Cybersecurity team monitors AI-flagged threats and server processes in a high-tech data center.
Microsoft's security leadership is warning about AI's next big effect on IT teams, and it isn't speed. The problem is volume. In a Microsoft Security blog post published October 6, 2026, Freddy Dezeure, Microsoft's Deputy CISO for Europe, and Sesha Mani, Partner Director of Product Security, argue that frontier AI models are about to give security teams far more vulnerability findings than they have ever handled. They say the real test is whether teams can patch quickly and still patch correctly, at a scale that human review processes were never designed for.

This matters to anyone who runs Windows Server, Active Directory, Exchange, SharePoint or SQL Server on-premises. Microsoft is telling those customers that heavy Patch Tuesday releases are likely to continue for some time.

The numbers behind the warning​

The post says most vulnerabilities in Microsoft's cloud services are fixed by Microsoft without any customer action. On-premises software is different. Microsoft tells customers to expect far more vulnerabilities per Patch Tuesday than before frontier AI models arrived earlier this year. It calls September 2026 a record month with "close to 1,000."

Independent coverage of that release supports the claim, though outlets counted differently:

  • BleepingComputer reported that security updates were released for a record-breaking 966 flaws, including two actively exploited zero-day vulnerabilities, with 105 "Critical" vulnerabilities, 81 of which are remote code execution.
  • SecurityWeek and The Hacker News put the total at 974. The Hacker News reported 723 flaws in Windows, 111 in Office and Office 2016, 62 in SQL, and 22 in Developer Tools.
  • Windows Report, citing BleepingComputer, noted that the 966 figure does not include another 204 vulnerabilities that Microsoft fixed earlier in September across products and services including Azure, Copilot Studio, Entra ID, Edge, Microsoft Fabric, and Power Automate.
  • One aggregator summarizing that coverage put the trend in context: 966 in September after 570 in July and 400 in August.

The two zero-days were CVE-2026-85880 and CVE-2026-81963. They affect the Windows ALPC component and the Windows Update Stack, and both let an attacker escalate privileges to SYSTEM.

Whichever count you use, the trend is clear. A large CVE count tells you how many flaws were disclosed. It doesn't mean every flaw is exploitable or equally urgent. Part of the job is now deciding which few dozen fixes matter most in your environment.

Section summary: Microsoft's "close to 1,000" figure matches independent counts of 964–974 for September 2026. The monthly total has roughly doubled since summer, and that growth is mostly in on-premises products that customers have to patch themselves.

Why more scans aren't enough on their own​

The authors are open about a limitation of AI scanning. Because AI models are non-deterministic, two runs of the same model can produce different results, and so can two different models. Microsoft reviews each possible finding for validity, severity and potential impact before acting on it. The post also says many steps in Microsoft's vulnerability handling and disclosure process are now AI-assisted.

The main idea is the harness. This is a layer around the AI model that controls how it reads code, checks its own output, and passes findings into triage and remediation workflows. Microsoft says it now uses harnesses across all of its engineering groups. Its internal Red Team also uses AI to find weaknesses in security controls.

One of those harnesses, codename MDASH, is now available to customers. Microsoft Learn documentation describes it as a preview agentic code scanner in Microsoft Defender, so it is not yet generally available. According to that documentation, it works in four stages:

  1. Prepare: ranks files by risk using call-graph analysis and code-complexity metrics.
  2. Scan: runs more than 100 specialized agents, such as injection, memory-safety and auth-bypass auditors, across multiple models.
  3. Validate: uses taint analysis and Language Server Protocol type resolution, plus a "debate" between several models, to remove false positives.
  4. Dedup: merges duplicate findings into one final list.

Practical details from the Learn page:

  • Languages with specialized agents: Java, C/C++, C#, JavaScript/TypeScript (minified JavaScript is excluded) and Python.
  • Other languages: Go, Rust, Kotlin, PHP, Ruby, Swift, Objective-C and Zig are handled by general-purpose agents, and Microsoft warns that scan quality will vary.
  • Integration: connectors for GitHub and Azure DevOps, on-demand or CI/CD scans through the Defender CLI, and AI-generated fixes via a defender fix command.
  • Results: findings are published to Microsoft Security Exposure Management.
  • Regions: Azure commercial cloud in the US, EU, UK, Australia, India, Switzerland and the UAE. The UAE currently supports CLI scans only.
  • Network: the CLI host needs outbound access to a list of Microsoft domains. Locked-down build agents will need firewall exceptions.

For background, Microsoft's May 12, 2026 announcement said MDASH helped find 16 vulnerabilities in Windows networking and authentication code, including four critical remote code execution flaws. It also reported finding all 21 planted bugs in a private test driver with no false positives, and a top score of 88.45% on the public CyberGym benchmark at the time. These are Microsoft's own test results. They are not independent proof of how MDASH will perform on your code. Microsoft itself described its historical recall figures as retrospective benchmarks that don't predict future hit rates.

