www.microsoft.com 7 Oct 2026, 16:00 UTC

Microsoft’s AI Research Uncovered 140 Windows Vulnerabilities and Spurred Linux Fixes

Microsoft’s AI Research Uncovered 140 Windows Vulnerabilities and Spurred Linux Fixes
CyberSIXT Evidence Panel Source marked as original reporting

MICROSOFT’S FORGE Lab reports three design-ready lessons on how AI-assisted vulnerability research scales beyond initial discoveries into real-world fixes. From May to September 2026, the team helped identify Windows vulnerabilities amounting to 140 CVEs, with 52 addressed in September’s security release.

The effort also spanned open-source software, submitting 155 internally validated reports across 23 projects, and achieving maintainer acknowledgement in 93 instances; among publicly disclosed examples are CVE-2026-9545, CVE-2026-13608 (curl), CVE-2026-56848 (Node[.]js), and CVE-2026-64563 (Linux kernel). A notable outcome through Akrites was the Linux kernel patch stemming from one of the Linux reports, underscoring coordinated vulnerability disclosure in critical open-source software.

The article details three shifts to sustain vulnerability research at scale: moving from frontier capability to scalable pipelines; transitioning from token-based throughput to reasoning economics, where cost and evidence quality guide each step; and treating validation and remediation as a continuous loop that feeds back into discovery.

The Forsage MDASH framework is used to organise multi-model scanning, with automated provers and harnesses generating reproducible evidence to accelerate fixes while reducing human triage. Measured costs for automated validation in Linux kernel work are presented (e.g., PoC generation averaging USD 3.61 and 21.5 minutes; local privilege-escalation testing around USD 8.56 and 25.4 minutes for selected cases).

The piece concludes that the next advance will hinge on integrating frontier capability with scalable systems engineering and repeatable remediation, not solely on model power.

View full article

Article by CyberSIXT