CYBER DELTA FORCESearch

Microsoft Plugs Nearly 1,000 Security Holes

today issued updates to plug at least 974 security holes in its Windows operating systems and other software, by far its biggest single patch batch ever.

CDF News DeskKrebsOnSecurity9 Sept 2026, 3:14 am
CDF REPORT

today issued updates to plug at least 974 security holes in its Windows operating systems and other software, by far its biggest single patch batch ever. Microsoft says artificial intelligence is helping to speed the discovery of vulnerabilities, but security experts warn that many organizations already are struggling to prioritize the more human-intensive endeavor of testing and deploying so many fixes each month. September’s Patch Tuesday brings this year’s total to more than 2,600, more than twice Microsoft’s previous record-setting patch year in 2020 (1,245) and with three more months to go. Fully 113 of the bugs addressed today earned Microsoft’s “critical” rating, meaning they could be abused by malware or miscreants to seize control over a vulnerable Windows machine with little or no help from the user.

Do you have your teams deploy after hours and on weekends to avoid disruption to the business environment?

Time to dig into your budget and buy dinner for your teams that are working on Saturday to get patches rolled out before users return to work on Monday.” Satnam Narang is senior staff research engineer at Tenable .

What changed

Many other large software companies, including Adobe, Cisco, Google, Mozilla and Oracle, all have recently credited AI-assisted research with increasing their patch cadence and volume (Google said today it is now going to ship security updates every two weeks).

Narang said it’s important to recognize that while the number of vulnerabilities being patched by Microsoft is rising, the number of flaws that can and will affect most organizations remains quite low.

Who is affected

Time to dig into your budget and buy dinner for your teams that are working on Saturday to get patches rolled out before users return to work on Monday.” Satnam Narang is senior staff research engineer at Tenable .

Why this matters

Do you have your teams deploy after hours and on weekends to avoid disruption to the business environment?

How organizations are responding

Microsoft is hardly alone in shipping monster patch bundles lately.

What to watch next

Watch for additional exploitation reporting, newly published indicators, and changes to vendor guidance.

Watch for revised fixed-version guidance and confirmation that mitigations are holding in affected environments.

What remains unknown

The available reporting does not establish who is behind the activity, if an attacker is involved.

MORE IN THREAT RESEARCH

More cybersecurity reporting

Suspected Black Axe gang leaders face cybercrime charges in the USBleepingComputer · 15 Sept 2026, 3:20 pmMicrosoft confirms KB5002914 Excel update breaks copy and pasteBleepingComputer · 15 Sept 2026, 2:10 pmMicrosoft releases emergency Windows updates to fix RDS failuresBleepingComputer · 15 Sept 2026, 2:22 amMembers of ‘Black Axe’ cybercriminal group extradited from South AfricaThe Record · 15 Sept 2026, 1:10 am