Patch Tuesday is the second Tuesday of each month, when Microsoft releases security updates for Windows, Office, Exchange, SharePoint, SQL Server and the rest of its products. Security and IT teams have planned around it for two decades. It was predictable work: test the updates, schedule a maintenance window, deploy, move on.
In 2026, that rhythm broke.
In September, Microsoft fixed 974 vulnerabilities in a single release, the largest Patch Tuesday in its history. The next one lands Tuesday, October 13. For most teams, the hard question this month is which of nearly a thousand fixes deserve this week's maintenance window, and which can wait.
How big the patch queue has become
In June, Microsoft shipped about 200 fixes, a record at the time. July nearly tripled that with 570. September nearly doubled July with 974, including 723 for Windows alone, 113 rated Critical, and two vulnerabilities already under active attack.
Microsoft has now fixed more than 2,760 vulnerabilities in 2026, more than double its total for all of 2025.
The cause is AI-assisted discovery. Microsoft now runs an AI vulnerability discovery pipeline that feeds its patch stream, and it told customers before the July release to expect higher volumes from here on. Other vendors are seeing the same thing. Adobe moved to security bulletins twice a month, citing the same acceleration.
Bottom line: the volume is the new normal. AI is finding vulnerabilities faster than any team can patch them, and every vendor's release is getting bigger.
"Exploitation unlikely" was written for human attackers
When the queue gets this long, teams lean on shortcuts. One of the most common is Microsoft's own exploitability rating, which labels each fix with how likely attackers are to use it. A fix marked "Exploitation Less Likely" or "Exploitation Unlikely" often slides to next month.
That shortcut is breaking. Anthropic's red team took 14 vulnerabilities Microsoft had rated less likely or unlikely to be exploited and built working proof-of-concept exploits for 13 of them. One security researcher put it plainly: the exploitability index was built around human attackers, not AI tools.
The real world agrees. A SharePoint vulnerability Microsoft rated "Exploitation Less Likely" landed on CISA's Known Exploited Vulnerabilities list on July 1, weeks before it was patched on July 14.
Bottom line: a vendor rating is an estimate about who might attack you and how. Testing it in your own environment is the only way to know what's actually exploitable.
Most teams were falling behind before the flood
The patch volume landed on teams that were already losing ground. Verizon's 2026 Data Breach Investigations Report found:
Exploiting a vulnerability is now the most common way breaches start, at 31%, up from 20% a year earlier.
Only 26% of vulnerabilities on CISA's known-exploited list were fully fixed last year, down from 38%.
The median time to fix one of those vulnerabilities rose to 43 days, from 32.
Attackers move in the other direction. Mandiant's M-Trends 2026 puts the average time to exploit at negative seven days, which means many vulnerabilities are being exploited before a patch exists.
The cost of that gap is clear. IBM's 2026 Cost of a Data Breach report put the global average breach at a record $4.99 million, and $11.5 million in the U.S. Containing a breach took 247 days on average, the first increase in five years.
Bottom line: the gap between finding a vulnerability and fixing it was already widening. A thousand fixes a month makes it wider.
How to decide what to fix first
In June, CISA issued Binding Operational Directive 26-04, which replaced severity-based patch deadlines for federal agencies with four questions. It applies only to federal agencies, but its logic works for any team, and federal rules have a way of showing up in audits and vendor contracts.
Is the vulnerable system reachable from the internet?
Is the vulnerability on CISA's Known Exploited Vulnerabilities list?
Can an attacker exploit it automatically?
Would exploiting it give an attacker total control of the system?
The answers set fix windows of 3, 14 or 60 days. Most teams can answer the first two today from an asset inventory and the KEV list. The last two are harder, because they depend on how the vulnerability behaves in your environment, not in a lab.
Here's a practical order for October:
Fix the actively exploited vulnerabilities first. September's two were CVE-2026-81963 in the Windows Update Stack and CVE-2026-85880 in the Windows Advanced Local Procedure Call subsystem. CISA set a federal deadline of September 22 for both. If they're still open, they come before anything in October's release.
Sort by exposure. Internet-facing systems go to the top: VPNs, remote desktop, email, web servers and anything at the edge.
Cross-check against the KEV list. Anything that's internet-facing and actively exploited gets the 3-day window.
Confirm what's exploitable in your environment. A scanner reports that a vulnerable version exists. It can't tell you whether a compensating control, a network path or a configuration already blocks the attack. Testing can.
Verify the fix. A deployed patch that failed on a third of your servers looks the same in a dashboard as one that worked. Re-test after patching to confirm the exposure is closed.
Bottom line: exposure and active exploitation set the order. Proof decides how much of the remaining queue needs this week's window, and verification confirms the work is done.
Where Agent Bounty fits
Agent Bounty runs all five steps as one continuous loop. A continuously expanding fleet of specialized security agents maps your assets and what's exposed to the internet, checks every finding against active exploitation data, including CISA's KEV list, and tests which vulnerabilities are actually exploitable in your environment. It then prepares the fix and hands it to your team for approval before anything changes, and re-tests afterward to confirm the exposure is closed. Only verified, exploitable findings reach your queue.
Find. Prove. Fix.
Bottom line: when the queue holds a thousand items, the goal is to fix the dozen that matter this week and prove it worked.
Frequently asked questions
How many vulnerabilities did Microsoft patch in September 2026?
Microsoft's September 2026 Patch Tuesday fixed 974 vulnerabilities, the largest monthly release on record. That included 723 Windows vulnerabilities, 113 rated Critical, and two zero-days under active exploitation. Counts from different trackers range from 964 to 995 depending on what they include.
When is Patch Tuesday in October 2026?
October's Patch Tuesday is Tuesday, October 13, 2026. Patch Tuesday falls on the second Tuesday of every month.
Why are Patch Tuesday releases so large in 2026?
Microsoft attributes the increase to AI-assisted vulnerability discovery, including an internal AI pipeline that now feeds its patch stream. It has told customers to expect higher volumes going forward.
What does "Exploitation Less Likely" mean on a Microsoft patch?
It's Microsoft's estimate of how likely attackers are to exploit a vulnerability. It isn't a guarantee. In 2026, AI tools built working exploits for 13 of 14 vulnerabilities rated less likely or unlikely to be exploited.
How should a small security team prioritize patches?
Start with vulnerabilities that are actively exploited, then internet-facing systems, then anything on CISA's KEV list. After that, test which remaining vulnerabilities are exploitable in your environment, and re-test after patching to confirm each fix worked.
What is CISA BOD 26-04?
BOD 26-04 is a June 2026 directive that requires federal civilian agencies to prioritize patches using four factors: internet exposure, known exploitation, whether exploitation can be automated, and whether it gives an attacker total control. It sets fix windows of 3, 14 or 60 days. It replaced BOD 19-02 and BOD 22-01.
See how it works
Try the interactive demo to see how Agent Bounty proves what's exploitable, prepares the fix, and keeps your team in control of every change.
Sources
Microsoft Security Response Center, Security Update Guide, September 2026 release
Cloud Security Alliance, AI Discovery Outpaces Patch Capacity, August 2026
Help Net Security, AI-driven bug hunting fuels record Microsoft Patch Tuesday, July 2026
Google Cloud, Mandiant M-Trends 2026




