Skip to content

Product1 publisher3 min readPublished

Microsoft's record 974 patches are one month inside a year that has logged 66,401 CVEs

The year's CVE tally has reached 66,401, close to double where it stood last September, and Microsoft alone patched 974 in a single month. Jerry Gamblin, who keeps the count, says more known bugs is mostly the system working.

The Product Desk · Product desk

Illustration accompanying Microsoft's record 974 patches are one month inside a year that has logged 66,401 CVEs

What happened

  • Microsoft said last week that it had issued patches for 974 CVEs so far this month, a record for the company.
  • Google Chrome's two major version releases in June included 1,072 patches, more than all the vulnerability fixes shipped across the previous 23 big releases combined.
  • Jerry Gamblin's cve.icu project had recorded 66,401 CVEs as of Wednesday this week, against 33,512 by September 16 last year and 25,000 for the whole of 2022.

Compiled by The Product DeskSomething wrong?How this is made

Why it matters

  • constraint Remediation capacity is set by headcount, so a doubled inbound count lengthens the wait before any given fix reaches production. The count of fixes applied does not move.
  • contradiction Wired reports an explosion in findings while Gamblin, who runs the count, calls the larger number mostly the system working; reading it as risk or as inventory leads to different hiring.
  • cost Part of the triage bill falls on unpaid open source maintainers who sit outside the org chart of every company depending on their code.
  • decision A quarterly patch window sized for 309 Oracle fixes now has to be replanned or the backlog carries into the next one.

Microsoft's 974 fixes come to about 32 CVEs a day across one vendor's products, dividing by a 30-day month [19]. Whoever owns that list reads and sorts it before a single patch is applied, and the sorting is done by people on payroll.

The year-scale numbers move the same direction. cve.icu logged 66,401 CVEs as of Wednesday against 33,512 by September 16 last year, 32,889 more, or 1.98 times the total at roughly the same date [5][6][17]. Oracle's July release, 1,448 patches against 309 in July 2025, is 4.7 times the size [2][18]. In 2022, the year ChatGPT first shipped, cve.icu recorded 25,000 CVEs for the full twelve months, so this year is already at 2.7 times that [7][20].

Gamblin, who keeps the tally, does not read the number as a danger reading. "I don't think it's overblown," he said of the apparent explosion in findings across the industry [8]. He added: "What I would push back on is the idea that a bigger number is itself the harm. More CVEs is not more vulnerability. It's more known vulnerability, which is mostly the system working." [9]

That distinction decides who you hire. A known flaw in software you do not run is inventory. A known flaw in a library you ship is work, and Britain's National Cyber Security Centre states the limit: "Just finding vulnerabilities does nothing to improve your security." [11]

Wired's Kernel Panic newsletter says the surge is straining the volunteers who maintain crucial open source software and piling pressure on under-resourced IT and security teams [10], without putting a number on the volunteer load [21]. The maintainer who triages your upstream dependency sits outside your headcount, and you do not control that person's schedule. Mozilla's April sprint, 271 Firefox vulnerabilities found using Anthropic's Mythos model, shows how quickly one team can fill somebody else's queue [4].

On the attacker side the evidence is thinner than the discovery counts. Matthew Olney, director of threat intelligence at Cisco Systems, said: "Actors, just like industry, are trying to figure out, 'where do I use AI?'" [12] Researchers told Wired there is at least a tenuous balance between AI speeding up bug discovery and AI helping defenders [14].

The sort that matters runs on two facts: whether the affected code is reachable in something you actually run, and whether the fix can ship without cutting a release. Reachable and shippable is this week's work. Reachable and release-gated is the cell that needs staffing, because your release calendar sets that pace. Unreachable and shippable batches with the next routine update. Unreachable and release-gated goes in a register with a note on what would make it reachable.

Gamblin said discovery scales with compute while remediation scales with people, and people are the part you cannot buy more of in a quarter [13].

What to watch

  • Whether Microsoft's next monthly total holds above 974 or the record turns out to be one unusual batch.
  • Whether cve.icu's year-end figure lands near double 2024, which sets the triage baseline teams plan against.
  • Whether any vendor publishes remediation-side numbers, such as mean time to patch or maintainer counts, to sit beside the discovery totals.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories