September’s Patch Tuesday bundle from Microsoft ran to 972 fixes. That takes the company to roughly 2,750 repaired flaws this year, well past the 1,250 it logged across all of 2020.
Volume like that has a cause, and researchers keep landing on the same one. Automated code review is finding bugs faster than human reviewers ever managed.
Two items on the list were already in use. Attackers could raise their privileges on Windows through CVE-2026-81963 and CVE-2026-85880. Proofpoint and Volexity are credited with the second, while Airbus Helicopters and Microsoft’s own Threat Intelligence Center reported the first independently.
Severity splits matter as much as totals. Microsoft marked 113 issues critical. Partner tallies put 258 in the remote code execution column and 438 under elevation of privilege.
Context arrived the same week. OpenAI, Anthropic, AWS, Google and Microsoft jointly warned that AI-enabled attacks are about to become wider and more sophisticated.
Practitioners are less worried about finding flaws than absorbing them. Jack Bicer at Action1 said triage now matters more than coverage. Marva Bailer of Qualaix pointed out that testing a fix and pushing it to thousands of devices is the point where patching stops being technical. Fortra’s Tyler Reguly was blunter, arguing the numbers have stopped carrying meaning while the company stays in catch-up mode.