Microsoft has released security updates addressing 398 vulnerabilities in Windows and related software, including one actively exploited zero-day flaw, as AI-driven discovery continues to increase monthly patch volumes.
Key Points
- Microsoft issued 398 security fixes this month, with 42 vulnerabilities rated as critical.
- The update addresses CVE-2026-68820, a privilege escalation zero-day flaw found in the Windows afd.sys driver.
- Two additional vulnerabilities, CVE-2026-62832 and CVE-2026-72971, were publicly disclosed prior to the official patch release.
- Security experts attribute the rising volume of discovered flaws to the increased use of artificial intelligence in vulnerability research.
- Research from 1Password indicates that AI-generated patches often fail to resolve issues or introduce new security weaknesses, necessitating human oversight.