Microsoft Patches a Record 570 Security Flaws

Microsoft Patches a Record 570 Security Flaws

AI is helping Microsoft find bugs faster than ever — but it's also arming the attackers racing to exploit them.

Written by OutOfToken AI

August 10, 2026 · 4 min read · Synthesized from reporting by Krebs on Security · How this works

AI Likely Accurate · 7/10

Microsoft shipped fixes for at least 570 security vulnerabilities today, nearly tripling the tally from its already record-breaking Patch Tuesday release last month. The company says artificial intelligence is behind the surge, with AI-assisted vulnerability discovery uncovering flaws that have sat dormant in Windows code for years.

The Numbers Keep Climbing

This month's release includes patches for several zero-day vulnerabilities already being exploited or publicly disclosed before a fix existed, according to multiple reports. The batch covers critical remote code execution bugs alongside a long tail of lower-severity issues across Windows and other Microsoft products. The 570 figure marks a dramatic jump from June's total, which had already set a record at the time.

Microsoft Points to AI

Windows chief Pavan Davuluri attributed the ballooning patch counts directly to AI-powered vulnerability research, telling reporters that customers should expect larger security releases as AI helps defenders find more issues. Much of Windows' codebase dates back decades, and researchers are now using AI models trained specifically on cybersecurity tasks to comb through that legacy code for flaws that manual review missed.

"Microsoft's July patch batch is nearly triple the size of June's release — which itself broke records just weeks earlier."

A Double-Edged Sword

Not everyone views the AI-driven bug hunt as an unambiguous win for defenders. Satnam Narang of Tenable has argued that the same AI capabilities helping Microsoft find flaws are also letting attackers generate exploits for known vulnerabilities faster than before. He points to this cycle's SharePoint zero-day, initially rated as less likely to be exploited, as an example of how Microsoft's own severity scoring may be lagging behind the speed at which AI-assisted attackers can now operationalize a bug.

If AI is genuinely accelerating vulnerability discovery on both sides of the fight, the era of predictable, manageable Patch Tuesdays may be ending. Security teams already strained by monthly patch cycles now face the prospect of triple-digit — or higher — vulnerability counts becoming routine, with attackers weaponizing disclosures on a compressed timeline. How Microsoft recalibrates its exploitability ratings in response will be worth watching closely.

Editorial Note

The research strongly confirms the core claims about the 570 patch release and AI's role in vulnerability discovery. However, discrepancies exist regarding the exact number of zero-days (two vs. three), and the specific comparison to June's patch count cannot be fully verified from the sources. The security expert skepticism cited is accurately represented in the research.

Claim Tracker

AI-assessed

VerifiedMicrosoft released 570 security vulnerabilities in the patch release discussed

Confirmed by Source 1 (TechRepublic), Source 2 (LinkedIn), Source 3 (TechCrunch), Source 4 (Grand Linux), and Source 6 (Techzine).

DisputedThis month's release included several zero-day vulnerabilities already being exploited or publicly disclosed

Source 1 and Source 2 specify three zero-days, while Source 5 mentions two zero-days. The article states 'several' without a specific count, and sources contradict the exact number.

UnverifiedJuly's release is nearly triple the size of June's release

Research confirms July 2026 had 570 patches and that June was a prior record-breaking month, but the exact June figure and the 'triple' comparison are not provided in the research sources.

VerifiedMicrosoft attributed the surge in patch counts to AI-assisted vulnerability discovery

Confirmed by Source 3 (TechCrunch), which quotes Windows chief Pavan Davuluri on this point, and Source 4 (Grand Linux).

VerifiedSatnam Narang of Tenable argues that AI capabilities are also letting attackers generate exploits faster than before

Source 6 (Techzine) corroborates this argument, noting Narang's position that 'AI models can generate exploits for known vulnerabilities at an ever-faster rate.'

Ask AI about this story

// discussion

sign in to join the discussion