Microsoft’s latest Patch Tuesday update has plugged nearly 400 security vulnerabilities across its Windows operating systems and supported software, including one critical flaw that is already being actively exploited. The sheer volume of patches released by Microsoft has raised questions about whether artificial intelligence (AI) is truly effective in helping to identify and fix these vulnerabilities.
Of the 398 flaws addressed this month, a staggering 42 have been rated as “critical” by Microsoft, meaning they could be exploited remotely with little to no user interaction. The most notable of these is CVE-2026-68820, a privilege escalation weakness in Windows’ core component, afd.sys, which allows an attacker to gain control over a computer once they’ve already gained a foothold through phishing or other means.
Another publicly disclosed flaw, CVE-2026-62832, has been labeled as likely to be exploited due to its proximity to the recent “LegacyHive” public disclosure by bug hunter Nightmare Eclipse. While this vulnerability is also a privilege escalation issue, Microsoft estimates it’s unlikely to be exploited in the wild.
The increasing number of patches being released by Microsoft and other major software makers – including Adobe, Cisco, Google, Mozilla, and Oracle – has been attributed to the use of AI in vulnerability discovery. However, experts are still debating whether these technologies can accurately identify vulnerabilities, let alone effectively fix them.
A recent study by 1Password found that large language models (LLMs) were unable to generate patches for complex vulnerabilities more than half the time, either failing to fix the flaw or introducing new weaknesses instead. While some researchers, such as Ed Skoudis of the SANS Technology Institute, have reported excellent results using AI-generated patches with human oversight, others caution that relying solely on AI may not be reliable.
Tyler Reguly at Fortra notes that only one of the nearly 400 bugs addressed by Microsoft this month is known to be actively exploited. He advises security leaders to review their teams’ patching processes and ensure they’re adequately testing fixes before deploying them in production environments.
As the volume of patches released each month continues to grow, it’s clear that AI will play an increasingly important role in vulnerability discovery – but human oversight and testing will remain essential for effective patching. Security leaders would do well to prioritize iterative improvement and verification when using AI-generated patches, rather than relying on a single “one-shot” solution.
Ultimately, this month’s Patch Tuesday serves as a reminder that the cat-and-mouse game between attackers and defenders is far from over. As vulnerabilities continue to emerge at an alarming rate, it’s essential for organizations to remain vigilant in their patching efforts, leveraging AI tools when possible but always prioritizing human oversight and testing to ensure the integrity of their systems.
Source: Krebs on Security — 2026-08-11