For those of you who monitor vulnerabilities, either for your job or as an ancillary part of your job like me, the July 2026 Patch Tuesday updates from Microsoft hit like a ton of bricks. In those updates, Microsoft fixed a record 570 vulnerabilities in its software. Fifty-nine of those were listed as Critical vulnerabilities, and three patches fixed zero-day vulnerabilities.
When something like that is reported, speculation usually turns to why such a large number of issues and vulnerabilities has been identified. There’s no way to know exactly, but one of the likely culprits is AI.
It’s in the AI
No matter your stance on AI, it’s becoming a major player in software development and in finding bugs and vulnerabilities. In a survey by Stack Overflow, 84% of developers are using or planning to use AI, and nearly half of them use AI daily. 20% of developers responded to Stack Overflow saying that they use AI to debug or fix code. There are obviously no metrics on how many people are using AI to attempt to find and exploit vulnerabilities, but GitHub did announce that they identified 170,000 issues over a 30-day period with internal testing. They also said that developer feedback was 80% positive on the findings generated. Suffice it to say AI is being used to develop and remediate code.
It’s a race
With the large number of vulnerabilities being identified and remediated, it’s become a race between how fast an issue is discovered and how quickly the developer can update their software to fix the problem. Recast has even seen the velocity of updates increase in our own Setup Store data. Setup Store is where both Recast Right Click Tools Patching and Application Workspace get their update data. This proprietary database tracked a 341% increase in Common Vulnerabilities and Exposures (CVEs) in the first half of 2026, from 477 in Q1 to 2,102 in Q2. This data includes third-party applications and doesn’t just affect OS components. The increase is across all the software that you have in your environment.
You’re part of this race too. It’s time to go fast.
With the velocity of vulnerabilities and patches becoming more frequent, it has become a liability to sit on the sidelines. What used to be standard practice, waiting for a specific time in the month to deploy all the patches that have built up since the last time you patched, could leave security gaps with the increasing speed of vulnerability discovery. In fact, the US Cybersecurity and Infrastructure Security Agency (CISA) recommends that vulnerabilities should be remediated within three days if they are:
- Internet facing
- Actively exploited
- An exploit that can be automated
- Capable of giving attackers control of systems
How do I get updates out there quickly?
Low-risk updates that don’t need extensive testing need to be deployed as soon as possible. Updates that need testing should be verified as soon as possible so they can be deployed quickly.
Software like Recast Right Click Tools Patching and Application Workspace can help automate the process. These solutions will update with the newest versions of software as soon as they become available, and you can either send the update out immediately (and even automate it if you want), or manually start deployments, whatever works best for your environment.
The best part of the automated process is that it can happen in the middle of the night when a new update drops. It doesn’t matter if it’s a holiday, or a day that your whole patching team has taken the day off. It can start the process of getting updates into your environment without interaction. Waiting even a couple of days to start remediating a vulnerability could make the difference between an exploit being used or having it patched.
Brave new world?
The old days of not patching third-party applications have been over for a long time. With the new influx of AI-related updates, the time for once-a-month patching is over as well. As AI-discovered vulnerabilities increases, organizations need to make sure that they are patching as soon as possible.