Microsoft released patches for 570 security vulnerabilities on Tuesday as part of its regular monthly update cycle for Windows, Office and other product lines. The scheduled release, commonly called “Patch Tuesday” by security researchers, represents a record tally of fixes in a single update.
Two zero-days and an active SharePoint exploit
Among the disclosed flaws at least two are classified as zero-days, indicating they were exploited before Microsoft was notified. One of the bugs affects Windows Server and can allow attackers to escalate privileges from a limited user to a system administrator. Another vulnerability impacts SharePoint file-sharing servers; the U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that attackers were actively exploiting this bug to compromise organizations.
The reporting was first published by Krebs on Security.
Microsoft attributes increase to AI-assisted discovery
The large patch bundle comes one week after Microsoft said in a company blog post that it expects the typical monthly security update counts to rise. Microsoft explained the increase by noting that it is using artificial intelligence tools to help its engineers and security teams uncover previously undetected bugs in its software.
Pavan Davuluri, head of Windows, said: “As AI helps defenders discover more issues, customers will see a higher volume of security updates included in each security release.”
Why this matters
As AI models become more capable and are applied to cybersecurity research, they can surface vulnerabilities that have remained dormant in code for years. Some components of Microsoft’s Windows codebase date back decades, which can make long-standing flaws more likely to be found when automated or semi-automated techniques are applied.
While a higher volume of discovered issues can improve overall security by driving fixes, it also creates operational demands for organizations that must test and deploy a larger number of patches promptly to reduce exposure.
The size of this month’s update underscores how the dynamics of vulnerability discovery and exploitation are shifting as AI tools enter the security ecosystem.



