Microsoft warns: Don’t delay Windows 11’s update released today, confirms record security fixes as AI becomes a threat

Peer Networks UK Windows Latest Microsoft warns: Don’t delay Windows 11’s update released today, confirms record security fixes as AI becomes a threat

Microsoft has just released its September 2026 Patch Tuesday updates, with the movable taskbar being the talk of the town, but there’s more to the story than fancy features. 974 Microsoft CVEs (Common Vulnerabilities and Exposures) overall have been addressed this month, and that includes at least 723 known vulnerabilities across the Windows product family.

Based on my analysis, 611 unique security flaws map specifically to Windows 11 24H2 and 25H2. My 611 count does not include Windows Server, so including Windows Server raises it to 723. And when you consider all Microsoft products covered by the release, you’ve got a huge 974 figure.

Unless you use the PC offline, I don’t think you should delay security updates anymore, and my recommendation aligns with Microsoft’s recently updated guidelines.

In July 2026, Microsoft warned against delaying Windows updates, as AI-enabled threats are accelerating at an alarming rate.

Microsoft 365 director Jeremy Chapman noted that you should not delay quality updates like the September 2026 update by more than three days, and if the update has a zero- or one-day deadline, it has a grace period of no more than two days. If you put that simply, do not pause Windows updates!

Microsoft says bad actors are using AI to come after your vulnerable products

Microsoft previously warned IT admins that attackers have “ample time” to use AI and “find and exploit known security gaps” if you’re sitting on critical quality updates with security fixes for a “couple of weeks.”

“If you’re not delivering critical quality updates with security fixes until a couple of weeks after they’ve been issued, that’s ample time for attackers using AI to find and exploit known security gaps,” the Microsoft 365 director warned.

“To address this, we’ve updated our recommendations for deploying Windows updates to less than three days as the deferral period for quality updates, setting deadlines for those updates to zero or one day, and the update grace period to a maximum of two days.”

Jeremy Chapman, a director at Microsoft 365, shared the following security advisory for everyone, particularly IT admins:

Do not delay Windows 11’s September 2026 Update

Windows 11’s September 2026 Update is one security update I would not delay, as it fits Microsoft’s new recommendations.

In its Security Update Guide, Microsoft noted that the September 2026 security release consists of 974 Microsoft CVEs across its products. Tom Gallagher, Vice President of Engineering at the Microsoft Security Response Center (MSRC), also highlighted the 974 figure.

The 974 CVEs, which is the number Microsoft’s own security release quotes, include vulnerabilities in products such as Office, SQL Server, Azure, Exchange Server, SharePoint Server, and developer tools.

Some of these products obviously run on Windows, but Microsoft tracks their vulnerabilities separately from the Windows product family.

Of those, Microsoft lists 723 vulnerabilities as addressed under the Windows product family, which covers multiple versions of Windows and Windows Server. Based on my calculations, 611 unique CVEs map specifically to Windows 11 25H2 and 24H2. Server-only vulnerabilities are not included in the 611 figure.

September 2026 security fixes Count Explanation
Microsoft security release 974 Microsoft CVEs across all affected product families
Windows product family 723 Windows and Windows Server vulnerabilities
Windows 11 24H2 and 25H2 611 Unique CVEs that map to the September 2026 fixed builds for Windows 11 24H2 and 25H2

For the Windows 11 calculation, I looked at Microsoft’s CVE data and counted unique vulnerabilities that map to Windows 11 24H2 Build 26100.9445 and Windows 11 25H2 Build 26200.9445, delivered with KB5124008.

Microsoft security updates have exploded in 2026

The increase becomes clearer when you compare Microsoft’s own release-day CVE totals for each Patch Tuesday:

Month Microsoft CVEs in 2025 Microsoft CVEs in 2026 YoY
January 159 112 -29.6%
February 63 59 -6.3%
March 57 83 +45.6%
April 126 165 +31.0%
May 78 137 +75.6%
June 66 206 +212.1%
July 130 622 +378.5%
August 111 421 +279.3%
September 86 974 +1,032.6%
January-September 876 2,779 +217.2%

Note: I extracted these numbers from Microsoft’s security portal, and they include release-day CVE totals. The company can revise older entries after release, and the final numbers could end up being higher.

For the above table, I also added YoY growth for the bugs (why let only the company’s revenue growth get all the attention!). From January through September, Microsoft’s release-day CVE total climbed from 876 in 2025 to 2,779 in 2026, an increase of 217.2%.

September alone is up more than 1,000% year over year, and I can tell you with confidence that it’ll get worse in the coming months.

What does Windows 11’s September update actually fix?

Whether you look at Microsoft’s 974 security fixes or my Windows 11 24H2/25H2-only figure of 611, those are huge numbers, and they tell you that something is very wrong with the products we use in our daily lives.

The September security fixes reach some of the most fundamental parts of Windows, including Windows Update, Windows Hello, biometrics, and the Windows graphics stack:

CVE Windows component Type Meaning
CVE-2026-81963 Windows Update Stack Elevation of privilege Microsoft says exploitation has already been detected
CVE-2026-69784 Windows Hello Elevation of privilege Use-after-free vulnerability affecting Windows 11 24H2 and 25H2
CVE-2026-73017 Windows Graphics Kernel Remote code execution Could allow an authorized attacker to execute code
CVE-2026-83979 Windows Biometric Service Elevation of privilege Use-after-free vulnerability affecting the Windows biometric stack

For example, the most urgent security issue is labeled CVE-2026-81963, which is an elevation-of-privilege vulnerability in the Windows Update Stack.

In its advisory, Microsoft says the vulnerability is caused by improper link resolution before file access in the Windows Update Stack, which could allow an authorized local attacker to elevate privileges.

Why are Microsoft security updates getting so much larger?

Windows has not suddenly turned into a security disaster, and Microsoft anticipated that we’d all be highlighting these huge numbers, so it was prepared with a valid explanation.

In May 2026, Microsoft itself confirmed that Patch Tuesday updates would become larger in the coming months because reporting volume is climbing and the company’s in-house AI models have matured, so it’s able to find more bugs in a short span of time. It’s also because more researchers are now participating, and Microsoft is using AI to find bugs faster than ever.

At the same time, attackers are also using AI to find and exploit known security gaps faster. It’s a cat-and-mouse game, and Microsoft can’t afford to lose it, so it’s rapidly investing in its own AI models.

For example, the company revealed MDASH as its answer to AI threats.

“Codename MDASH is, at its core, an agentic vulnerability discovery and remediation system,” Microsoft explained and shared the following chart to explain the process:

MDASH in Windows 11

The post Microsoft warns: Don’t delay Windows 11’s update released today, confirms record security fixes as AI becomes a threat appeared first on Windows Latest