Microsoft announced that it has fixed approximately 972 vulnerabilities (997 if Chromium-based Edge is included) in its September patch release. Among these, 112 were categorized as "Critical."\ The company's vulnerability fix count for the current fiscal year has reached 2,760, which is more than double the pace of the previous fiscal year.

This update includes two zero-day vulnerabilities in the Windows Update service (CVE-2026-81963 and CVE-2026-85880). Additionally, at least 20 vulnerabilities with "wormable" properties—meaning they could potentially spread infections without requiring user interaction—have been identified.

Against the backdrop of this surge in vulnerabilities, companies such as OpenAI, Anthropic, Google, and Microsoft have published a joint open letter warning of the increase in AI-powered cyberattacks. The letter states that while AI is improving the efficiency of vulnerability discovery, the risk of attackers using AI to launch sophisticated attacks is also rising. It calls for the utilization of AI technology on the defensive side and the implementation of rapid countermeasures for critical infrastructure.


Source: