{
  "id": 7307606,
  "title": "Microsoft’s Patching",
  "url": "https://urgent.news/2026/09/14/microsofts-patching",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-14T11:03:26.000Z",
  "source": {
    "name": "Schneier on Security",
    "slug": "schneier-on-security",
    "url": "https://www.schneier.com/blog/archives/2026/09/microsofts-patching.html"
  },
  "original_language": "en",
  "account": "Microsoft releases a monthly security update for all Windows users. This month's update, set for tomorrow, is particularly significant: it addresses a record-breaking 972 vulnerabilities, with 112 of them classified as high critical severity. Just two months ago, Microsoft patched 570 vulnerabilities, and last month, they tackled around 620.\n\nIn recent months, other major companies like Google and AWS have also reported record-high numbers of vulnerabilities. Two weeks ago, a coalition including OpenAI, Anthropic, Amazon Web Services, Google, Microsoft, and 100 other companies issued an open letter warning of a shrinking window for patching vulnerabilities before AI-enabled attacks exploit them.\n\nThe industry is responding to this threat by producing an unprecedented number of patches for their software. This surge is largely due to AI-powered vulnerability discovery, demonstrating how AI is proving more beneficial to defenders than attackers at the moment.\n\nAs AI technology advances in identifying software vulnerabilities, the number of reported vulnerabilities is expected to increase over the coming months. However, the trend is anticipated to reverse once AI systems have exhausted potential vulnerabilities to uncover. The magnitude, pace, and rate of decline after this peak remain uncertain.\n\nMicrosoft emphasizes that the window for patching has compressed to \"immediately.\" AI systems can also reverse-engineer exploits from patch releases, meaning that these vulnerabilities could be weaponized shortly after the update is deployed.",
  "summary": "Once a month, Microsoft pushes a security update to all Windows users. Tomorrow’s is a new record : Microsoft’s patch for September is a doozy, with a record number of roughly 972 vulnerabilities fixed and 112 of them meeting the high critical-severity threshold. It was only two months ago that Microsoft patched a then-record 570 vulnerabilities. Then, last month, Microsoft patched some 620 of…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}