// PC GAMER — GAMING
Microsoft's AI vulnerability detection results in record-breaking Patch Tuesday, addressing 974 security flaws
When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works.
It's not always interesting, but it's important to stay on top of operating system updates. However, if you're on Windows, you're definitely gonna want to prick up your ears for Microsoft's September 2026 Patch Tuesday.
This might be Microsoft's biggest Patch Tuesday to date, addressing a whopping 974 security flaws found across both Windows 10 and Windows 11. Bleeping Computer offers a handy breakdown, reporting that 438 of these flaws were elevation of privilege vulnerabilities, 258 were remote code execution vulnerabilities, and 19 were security feature bypass vulnerabilities.
Perhaps more importantly, this Patch Tuesday also targets two actively exploited zero-days. Specifically, these are CVE-2026-85880 and CVE-2026-81963, which had both been leveraged previously to give attackers elevated system privileges.
Microsoft began leveraging AI vulnerability detection back in July, stressing back then that only the highest-confidence findings would ever reach the engineering team for fixing. As a result, July enjoyed a similarly record-breaking Patch Tuesday, stamping out 622 security vulnerabilities.
There's been a lot of praise for AI bug-hunting tools in recent months, with the CTO of Firefox raving about how an early version of Claude Mythos found 271 security vulnerabilities in the browser back in April. Anthropic itself was only too keen to toot its own horn that same month, saying that its AI had in fact found "thousands of high-severity vulnerabilities, including some in every major operating system and web browser."
Now, compare and contrast this to, say, all the times OpenAI's agents have reportedly breached containment in recent months. For instance, there was the 'wiki incident', where AI agents took over a communally editable German website, and then there was also the 'Hugging Face incident'. OpenAI has been taking steps to learn from these incidents.
But to bring it back to Microsoft, the Edge team recently implemented an automated browser extension review system to better deal with the tidal wave of "AI-assisted" submissions. It's currently unclear if the automated system also uses AI or machine-learning (via The Register).
Keep up to date with the most important stories and the best deals, as picked by the PC Gamer team.
It's an odd state of affairs when AI is both the source of a major security incident and core to the tools engineers now use to address vulnerabilities. Obviously, agentic AI is a bit different to the tools Microsoft is using, but here's hoping this latter AI tech continues to be more of a help than a hindrance.