Microsoft’s massive Patch Tuesday releases continue as AI reshapes bug discovery
Microsoft on Tuesday released fixes for 419 security vulnerabilities, one of the largest monthly counts on record and the latest sign that artificial intelligence is dramatically increasing the number of software flaws security teams must contend with.
In May, when Microsoft shipped patches for 137 vulnerabilities, the company stated the industry had reached a moment “where AI-powered vulnerability discovery stops being speculative and starts being an engineering problem.”
Since then, successive record-breaking releases — 206 in June, followed by 622 in July — have seen the company explode past its annual record for vulnerabilities, of around 1,250.
According to the company’s August release notes, the latest update addresses 62 critical and 357 important-rated issues. As with last month, Microsoft no longer lists the individual CVEs and has replaced the previously itemized batch with a summary table showing a count of bugs by product family, alongside a “Notable CVEs” section.
This month’s update features about five times the volume of patches Microsoft was shipping in a typical month before AI-assisted vulnerability discovery took hold. On the eve of that surge, Britain’s National Cyber Security Centre warned that organizations needed to prepare for a new tempo in mitigating vulnerabilities.
Three of this month’s flaws are zero-days. Two were publicly disclosed before the patches dropped, while one of which — CVE-2026-68820, affecting the Windows component that handles network connections — has been seen exploited in the wild.
The company tied the attacks to a campaign by Lazarus Group, which has been been targeting applicants for “attractive job opportunities at well-known companies in the defense, aerospace, and aviation industries” in a complicated attack that sees them combine PDFs with a trojanised reader allowing the hackers to secretly take control of the applicants’ machines.
One of the publicly-known flaws, CVE-2026-62832, was attributed by Microsoft to an anonymous researcher. The details of the vulnerability appear to match a proof-of-concept called LegacyHive published by the pseudonymous researcher Nightmare Eclipse hours after last month’s Patch Tuesday — the latest instalment in a months-long standoff over the company’s disclosure and bounty practices.
Widespread exploitation of the surge in vulnerabilities has not yet been observed. But the Five Eyes intelligence alliance warned in June that frontier AI models would soon be “fundamentally transforming both offensive and defensive cyber capabilities,” adding “the timeline is not years, it is months.”
The release date marks the start of a regular cycle for cybersecurity defenders. Once a patch is out, attackers pick it apart in an attempt to reverse-engineer the holes it plugs and then race to break into machines that have not yet been updated — a phenomenon often described as “Exploit Wednesday.”
Although the volume of bugs likely makes it more difficult for Microsoft to provide a detailed advisory, the new clustered format of the Security Updates page risks making triage more complex. Defenders and third-party trackers must now piece together the full picture from underlying advisory feeds themselves and figure out what needs to be patched first.
Alexander Martin
is the UK Editor for Recorded Future News. He was previously a technology reporter for Sky News and a fellow at the European Cyber Conflict Research Initiative, now Virtual Routes. He can be reached securely using Signal on: AlexanderMartin.79



