.webp)
On September 8, 2026, Microsoft released fixes for around 974 security vulnerabilities in a single day. More than 110 were rated critical. It is the largest batch the company has ever shipped, comfortably beating the previous record of 569 set in July. Microsoft has now patched roughly 2,760 flaws in 2026, more than double its worst year on record, and we still have three months to go.

Here is the detail that should shape how you react to that number. The two flaws that attackers were using before the patch existed were not rated critical. Both were rated important. One sits in the Windows Update Stack, the other in a component called Advanced Local Procedure Call, and both let an attacker already on your machine promote themselves to full system control.
The severity label was not a good indicator of which ones mattered. Neither did the headline number. Which raises the real question for a small business, and it is not whether you can absorb a thousand patches a month. Rather, it is whether you know what you own well enough to find the handful that apply to you.
Why the Numbers Have Exploded
Microsoft credits artificial intelligence with finding these flaws faster, and it is not alone. Adobe, Cisco, Google, Mozilla and Oracle have all reported the same pressure on their patch volumes. Google's AI pipeline fixed more than a thousand security bugs across two Chrome releases, more than the previous two years of releases combined.
Software is not getting worse. These bugs have been sitting in the code for years, in some cases decades, and machines are now reading code fast enough to find them. Dustin Childs at the Zero Day Initiative has called the current pace the new normal, and he is right. Next year this is not going to drop back to a hundred fixes a month.
That is mostly good news. Thousands of holes are being found and closed by people on your side, and to date, the flood of patches has not been matched by a flood of attacks.
The caveat is that two of September's flaws were exploited before a fix existed. Researchers counted twenty wormable bugs, the kind that hop between machines without anyone clicking anything. And one Exchange flaw that fires when the server indexes an emailed attachment, which means no click, no preview, no credentials, nothing a user could have done differently. When something does get weaponized, the window between disclosure and exploitation keeps shrinking.
Bigger Haystacks, Same Number of Needles
Satnam Narang at Tenable put it well when he said AI assisted vulnerability discovery is creating larger haystacks without finding more needles. The number of these flaws that will ever touch a fifteen-person business is small. A DNS weakness in Windows Server matters if you run one and not at all if you do not.
That is genuinely reassuring, and it is also the trap. Because knowing that only a few patches matter is useless if you have no way of working out which few.
The Visibility Problem
Most small businesses do not have a reliable list of what they own. How many laptops are in circulation, which ones are still getting updates, what server software is running and when it was last touched, which of those old phones still have access to email. When Patch Tuesday was a modest affair, fuzzy coverage was survivable. You could absorb a bit of guesswork because the volume was small enough that keeping broadly current was close enough to keeping current.
At a thousand fixes a month, guesswork stops working. You cannot triage a haystack you have never measured. The businesses that will handle this well are not the ones patching fastest. They are the ones who can answer what they run and where it sits.

An asset inventory is not glamorous. It is a list. But it turns an unmanageable number into a short one, and it is the single thing that makes every other security decision cheaper.
Your AI Tools are A Part of Your Inventory
AI features are software, and software has flaws. AI assistants make attractive targets because of what they can reach. A copilot with access to your inbox, your files, and your customer records holds a set of keys that a spreadsheet never did. Agents that act on your behalf can sometimes be talked into acting against you.
Small businesses have embraced these tools and almost entirely organically. Someone added a helpful browser extension. Someone connected a meeting note taker to the company calendar. Someone gave an assistant access to the shared drive to save an afternoon. Every one of those choices made good sense at the time.
What lagged is any record of it happening. Ask most owners which AI tools are in use across their business and what data those tools can reach, and you will get a thoughtful pause. That is shadow AI and it is a visibility gap.
The Stability Question
One more reason the inventory matters. Larger companies test updates before rolling them out, because third party software does not always react well to change. Smaller firms tend to skip that step and usually get away with it. With volumes climbing this fast, the odds that one update breaks something else are climbing right alongside them. When that happens, who works out which of the patches you applied last month caused it? If you do not know what you deployed and when, that becomes an expensive afternoon.
What to Do About It
You do not need dedicated security operations. You need a decent IT partner and a few conversations.
Start by asking for the list. Every device, every piece of software, who has what, what is still supported. If your provider cannot produce that reasonably quickly, that is something to consider. Have them scan for shadow AI while they are at it, and make sure updates cover software and browsers rather than just the obvious Windows machines.
Then decide who approves a new tool before it gets near customer data. Turn on multifactor authentication, which still stops most account takeovers. Back up your data and test a restore, because an untested backup is a hope rather than a plan.
Two free things worth knowing about. CISA publishes a catalog of vulnerabilities confirmed to be under active exploitation, and both of September's zero days landed on it within days. That list is a far better prioritization tool than raw severity scores. And if you work with a managed service provider, ask them directly how fast critical patches reach your machines and how they decide what jumps the queue. A good provider will have an answer ready.
Cybersecurity Insurance
This is not only about avoiding a breach.
Your cyber insurance renewal will ask about patch cadence, multifactor authentication, and backups, and the questions get sharper every year. So will any enterprise client running a vendor security review, and those reviews are increasingly where deals are won or quietly lost. An asset register and a documented patch process are what is needed.
Tidying your effort increasingly decides who you get to do business with.
The Bottom Line
The headline number is alarming by design. What sits underneath it is more encouraging. Most of those 974 flaws will never come near you, and the ones that might are being found and fixed by people on your side, faster than ever.
Your job is not to keep up with the count. It is to know what you own, so that when something on that list has your name on it, you can find it before anyone else does.
Patch early, patch often, and keep a list. You will sleep better.
Not sure your IT is pulling its weight? Book a meeting with one of our experts. Net Friends has helped plenty of clients turn shaky governance into a security posture worth standing on.
Take IT Off Your To-Do List.
Tech holding you back? Losing productivity to downtime?
Discover how we can simplify your tech and free up your time, contact us today.
At Net Friends, we believe in the power of human expertise. While we leverage AI to enhance our content and processes, all blog posts are written and edited by our knowledgeable staff. You can trust you are getting insights directly from our team.
