If you run a critical system on Windows - whether it's an AI system, CRM, or automation - you need a testing process before every update. Installing directly in production can break integrations. Set up a small test environment, define a regular maintenance window, and ensure you have rollback capability. If you lack resources for this, at minimum maintain daily automated backups before any update.
Microsoft released security updates on September 8, 2026 for 974 vulnerabilities in Windows and other software - the largest batch the company has ever issued. 113 of the vulnerabilities were rated critical, and two zero-day vulnerabilities are actively exploited in the wild: CVE-2026-81963 and CVE-2026-85880, both enabling privilege escalation. Microsoft attributes the increase in discovered vulnerabilities to the use of AI for code scanning.
Unprecedented volume
The total number of vulnerabilities patched in 2026 so far stands at over 2,600 - double the previous record set in 2020. The increase does not necessarily indicate declining code quality, but rather improved detection capability using AI tools.
For an organisation running production systems, these numbers translate to a real operational problem. Every update requires testing against third-party software, existing integrations, and the specific production environment. Blind installation can break critical systems in the middle of a working day.
Two active vulnerabilities require immediate attention
The two actively exploited zero-day vulnerabilities allow an attacker to escalate privileges on the system. This means that even if the attacker enters with limited permissions, they can become a system administrator. Organisations running AI systems or automation on Windows need to prioritise this update.
The problem is that immediate updating is not always possible. A system that processes sensitive data, integrates with external systems, or depends on specific libraries may break after an update. This is why large organisations maintain a separate testing environment.
What to do this week
If you run a critical system, set up a test environment - even if it’s just an additional computer with the same configuration. Install the update there, run the critical processes, and verify everything works. Only then move to production, in a planned maintenance window.
If you lack resources for a test environment, at minimum configure daily automated backup with a clear restore point. Make sure you know how to roll back to a previous version if something breaks. It’s not perfect, but it reduces risk.
For systems that integrate automation or AI, consider managed automation and security as part of routine operational process.
- Microsoft Plugs Nearly 1,000 Security Holes — Krebs on Security
Frequently asked
You cannot postpone indefinitely, but you can delay by days or weeks if you have a testing process. Updates that fix active zero-day vulnerabilities require immediate attention. If you lack a test environment, at minimum ensure you have a current backup before installation.
Run the most critical processes immediately after the update - logging into systems, sending documents, connecting to external systems. If something does not work, check Windows logs and the software's own logs. If you do not know how, that is a sign you need external help.
A short call, no commitment, and we will tell you whether it is relevant to your business or not.