The workload for defenders just increased, after Microsoft released patches for roughly 972 vulnerabilities in September, 112 of them flagged as critical. That surge more than doubles the company’s previous monthly high, set two months earlier when Microsoft addressed 570 vulnerabilities.
Other major vendors have posted similar spikes. The pattern of rising vulnerability disclosures has accelerated in recent months across the industry, with Google and unnamed peers also reporting record counts. The bursts of fixes arrive against an unusual backdrop: two weeks ago OpenAI, Anthropic, Amazon Web Services, Google, Microsoft and about 100 companies and organisations published an open letter warning that the window for patching security flaws is narrowing, and that AI-enabled attacks could exploit vulnerabilities faster than defenders can respond.
That warning is driving the current rush of patch releases. Companies are publishing and shipping fixes at unprecedented rates as they try to close flaws before automated exploit methods can find and weaponise them. Dustin Childs, a researcher at the Zero Day Initiative, calls the spikes "the new normal," and he also cautions that despite the higher volume of patches, the damage that is likely to result from AI-assisted attacks could eventually be substantial.
The immediate result is a heavier cadence of updates for software teams and organisations that run Microsoft products, and for anyone tracking cross-vendor vulnerability disclosure. The two-month jump from 570 to roughly 972 patched flaws shows how quickly the scale of the problem can change, and how pressure from a perceived AI threat is altering the operating rhythm of security teams.
What happens next depends on whether vendors and customers can keep pace. The open letter's warning of a shrinking patching window makes it more likely that high-volume patch months will continue until defenders feel the pressure from AI-driven exploitation has eased. For now the industry is responding by accelerating fixes, while security practitioners must prioritise and deploy them at a faster clip to limit exposure.
