Safety2 min read

Microsoft Patches Record 972 Software Flaws This Month

By , Senior AI ConsultantPublished

Microsoft's September security update fixed a record 972 vulnerabilities, up sharply from 620 last month and 570 the month before, as AI tools speed up how fast both security researchers and criminals can find and exploit software weaknesses.

Microsoft's September security update fixed 972 separate flaws across Windows, Office, and its other products. That is the largest single batch of fixes the company has ever shipped in one month. Of those, 112 were rated critical, the most severe category, meaning a hacker could take over a machine with little effort.

Two of the bugs were already being used by attackers before Microsoft even released the fix. The US government's cyber defense agency told federal agencies to patch those two within days, not weeks.

This is not a one-off spike. Two months ago Microsoft set what was then a record with 570 fixes. Last month it was 620. In just two months, the size of a single month's patch batch has grown by roughly 70 percent.

The pattern goes beyond Microsoft. Across the whole software industry, security researchers logged far more newly discovered flaws in 2025 than in any prior year, with the yearly count approaching 50,000 and growth of around 20 percent over the year before.

There are two forces pushing these numbers up at the same time. Security teams are now using AI tools to scan code for weaknesses much faster than a person could do by hand, which is a big reason so many bugs are being found and fixed in bulk. But the same kind of tool is available to criminals, who can now turn a newly announced bug into a working attack far faster than they used to.

Two weeks before this patch release, OpenAI, Anthropic, Google, Microsoft, Amazon, and more than 100 other companies, including banks, telecom operators, and cybersecurity firms, signed an open letter warning that businesses have a shrinking window to strengthen their defenses before AI-powered attacks become common. The letter specifically flagged hospitals and water treatment plants as examples of organizations that are attractive targets because they often lack a dedicated security staff.

That last point matters far beyond hospitals and utilities. Most mid-sized companies also do not have a full-time security team watching for new threats every hour of the day. If your business relies on Windows machines, cloud software, or any vendor's product, the honest assumption now is that a new critical flaw could be found and used against you within hours of becoming public, not weeks.

Dustin Childs, a researcher who tracks these releases every month, calls this the "new normal." The practical takeaway is simple: treat critical security updates as same-day work, not something to schedule for next quarter, and ask your software vendors and IT provider directly how fast they apply patches once one is released. Waiting for the old monthly rhythm is no longer a safe bet.


STAY INFORMED

Get AI intelligence like this delivered to your inbox.

Free forever · Unsubscribe anytime


You May Also Find Valuable