Microsoft's Patch Cycle Overwhelmed by Agentic AI-Driven Vulnerability Surge
Microsoft's patch cycle has become increasingly challenging due to an explosion of risk with agentic AI, leading to a significant increase in vulnerability patches. In September 2026, Microsoft released nearly as many fixes as it shipped during all of 2024, including 114 critical vulnerabilities, but only two were listed as actively exploited.
The number of new Common Vulnerabilities and Exposures (CVEs) has skyrocketed since late 2025, with an average of 249 per month from October 2025 to September 2026, a 178% increase from the previous year. This surge in vulnerability counts requires administrators to adapt patch strategies accordingly.
AI-assisted discovery is partly responsible for this rise, as Microsoft's multi-model agentic scanning harness (MDASH) uses over 100 specialized agents to scan code and identify vulnerabilities. However, AI does not necessarily mean more security issues, as it can also highlight old bugs that better tooling can finally see.
Managing the surge in vulnerability patches demands a shift in patch strategies, including automation, precise exposure data, and staged deployment rather than one long Patch Tuesday night. Microsoft recommends gradual rollout for Windows quality updates and requires at least two rings in Autopatch groups.