AUTO-UPDATED

Microsoft Plugs Nearly 400 Security Holes

Microsoft has released security updates addressing 398 vulnerabilities in Windows and related software, including one actively exploited zero-day flaw, as AI-driven discovery continues to increase monthly patch volumes.

Key Points

  • Microsoft issued 398 security fixes this month, with 42 vulnerabilities rated as critical.
  • The update addresses CVE-2026-68820, a privilege escalation zero-day flaw found in the Windows afd.sys driver.
  • Two additional vulnerabilities, CVE-2026-62832 and CVE-2026-72971, were publicly disclosed prior to the official patch release.
  • Security experts attribute the rising volume of discovered flaws to the increased use of artificial intelligence in vulnerability research.
  • Research from 1Password indicates that AI-generated patches often fail to resolve issues or introduce new security weaknesses, necessitating human oversight.

Why it Matters

The surge in AI-assisted vulnerability discovery is forcing organizations to manage significantly higher patch volumes, complicating standard IT maintenance workflows. While AI excels at identifying security gaps, the current reliance on human verification remains critical to ensure that automated fixes do not destabilize production environments.
Krebs on Security Published by BrianKrebs
Read original