Infrastructure

Microsoft patches a record 972 vulnerabilities in September, and one of them is triggered by SQL Copilot

September 9, 2026 at 7:20 PM PT

Bar chart from Ars Technica showing Microsoft vulnerability patches per year, with 2026 already above the totals for 2023, 2024 and 2025 combined

Image: Microsoft, via Ars Technica

Why it mattersAny team that runs Exchange, SharePoint, SQL Server or Remote Desktop is patching against a critical bug this week, and one of them fires when a user asks SQL Copilot a question.

Microsoft's September patch release fixes a record 972 vulnerabilities, Ars Technica reports, citing counts by Dustin Childs of the Zero Day Initiative. 112 of them are rated critical, and the remainder are marked important.

The record has been climbing for months. Microsoft patched 570 vulnerabilities in July and about 620 in August, both of those also records at the time. Year to date the company has now fixed 2,760 vulnerabilities, more than double the same period last year, and at that pace it will end 2026 having shipped more fixes than 2023, 2024 and 2025 combined.

Ars attributes the run to AI-assisted vulnerability discovery. Two weeks ago OpenAI, Anthropic, Amazon Web Services, Google, Microsoft and about 100 other companies published an open letter warning of a narrowing window between when bugs are found and when AI-enabled attackers can weaponise them. Childs calls the spikes "the new normal" and says active exploitation has not risen to match the discovery rate yet.

Bugs a team is likely to be running

Childs called out several vulnerabilities that affect widely deployed Microsoft software. CVE-2026-55007 in Exchange Server lets a remote, unauthenticated attacker execute code by sending an email with a malicious Visio attachment. CVE-2026-69525 is a Remote Desktop Services flaw with a 9.8 severity rating. CVE-2026-69465 covers about 17 separate remote code execution vulnerabilities in SharePoint. CVE-2026-80097 is a local privilege escalation in Microsoft Authenticator that Childs describes as the worst kind, because the bug is in the authentication system itself.

Two zero days are in this release: CVE-2026-81963 in the Windows Update service and CVE-2026-85880 in the Windows Advanced Local Procedure. Ars says there is no public information yet on who is exploiting them or how widely.

The one that is triggered by a Copilot prompt

CVE-2026-65669 sits among 60 SQL Server privilege escalation bugs in this release. What makes it different is the trigger: Ars, citing Childs, says the flaw is exploited when a user submits instructions through SQL Copilot. That is the first entry in a monthly Microsoft release that names a Copilot prompt as the delivery mechanism for a privilege escalation, rather than a crafted file or a network packet. Teams that have connected SQL Copilot to production databases inherit that path until the patch is applied.

The count itself carries a caveat that Ars states directly. The 972 figure is Childs's count of new Microsoft-issued CVEs, and rises to 997 if the Chromium fixes ported into Edge are included. Some previously addressed bugs and non-Microsoft products are excluded. Different trackers will report different totals for the same release.

Source

Reported by: Ars Technica

This item was written by an AI system from the linked source. Reveneau is responsible for what it publishes.

More from AI News

Proofpoint says four groups are sharing one Chrome exploit kit, and the patches landed in the last 24 hours

Proofpoint says four hacking groups have been using the same three-bug exploit kit against Chromium browsers and Windows, and links the pace to AI-assisted exploit development.

Source: PressInfrastructure

Microsoft measured a phishing campaign that peaked at 2.37 million messages a day using the invisible Unicode trick built for prompt injection

Microsoft published measurements of a phishing campaign that hid invisible Unicode tag characters inside financial keywords, peaking at 2.37 million messages on a single day in February 2026.

Source: PressInfrastructure

Engineer Jyn says GLM 5.3-flash puts capable offensive AI on a $9,500 Mac, and security teams have about a year to prepare

An engineer writing at jyn.dev argues that GLM 5.3-flash and its refusal-stripped variants have made capable offensive AI cheap enough to run at home, and that industry has about a year before this becomes routine.

Source: Hacker NewsInfrastructure