I pulled Patch Tuesday numbers going back two years for this post and almost double-checked my math. The count barely moved for most of that time. Then it broke.

The numbers, side by side

Two years ago, September 2024: Microsoft patched 79 CVEs, seven of them critical.[1] One year ago, September 2025: 80 CVEs, eight critical.[2] Six months ago, March 2026: 83 CVEs, eight critical.[3] That’s three years of Septembers and one March sitting in a tight band, 79 to 83. If you built a patch program around “we get roughly 80 to 100 things a month, budget staff time accordingly,” that program was working fine right up until this summer.

This month, September 2026: 964 CVEs by Tenable’s count, 104 of them critical.[5] Ars Technica, citing Zero Day Initiative’s count, puts it at 972, or 997 once Chromium and external bugs are folded in.[6] The two trackers disagree by roughly 1%, which tells you the exact number matters less than the order of magnitude: this is somewhere around twelve times last September’s total, in the same calendar month, from the same vendor.

This isn’t a one-month spike. July 2026 broke the previous record at 570 CVEs, almost triple June’s count.[4] August and September each broke the record again, back to back.[6] Three records in three consecutive months is not noise.

Microsoft says it’s AI, and I believe them on this one

Microsoft’s own explanation, from an EVP’s blog post in July, is that AI is finding bugs faster than humans ever did, across more of the codebase, including issues that have been sitting in Windows for years.[4] I don’t have a reason to doubt the mechanism. Mozilla reported something similar in May: their AI tool Mythos found 271 vulnerabilities with almost no false positives, which is the kind of ratio that used to only happen with expensive, focused human audits.[6] Google’s June patch batch topped 900 fixes on its own.[4] This is not just a Microsoft story, and it is not a one-time bump from switching tools. I think this is a permanent change in how fast bugs get found industry-wide, though nobody has a year of data yet to prove that instead of assume it.[unverified]

Zero Day Initiative’s Dustin Childs called it the “new normal” and I think that’s the right frame, with one caveat he added himself: exploitation hasn’t spiked to match discovery yet.[6] That gap, more bugs found than are currently being used against you, is the good version of this story. Every source I read this week agrees it’s temporary, not permanent.[unverified]

The part that should worry you more than the headline number

Two weeks before this September’s Patch Tuesday, OpenAI, Anthropic, AWS, Google, Microsoft, and about a hundred other companies signed an open letter warning that AI-enabled attacks are about to get more widespread and sophisticated, and that defenders have a narrowing window to fix the backlog before that happens.[6][8] That’s not a vendor marketing a product. That’s the companies building the models telling you the clock is running on the side that benefits you right now.[8]

The evidence that the clock is already ticking showed up the same week, separate from Patch Tuesday. Proofpoint found four different espionage-motivated hacking groups using the same exploit kit, chaining two Chrome bugs and a Windows privilege-escalation flaw, within seven days of the first group using it.[7] The exploit developer had apparently been watching Chromium’s public source code commits, building working exploits during the gap between a fix landing in the code and that fix reaching the stable browser everyone actually runs.[7] That patch-gap window used to be something only well-resourced state actors could reliably exploit fast enough to matter.[unverified] Four separate groups doing it inside a week, per Proofpoint’s own count, suggests the barrier to building on someone else’s exploit chain just dropped.[7]

What I’d actually check this week

  1. Stop budgeting patch cycles around a fixed monthly count. 79 to 83 was stable for two years and is not coming back.[1][2][3] Build a triage process that scales with whatever number shows up, not one sized for last year’s average.

  2. Prioritize by exploitation status and exposure, not by raw CVE count. With over 900 CVEs in a single release, “patch everything this month” stopped being an achievable plan.[5] Patch what’s actively exploited and what’s internet-facing first. The edge-first triage I’ve been writing about since August still holds, it just matters more now.[9]

  3. Watch your patch-gap window, not just your patch backlog. The BlueMoon kit went from single-actor to four-actor in a week specifically because it targeted the delay between an upstream fix and the stable release most people run.[7] If you’re on Chrome/Edge or anything with a similar staged-rollout model, ask your vendor how long that gap actually is.

  4. Don’t assume “AI found more bugs” means “AI is winning.” Right now discovery is outpacing exploitation, which is the temporary advantage the open letter is asking everyone to use.[6][8] That’s a reason to move fast on the backlog, not a reason to relax.

Sources

[1] https://www.tenable.com/blog/microsofts-september-2024-patch-tuesday-addresses-79-cves-cve-2024-43491 — Tenable: September 2024 Patch Tuesday, 79 CVEs [2] https://www.tenable.com/blog/microsofts-september-2025-patch-tuesday-addresses-80-cves-cve-2025-55234 — Tenable: September 2025 Patch Tuesday, 80 CVEs [3] https://www.tenable.com/blog/microsofts-march-2026-patch-tuesday-addresses-83-cves-cve-2026-21262-cve-2026-26127 — Tenable: March 2026 Patch Tuesday, 83 CVEs [4] https://krebsonsecurity.com/2026/07/microsoft-patches-a-record-570-security-flaws/ — Krebs on Security: Microsoft Patches a Record 570 Security Flaws [5] https://www.tenable.com/blog/microsofts-september-2026-patch-tuesday-addresses-964-cves-cve-2026-81963-cve-2026-85880 — Tenable: September 2026 Patch Tuesday, 964 CVEs [6] https://arstechnica.com/security/2026/09/microsoft-patches-a-record-972-vulnerabilities-112-of-them-critical/ — Ars Technica: Microsoft patches a record 972 vulnerabilities, 112 critical [7] https://diesec.com/2026/09/top-5-cybersecurity-news-stories-september-11-2026/ — DIESEC: BlueMoon exploit kit adopted by four espionage clusters within a week [8] https://openai.com/collective-cyberdefense — OpenAI et al.: A call for collective action on cyber defense [9] https://blog.darkpixeltech.com/posts/weekend-wrap-415-patches-and-another-netscaler/ — Dark Pixel Tech: Weekend wrap, 415 patches and another NetScaler (edge-first patching)