AI Pulse by Inblix

Microsoft patches record 570 flaws after AI uncovers hidden bugs

TechCrunch AI · Jul 15, 2026 · 2 min read · Read original article →

Curated by the Inblix editorial team


Featured image for article: Microsoft patches record 570 flaws after AI uncovers hidden bugs

Microsoft dropped its largest-ever Patch Tuesday this week, shipping fixes for a staggering 570 security vulnerabilities across Windows, Office, and its broader product stack. That’s not a typo. The mountain of patches — roughly double what the company typically releases — comes directly after Microsoft admitted its internal use of AI tools is now surfacing bugs that humans missed, some of which have likely been sleeping in code for years.

The haul includes at least two zero-days that were already being exploited in the wild before Redmond caught wind of them. One is a privilege escalation flaw in Windows Server that lets a limited user become a system administrator. The other hits SharePoint, and it’s bad enough that CISA — the U.S. government’s cybersecurity agency — is warning organizations that attackers are actively using it to break in. That kind of federal nudge usually means someone important already got burned.

Windows chief Pavan Davuluri didn’t sugarcoat what’s coming. “As AI helps defenders discover more issues, customers will see a higher volume of security updates included in each security release,” he said in a blog post last week. The implication is clear: this isn’t a one-time flood. If your IT team thought patch cycles were already painful, they should brace for a new normal where hundreds of fixes per month becomes routine.

The AI angle here is genuinely double-edged. On one hand, models are finally good enough at pattern-matching to spot subtle memory corruption bugs and logic flaws in sprawling codebases — parts of Windows date back to the 1990s. That’s a win for defense. On the other hand, the sheer volume of newly discovered vulnerabilities raises an uncomfortable question: how long have these flaws been sitting there, and who else — besides Microsoft’s AI — might have already found them?

💡 Key Takeaways

  1. Microsoft's internal AI tools are now unearthing vulnerabilities at a rate that dwarfs human-led discovery, directly causing the largest patch release in company history.
  2. Two of the 570 flaws are confirmed zero-days already exploited in the wild, including one SharePoint bug serious enough to trigger a CISA warning.
  3. This signals a permanent shift in patch volume, not an anomaly — IT teams should expect significantly larger monthly updates going forward.

Keep reading: See related articles below for more coverage on this topic.

Get smarter about AI

The sharpest AI news, curated daily. Delivered free to your inbox.

Learn more

Glossary terms

← Back to all articles