Chief Information Security Officers (CISOs) are facing a new challenge in vulnerability management as frontier AI models accelerate both the discovery and exploitation of software weaknesses. While AI can scan code faster than human teams, the real test for security leaders is managing the sheer volume of findings and balancing speed with accuracy in patching.
Microsoft, which uses AI to identify vulnerabilities in its own code, emphasizes the importance of defense-in-depth strategies. The company reports that September 2026 saw a record number of vulnerabilities, close to 1,000, released on Patch Tuesday. To manage this, Microsoft employs a 'harness' layer around AI models to validate outputs and integrate findings into remediation workflows. The company has also made one of these harnesses, codename MDASH, available to customers.
CISOs are advised to rethink their patching strategies, particularly for critical systems. With AI reducing the time between patch release and exploitation, deploying fixes within 24 hours, rather than waiting for the next maintenance window, may become necessary. Additionally, CISOs should focus on monitoring the health of critical controls and consider implementing Microsoft Baseline Security Mode (BSM) to enhance their security posture.
Microsoft is also collaborating with industry peers to tackle vulnerabilities in open-source software, which poses a growing supply chain risk. The company is committed to Secure by Design and Secure by Default principles, implementing baseline security controls by default across its products to reduce the burden on customers.