Microsoft Ships Record 974 Security Fixes, and Businesses Are Struggling to Keep Up
Microsoft has released updates for at least 974 security holes in Windows and other software, by far its biggest single patch batch. The previous record was 570 fixes in July. With three months still to go, this year's total has passed 2,600, more than double the old annual record of 1,245 set in 2020. Microsoft says artificial intelligence is helping speed up the discovery of vulnerabilities, and other large vendors including Adobe, Cisco, Google, Mozilla and Oracle have also credited AI-assisted research with increasing their patch volume. Google said it will now ship security updates every two weeks.
Two of the flaws, CVE-2026-81963 and CVE-2026-85880, are "zero-day" bugs that attackers are already exploiting. Both allow an attacker to gain higher privileges on a Windows system. In total, 113 of the fixes are rated "critical", meaning malware or attackers could take control of a vulnerable machine with little or no help from the user. These include CVE-2026-69730, a DNS weakness affecting Windows Server 2012 onward and Windows 10, which Microsoft says could be exploited by an unauthenticated attacker sending a specially crafted packet and is likely to be targeted. Another is CVE-2026-69829, a Windows Shell remote code execution flaw with a severity score of 9.8 out of 10 that needs no privileges and no user interaction.
Security experts warn that many organisations are already struggling to prioritise, test and deploy so many fixes each month, a task that still depends heavily on people.