Microsoft Patch Tuesday Shatters Records as AI-Driven Bug Discovery Surges
Microsoft's Patch Tuesday releases have been record-breaking this year, with the latest update addressing 419 security vulnerabilities. This marks one of the largest monthly counts on record and is a direct result of artificial intelligence (AI) dramatically increasing the number of software flaws that security teams must contend with.
In May, Microsoft stated that AI-powered vulnerability discovery had reached a point where it was no longer speculative, but rather an engineering problem. Since then, successive record-breaking releases have seen the company exceed its annual record for vulnerabilities, which stands at around 1,250.
The latest update, released in August, addresses 62 critical and 357 important-rated issues. Microsoft has replaced its previous itemized list of individual CVEs with a summary table showing a count of bugs by product family, alongside a 'Notable CVEs' section.
Three of this month's flaws are zero-days, with two being publicly disclosed before the patches dropped and one having been seen exploited in the wild. The company has tied the attacks to a campaign by Lazarus Group, which has been targeting applicants for attractive job opportunities at well-known companies in the defense, aerospace, and aviation industries.
Microsoft attributed one of the publicly known flaws, CVE-2026-62832, to an anonymous researcher, whose details appear to match a proof-of-concept called LegacyHive published by the pseudonymous researcher Nightmare Eclipse hours after last month's Patch Tuesday.