Microsoft reportedly fixed 972 vulnerabilities in its September security release, including 112 rated critical and two zero-days. The practical message for Windows and Microsoft server administrators is wonderfully unglamorous: patching has just become the day’s main event.
Microsoft AI Watch analysis
What happened
The release landed on Tuesday, 8 September. Ars Technica’s archived account cites Zero Day Initiative researcher Dustin Childs, whose count rises to 997 when Chromium fixes ported into Edge are included.
The report says Microsoft has fixed 2,760 vulnerabilities during 2026, already more than twice the previous year’s total. WittyWires could not independently verify the advisories or totals, and the available evidence captures the article as archived on 9 September rather than establishing any later revisions.
Who is affected
- Windows administrators
Two reported zero-days affect Windows services, although the available account does not identify the attackers or scale of exploitation. - Exchange Server operators
CVE-2026-55007 reportedly allows unauthenticated remote code execution through an email carrying a malicious Visio attachment. - SharePoint administrators
The release reportedly addresses roughly 17 separate SharePoint vulnerabilities capable of remote code execution. - Remote Desktop users
CVE-2026-69525 is described as a remote-code-execution flaw carrying a 9.8 severity score. - SQL Server and Copilot users
CVE-2026-65669 reportedly enables privilege escalation when instructions are submitted through SQL Copilot. - Microsoft Authenticator users
CVE-2026-80097 is reported as a local privilege-escalation flaw inside the authentication system itself.
Why it matters
Childs reportedly stopped counting potentially wormable vulnerabilities after finding 20. Bugs requiring no user interaction can spread between machines and turn delayed patching from routine procrastination into an impressively efficient bad decision.
There is a larger AI-security signal too. The report links unusually large patch volumes across the industry with AI-assisted vulnerability discovery, while acknowledging live disputes over cost and false positives. Childs says active exploitation has not yet spiked in step with discovery, but expects AI-assisted hunting to keep accelerating.
Our read
Treat the extraordinary totals as a prioritisation prompt, not a substitute for checking the actual advisories. Administrators should review Microsoft’s September updates now, identify exposed Exchange, SharePoint, Remote Desktop and SQL Server systems, test the relevant fixes and shorten deployment windows for internet-facing services.
The encouraging bit is that defenders appear to be finding more flaws before attackers do. The less charming bit is that discovery capacity is accelerating on both sides, and the patch queue has apparently eaten the desk.
What to watch
- Whether Microsoft confirms the reported totals and affected configurations.
- Evidence about exploitation of the two reported zero-days.
- Deployment guidance or mitigations for systems that cannot patch immediately.
- Whether AI-assisted discovery produces sustained security gains without overwhelming validation teams.
Discussion spark: Which of these reported vulnerabilities creates the most urgent patching problem in your environment, and what would delay deployment?
Sources and evidence
- Why this month's Microsoft patch release is a doozy (8 September 2026, 21:11 UTC)
not affiliated with or endorsed by Microsoft