Microsoft Says Agentic AI Helped Identify 140 Windows Vulnerabilities
Microsoft says its security researchers used agentic AI to help identify Windows vulnerabilities assigned 140 Common Vulnerabilities and Exposures, or CVEs, between May and September. The company also submitted 155 internally validated reports across 23 open-source projects, showing how AI-assisted vulnerability research is moving into large-scale software security work.
In a report published October 7, Microsoft said its Frontier Offensive Research & Generative Exploitation, or FORGE, Lab worked across Windows, the Linux kernel and other open-source projects. Microsoft said 52 of the 140 Windows CVEs were included in the company’s September 2026 security release.
Microsoft also said one of its Linux findings became the first Akrites submission to result in a patch merged into the Linux kernel. Akrites, a Linux Foundation initiative, coordinates confidential remediation and disclosure for vulnerabilities in critical open-source software.
Why the research matters
Traditional security teams must review enormous codebases while attackers search for the same weaknesses. Microsoft says frontier AI can expand the amount of code researchers examine, but finding a flaw is only useful if engineers can reproduce, validate and fix it.
The FORGE Lab uses a multi-model agentic scanning harness called MDASH. Rather than relying on one model, MDASH coordinates specialized agents that analyze code, investigate suspected weaknesses, validate findings and help produce technical evidence. Microsoft’s earlier descriptions say the system can connect validated findings with Microsoft Defender, GitHub Advanced Security and Azure DevOps workflows.
That integration matters because an automated report can otherwise become another item in an overwhelmed security backlog. Microsoft says its process is designed to move a finding toward an owner, a code change and a released fix.
What organizations should do now
- Prioritize validation. Treat AI-generated findings as leads that require reproducible testing, severity assessment and human review.
- Connect scanning to engineering. Route confirmed vulnerabilities into the same code-review and work-tracking systems used for normal software changes.
- Strengthen open-source response. Maintain an inventory of critical dependencies and establish coordinated-disclosure procedures before a vulnerability is found.
- Measure remediation, not discovery. Track how quickly teams confirm, assign, patch and deploy fixes rather than counting raw scanner results.
MDASH is being used by Microsoft security engineering teams and tested by a small set of customers through a limited private preview. The broader lesson is available now: as AI increases the speed and volume of vulnerability discovery, security programs must improve their validation, coordination and remediation pipelines at the same time.
References
Kim, T. (2026, October 7). 3 lessons from frontier AI vulnerability research. Microsoft Security Blog. https://www.microsoft.com/en-us/security/blog/2026/10/07/3-lessons-from-frontier-ai-vulnerability-research/
Kim, T. (2026, May 12). Defense at AI speed: Microsoft’s new multi-model agentic security system tops leading industry benchmark. Microsoft Security Blog. https://www.microsoft.com/en-us/security/blog/2026/05/12/defense-at-ai-speed-microsofts-new-multi-model-agentic-security-system-tops-leading-industry-benchmark/
Kim, T. (2026, June 17). Beyond the benchmark: Advancing security at AI speed. Microsoft Security Blog. https://www.microsoft.com/en-us/security/blog/2026/06/17/beyond-the-benchmark-advancing-security-at-ai-speed/
