Microsoft’s September security release fixes roughly 972 vulnerabilities by one researcher’s count, including 112 rated critical. Adding Chromium fixes carried into Edge brings the estimate to 997. Exact totals vary because some flaws were addressed earlier or affect products outside Microsoft.
The release includes two zero-days in Windows services, though public details about their exploitation remain limited. Other notable patches cover an Exchange Server flaw triggered by a malicious Visio attachment, a high-severity Remote Desktop Services bug, multiple SharePoint code-execution issues and dozens of SQL Server privilege-escalation flaws. Zero Day Initiative researcher Dustin Childs said he stopped counting potentially wormable bugs after finding 20.
Microsoft has fixed 2,760 vulnerabilities so far this year, more than twice last year’s count. Security researchers link the surge partly to AI-assisted bug discovery, but the long-term balance between useful findings, false positives and AI-enabled attacks is still uncertain. The immediate consequence is straightforward: organizations should prioritize exposed servers and remotely exploitable flaws rather than treating this as a routine monthly update.