Microsoft Patch Tuesdays are getting bigger.
In a blog post published July 9, Windows and Devices EVP Pavan Davuluri explained that AI is now helping Windows engineers find security flaws that used to sit undiscovered in the code for years, and that customers should expect more updates in every release as a result. Davuluri framed the higher volume as evidence that defenders are getting better at their jobs, and five days later, on July 14, Patch Tuesday backed him up. Windows shipped fixes for 570 vulnerabilities, the largest single Patch Tuesday release on record, and outlets tracking the totals noted Microsoft has now patched more than 1,300 vulnerabilities across its products in the first seven months of 2026 alone, nearly double the pace from the same period a year earlier.
How MDASH Works
The engine behind a lot of this is a system Microsoft calls MDASH, a multi-model agentic scanning harness that runs several AI models, including third-party ones, against Windows binaries at scale. Microsoft describes a validation step it calls multi-model debate, where findings get cross-checked across model families before a human engineer ever looks at them. A person still decides what gets fixed and how. What’s changed is how much gets put in front of that person to begin with.
This Isn’t Just A Microsoft Story
To be fair, Windows isn’t an outlier here. It’s an early, visible example of where the rest of the industry is headed. In that same July stretch, Google fixed more than 460 flaws in Chrome and Edge, and Adobe moved from a monthly to a twice-monthly patch cadence to keep up with its own release volume. Mayuresh Dani, a research manager at Qualys, told Infosecurity Magazine the trend was predictable, driven by AI-assisted fuzzing and automated variant hunting turning up bugs faster than most organizations can remediate them, and he expects the volume to keep climbing before it eventually levels off as the AI models mature. His advice to security leaders was to stop treating patch volume as a monthly surprise and start funding it as a fixed, ongoing cost, because the intake isn’t shrinking anytime soon.
That’s the operational reality every IT and security team needs to plan around, not just for Windows, but for every vendor in the stack that starts running AI against its own codebase.
What Researchers Are Watching
Amol Sarwate at Cohesity told TechRepublic that packing this many high-severity, remotely exploitable bugs into a single release is testing the limits of the standard CVSS-plus-severity model a lot of teams still use to decide what gets patched first. And Satnam Narang at Tenable flagged a detail worth tracking closely, since so many security teams lean on Microsoft’s own guidance to set priority: Microsoft’s exploitability index, according to Krebs on Security, initially rated this month’s SharePoint zero-day as “less likely” to be exploited. It landed on CISA’s Known Exploited Vulnerabilities list a short time later. That’s less a knock on Microsoft’s process and more a sign that the tools built to help teams triage need to evolve at the same speed the discovery side already has.
The Tools Microsoft Is Offering To Help
To Microsoft’s credit, the July 9 post doesn’t just warn customers and walk away. It lays out several tools meant to help absorb the added volume without sacrificing stability.
- Security Update Validation Program (SUVP) is Microsoft’s internal and partner-driven testing pipeline that vets patches against a wide range of real-world hardware and software configurations before they ship broadly, which is meant to catch the kind of update-breaks-something problem that makes IT teams gun-shy about patching quickly in the first place.
- Known Issue Rollback (KIR) lets Microsoft or an administrator revert a specific problematic change, feature, or fix without uninstalling the entire update it shipped in. That matters more than it sounds like, because it means a team that hits a bad interaction from one patch doesn’t have to strip out every other fix in that release to fix it, which used to be the tradeoff.
- Hotpatching through Azure Arc lets Windows Servers take certain security updates without a reboot, managed at scale through Azure Update Manager. For a shop running servers that can’t just go down for patching every time Microsoft ships one, that’s the difference between staying current and falling three releases behind because nobody could find a maintenance window.
Microsoft also points to Microsoft Defender Vulnerability Management and Intune insights to help teams see what’s still exposed and prioritize accordingly, plus Conditional Access and security baseline policies that can harden a device or restrict its access when a patch can’t be applied right away.
What This Means For Security Teams
None of this is really about whether Microsoft did the right thing. It did. Finding vulnerabilities that have been sitting in a codebase for years, sometimes decades, and fixing them before an attacker does is exactly what defenders are supposed to be doing, and AI is clearly making that faster.
What this really is, though, is an opportunity. IT security teams already couldn’t keep pace with the existing volume of vulnerabilities and patches, well before AI started finding more of them. So scaling up the same process, with more people or more point tools doing more of the same work at a higher volume, seems like a plan doomed to fail before it starts. If Dani and the others tracking this trend are right that every vendor is headed toward the same AI-assisted discovery curve Microsoft just hit, then the moment calls for organizations to step back and rethink how vulnerability and patch management actually works, rather than just turning up the dial on a process that was already behind.
- Record-Breaking Patch Tuesday Is A Sign It’s Time To Rethink The Process - July 26, 2026
- ‘Pompeii: Out of Time’ Series Reframes History as Survival Story - July 21, 2026
- Most AI Problems Are Really Capitalism Problems - July 19, 2026



