com/security/2026/09/microsoft-patches-a-record-972-vulnerabilities-112-of-them-critical/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-81963

  • https://www.cvedetails.com/cve/CVE-2026-81963/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-85880

  • https://www.cvedetails.com/cve/CVE-2026-85880/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-55007

  • https://www.cvedetails.com/cve/CVE-2026-55007/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-80097

  • https://www.cvedetails.com/cve/CVE-2026-80097/


  • Published: Tue Sep 8 19:58:12 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us