Microsoft’s September security release addresses roughly 972 vulnerabilities by one widely used count, including 112 rated critical. The total reaches 997 when fixes inherited from the Chromium browser in Microsoft Edge are included. Counting varies because some issues affect non-Microsoft components or were partially addressed earlier.

Researchers highlighted two zero-days, CVE-2026-81963 and CVE-2026-85880, involving the Windows update service and Windows Advanced Local Procedure. Public information did not identify who was exploiting them or how broadly. Other notable flaws affect Exchange Server, Microsoft Authenticator, SharePoint, SQL Server and Remote Desktop Services.

More than 20 of the patched vulnerabilities were described as wormable, meaning exploitation can spread without a user opening a file or clicking a link. One Exchange flaw could allow remote code execution through a malicious Visio attachment sent by email, while a Remote Desktop Services flaw carries a 9.8 severity rating.

Microsoft has fixed about 2,760 vulnerabilities so far this year, more than twice last year’s total, according to the Ars Technica report. July and August also set unusually high monthly counts. Researchers connect part of the acceleration to AI-assisted bug discovery, but they have not documented a corresponding rise in active exploitation at the same scale.

The release does not mean every Windows system faces every flaw. Exposure depends on products, configurations, privileges and network reachability. Administrators need Microsoft’s individual advisories and their own inventory to prioritize deployment. The long-term false-positive rate and cost-effectiveness of AI-assisted discovery remain unsettled.

The checked record for Microsoft’s September Update Fixes About 972 Security Flaws establishes the following dated facts: One count identifies roughly 972 patched vulnerabilities. The total is 997 when Chromium fixes in Edge are included. Researchers counted 112 critical issues. Two zero-days were identified in the release. More than 20 flaws were described as wormable. The relevant background is also specific: Vulnerability counts vary with included products and previously addressed issues. Microsoft has fixed about 2,760 flaws so far in 2026. AI-assisted discovery is increasing research throughput, but active exploitation has not risen at the same measured rate. The exact count is methodology-dependent, and public reporting does not establish exploitation for most flaws. The cited reporting does not resolve questions beyond those stated limits.