Back to news

Microsoft Patches Record 570 Flaws as Firefox Exploits Go Public

A historic Microsoft patch release and actively exploitable Firefox vulnerabilities are forcing IT teams into emergency update cycles this week.

Microsoft Patches Record 570 Flaws as Firefox Exploits Go Public

What happened

Microsoft issued fixes for 570 security vulnerabilities in its latest Patch Tuesday release — nearly triple the volume from the prior month, itself a record. The company credited AI-assisted vulnerability discovery as a key driver behind the surging patch counts. Simultaneously, Mozilla confirmed two critical Firefox flaws with publicly available exploit code: one involving an invalid pointer in the WebAssembly component (CVE-2026-15718) and another targeting site isolation in the DOM navigation layer (CVE-2026-15719). Adobe, Chrome, and VMware also pushed critical updates in the same window, compressing response time for security teams already stretched thin.

Why it matters for your business

Publicly available exploit code for the Firefox vulnerabilities means attackers no longer need sophisticated resources to weaponize these flaws — any employee browsing the web on an unpatched browser represents an open door. The sheer volume of Microsoft patches signals that AI tooling is accelerating the pace at which vulnerabilities are both discovered and disclosed, a trend that will only intensify pressure on patch management workflows. Organizations relying on manual or infrequent update cycles are increasingly mismatched against the speed of the threat landscape. The practical takeaway: prioritize Firefox and Windows updates immediately, and use this moment to audit whether your patch cadence can realistically handle a world where hundreds of fixes drop in a single week.

What to watch next

Microsoft has signaled that AI-aided discovery will continue to inflate vulnerability counts in future release cycles, meaning security teams should expect 500-plus-patch months to become normalized rather than exceptional. The Firefox situation also raises a broader question about browser security posture across distributed workforces, particularly where endpoint management is inconsistent. Watch for proof-of-concept exploitation activity tied to the Firefox CVEs in the coming days, as public exploit availability typically shortens the window between disclosure and active campaigns.

Sources

Want this kind of clarity applied to your own systems?

HashWhales can review your website, infrastructure, security posture, and growth bottlenecks, then send a prioritized action plan.

Free AuditChat on WhatsApp