This could be the “new normal” for 2026 and beyond, with monthly totals climbing sharply since mid-year.
This would require there to constantly be security flaws to patch. Sure, vulnerabilities are inevitable, but steps can be taken proactively to avoid them, and no operating system (most of these vulnerabilities were in Windows) should be introducing an uncontrolled stream of constant vulnerabilities (in many cases against the user’s wishes).
Anyway, patching security holes is a good thing at least so long as the total surface area of holes actually decreases over time.
The new normal part of this is that AI is really good at identifying security vulnerabilities too obscure for any normal human to catch. Every major piece of software is having a massive increase in vulnerability discovery, and no one is seeing an indication that it’ll plateau once “all the bugs have been fixed”
Maybe every patch introduces 2 new vulnerabilities, so next update they can patch 2 more with 0 effort
999 bugs in the OS, take one down, patch it around, 1000 more bugs in the OS
And broke 900 functions…




