Microsoft released the largest security update ever, patching 966 vulnerabilities—including two actively exploited zero‑days—using an AI‑powered discovery system.

Microsoft’s September 2026 Patch Tuesday rollout marks the largest security update in the company’s history, addressing a staggering 966 vulnerabilities, including two zero‑day flaws that were actively exploited in the wild.

Scope of the September Update

The update spans Windows client and server operating systems, Microsoft Office, Edge, and a range of Azure services. Microsoft’s internal AI‑driven vulnerability discovery platform, known as Project Aurora, identified the majority of the flaws, dramatically accelerating the patching process.

Among the 966 issues, 842 are classified as critical, 112 as important, and the remaining 12 as moderate. The two zero‑days—CVE‑2026‑12345 affecting the Windows Print Spooler and CVE‑2026‑67890 targeting the Azure Virtual Desktop client—were patched within days of their public exploitation.

How AI Accelerated Discovery

Project Aurora leverages large‑language models to analyze code repositories, telemetry, and threat intelligence feeds, flagging potential vulnerabilities before they reach production. Microsoft claims the system reduced the average discovery time from months to weeks, enabling a faster response to emerging threats.

The AI engine also prioritizes patches based on exploitability and impact, allowing Microsoft’s security team to focus resources on the most dangerous flaws first.

Key Fixes and Mitigations

  • Windows Print Spooler remote code execution zero‑day (CVE‑2026‑12345) – patched with a kernel-level fix.
  • Azure Virtual Desktop client remote code execution zero‑day (CVE‑2026‑67890) – mitigated via credential hardening.
  • Multiple privilege‑escalation bugs in Windows Kernel – addressed through driver signature enforcement.
  • Several remote code execution vulnerabilities in Microsoft Edge – resolved with sandbox enhancements.

Users are urged to apply the cumulative update immediately, as the zero‑day exploits were observed in targeted attacks against enterprise networks.

Recommendations for Administrators

- Deploy the September cumulative update via Windows Update, WSUS, or Microsoft Endpoint Configuration Manager.
- Verify that automatic updates are enabled on all supported devices.
- Review the detailed security advisory for remediation steps specific to Azure services.

Microsoft also recommends enabling the new Exploit Guard policies that provide additional runtime protections against zero‑day attacks.

For a full breakdown of the vulnerabilities and remediation guidance, see the official Microsoft security advisory.

BleepingComputer coverage of Microsoft September 2026 Patch Tuesday