CISO perspectives on managing vulnerability risks in the age of AI
Microsoft urges CISOs to patch faster as AI-driven scanning drives a surge in vulnerability disclosures.
Microsoft’s security blog says frontier AI models are flooding security teams with more vulnerability findings than human processes were built to handle. Microsoft uses AI inside validation harnesses to find and fix flaws, and said September 2026 Patch Tuesday approached 1,000 vulnerabilities, with most cloud issues mitigated without customer action. It advises more on-premises patching capacity, considering fixes for critical systems within 24 hours, defense in depth including Baseline Security Mode, and use of a customer-available scanning harness codenamed MDASH. Microsoft also described joint work with peers to scan and patch critical open-source components.