Section summary: Microsoft's advice is to judge AI security tools by how they validate findings and fit into your workflow, not by how many findings they produce. MDASH is a real product, but it is in preview and has clear limits on language support and regions.

Microsoft's four recommendations for CISOs​

1. Budget for patching, not just tooling​

Microsoft tells CISOs to put more resources into on-premises patching, prioritization and scheduling, because large Patch Tuesdays are expected "at least over the coming period." If your current process assumes about 100 CVEs a month, it was built for a smaller workload than you'll likely face.

2. Rethink the weekend maintenance window​

Teams have usually patched domain controllers and edge devices on weekends or holidays, when downtime hurts least. Microsoft says that habit may need to change as AI shortens the time between a patch's release and its exploitation. It suggests considering deploying fixes to these systems within 24 hours instead of waiting for the next maintenance window.

This is risk-based advice, not a Microsoft support requirement. It also doesn't mean every update should hit every server within a day. In practice, a 24-hour target for domain controllers only works if you already have:

  • a small, representative test ring that can validate a patch within hours
  • tested rollback steps, plus system-state backups for Active Directory
  • current dependency maps, so you know which line-of-business apps fail when a DC restarts
  • enough redundancy (more than one DC per site, and clustered or paired edge devices) to patch one node at a time

3. Scan your own code now​

Microsoft tells organizations that build software to start harness-based scanning "without delay" instead of waiting for access to frontier models. It also says to budget for both tokens and people to triage and fix what the scans find. That second part is the one teams tend to skip. A scanner that produces 400 findings with nobody assigned to them has created a backlog, not a security improvement.

4. Strengthen defense in depth and check your controls​

Not every vulnerability will be patched in time, so the post stresses controls that limit what an attacker can do after getting in, and ongoing monitoring of whether those controls are still working. It also notes that governments and regulators are raising cyber-resilience expectations through legislation. Microsoft points customers to a new Security Exposure Management guidance page for related capabilities.

Secure by Design, Secure by Default, and BSM​

The post separates two ideas:

  • Secure by Design: customers can't opt out. Examples include mandatory MFA for Azure administrators and Conditional Access enforcement for Windows Hello for Business and macOS Platform SSO registration.
  • Secure by Default: protections are on unless the customer turns them off. Examples include Azure Backup soft delete enabled by default and Azure VNet default outbound access disabled.

The main product recommendation is Microsoft Baseline Security Mode (BSM). Microsoft says BSM applies and monitors secure configurations at scale, based on "How Microsoft protects Microsoft." It also says BSM:

  • includes scenario analyses that show the impact of new controls on existing tenants, so you can roll them out in stages
  • lets you turn controls on and off and add or remove exceptions
  • is available to existing customers under their current license agreement
  • will be enabled gradually by default for new tenants

To be balanced: this part of the post is a vendor recommending its own product. That doesn't make the advice wrong, since baseline hardening is good practice. Still, run the impact analyses before enforcing anything, because legacy authentication flows and older integrations are the most likely to break when controls are tightened.

Open-source work​

Microsoft also says it is working with unnamed industry peers to coordinate scanning and patching of critical open-source components, pooling resources and working with maintainers. The reasoning is that many maintainers lack the tools or staff to respond quickly, and AI-assisted discovery increases the risk to the software supply chain. The post doesn't name specific packages, partners or fixes, so it's best treated as a stated commitment for now rather than something to evaluate yet.

What Windows admins should take from this​

Some of the post is product promotion, but the main argument holds up. AI has made finding vulnerabilities cheap, and the scarce resources are now validation, prioritization and deployment capacity. That applies to attackers and defenders alike.

What to do this quarter:

  • Rebuild your patch prioritization around known exploitation (the CISA KEV catalog), internet exposure and asset criticality, not CVE counts.
  • Pilot a faster track for Tier 0 assets such as domain controllers, identity infrastructure and edge appliances, with tested rollback.
  • Evaluate harness-based code scanning if you write software, but budget staff time for triage before you budget tokens.
  • Run BSM impact reports in a test tenant or in report-only mode before enforcing anything.
  • Monitor whether your controls are working, not just whether they're configured. A Conditional Access policy someone quietly excluded last spring won't protect you.

Microsoft ends the post by saying risk-based security management remains the foundation. With Patch Tuesday counts this high, that kind of risk-based prioritization is the only workable way to handle the volume.

 

References

  1. CISO perspectives on managing vulnerability risks in the age of AI Microsoft Security Blog 2026-10-06T16:00:00+00:00
  2. Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days bleepingcomputer.com
  3. Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days - SecurityWeek securityweek.com