메뉴
BL
Ars Technica • 17일 전

마이크로소프트 9월 패치, 사상 최대 규모…972개 취약점 수정

IMP
8/10
핵심 요약

마이크로소프트가 9월 월간 패치에서 약 972개의 취약점을 수정하며 사상 최대 기록을 갱신했고, 이 중 112개는 치명적(Critical) 등급입니다. AI 기반 취약점 발견과 공격이 폭증할 것이라는 업계 경고에 따라 패치 대량 릴리스가 '새로운 일상'이 되고 있습니다. 이번 패치에는 이미 악용 중인 제로데이 2개와 웜형 확산이 가능한 취약점 20여 개가 포함되어 있어 신속한 적용이 중요합니다.

번역된 본문

마이크로소프트의 9월 패치는 어마어마한 규모입니다. 약 972개의 취약점이 수정되었으며, 그중 112개는 높은 치명적(Critical) 심각도 기준을 충족합니다. 단 두 달 전만 해도 마이크로소프트는 당시 최대 기록이던 570개의 취약점을 패치했습니다. 그리고 지난달에는 약 620개를 패치했습니다. 구글을 비롯한 다른 기업들도 최근 몇 달간 기록적인 수의 취약점을 공개했습니다.

2주 전에는 OpenAI, Anthropic, 아마존 웹 서비스(AWS), 구글, 마이크로소프트 등 100개 기업과 단체가 공개 서한을 발표하며, 취약점을 우선적으로 능동적으로 악용하는 AI 기반 공격의 해일이 예상되는 가운데 패치를 적용할 수 있는 시간 창이 좁아지고 있다고 경고했습니다. 업계는 소프트웨어에 전례 없는 수의 패치를 쏟아내며 이 위협을 심각하게 받아들이고 있습니다.

새로운 일상

제로데이 이니셔티브(Zero Day Initiative)의 연구원 더스틴 차일즈는 이러한 급증을 '새로운 일상(new normal)'이라 부르며, 그럼에도 불구하고 AI 보조 공격으로 인해 발생할 수 있는 피해는 결국 상당할 수 있다고 경고했습니다. 차일즈는 화요일에 이렇게 썼습니다. "한편으로는 이런 속도로 버그를 패치할 수 있는 마이크로소프트의 보안 요정들에게 축하를 보낸다. 다른 한편으로는 AI 보조 취약점 발견이 느려질 기미를 보이지 않는다. 다만 아직까지는 실제 악용 사례의 상응하는 급증은 확인되지 않았다."

마이크로소프트의 월간 패치에서 수정된 취약점의 정확한 수를 세는 것은 결코 정확한 과학이 아닙니다. 어떤 경우에는 버그가 이전에 이미 수정되었거나 마이크로소프트 외 제품에 영향을 미치는 것들이었습니다. 차일즈의 집계로는 화요일 릴리스는 972개의 취약점을 패치했으며, Edge에 통합된 크로미움(Chromium) 브라우저 수정 사항을 포함하면 997개입니다. 새로운 취약점 중 112개는 치명적(Critical) 등급이며, 나머지는 중요(Important) 등급입니다.

올해 들어 마이크로소프트는 이미 2,760개의 취약점을 수정했으며, 이는 작년 전체보다 두 배 이상 많은 수치입니다. 이 속도라면 마이크로소프트는 연말까지 2023년, 2024년, 2025년 전체를 합친 것보다 더 많은 버그를 수정하며 해를 마무리하게 됩니다.

이번 달 릴리스의 주목할 만한 취약점으로는 윈도우 업데이트 서비스와 윈도우 고급 로컬 프로시저 콜의 제로데이 두 개, CVE-2026-81963과 CVE-2026-85880이 있습니다. 이들을 누가 악용하고 있으며 얼마나 광범위한지에 대한 공개 정보는 없습니다.

차일즈가 지적한 다른 주목할 만한 취약점은 다음과 같습니다.

  • CVE-2026-55007 (Exchange Server): 인증 없는 원격 공격자가 악성 Visio 첨부파일이 포함된 이메일을 보내는 것만으로 영향을 받는 Exchange 서버에서 코드 실행을 할 수 있습니다.
  • CVE-2026-80097 (마이크로소프트 Authenticator): 로컬 권한 상승 취약점입니다. 차일즈는 "인증 시스템 자체의 버그를 이용하는, 가장 나쁜 유형의 권한 상승"이라고 말했습니다.
  • CVE-2026-69465: 마이크로소프트 오피스 SharePoint의 원격 코드 실행을 허용하는 약 17개의 개별 취약점입니다.
  • CVE-2026-65669: 이번 달 공개된 SQL Server 권한 상승 취약점 60개 중 하나로, 사용자가 SQL Copilot을 통해 명령을 제출할 때 악용됩니다.
  • CVE-2026-69525: 심각도 9.8점의 원격 데스크톱 서비스 원격 코드 실행 취약점입니다.

이 연구원은 화요일 공개된 취약점 중 웜형(wormable) 취약점이 너무 많아 20개를 세다가 집계를 멈췠다고 밝혔습니다. 이러한 취약점은 악용에 사용자 개입이 전혀 필요하지 않아 스스로 머신에서 머신으로 전파될 수 있으며, 멈추기 어려운 연쇄 반응을 일으킬 수 있습니다.

AI 보조 취약점 발견의 효과성은 논쟁이 많습니다. 비판자들은 대규모 언어 모델(LLM) 사용 시 비용과 오탐(false positive)의 수에 의문을 제기합니다. 또한 결함을 발견하고 패치하는 데 사용되는 바로 그 AI 엔진을 개발에 수십억 달러를 쏟아부은 투자금을 회수하려는 기업들의 동기에도 의문을 제기합니다. 반론은 그 결과물, 즉 AI 보조 발견이 기록적인 수의 취약점을 찾아내고 있다는 점입니다.

원문 보기
원문 보기 (영어)
Text settings Story text Size Small Standard Large Width * Standard Wide Links Standard Orange * Subscribers only Learn more Minimize to nav Microsoft’s patch for September is a doozy, with a record number of roughly 972 vulnerabilities fixed and 112 of them meeting the high critical-severity threshold. It was only two months ago that Microsoft patched a then-record 570 vulnerabilities. Then, last month, Microsoft patched some 620 of them. Google and other companies have also published record numbers of vulnerabilities in recent months. Two weeks ago, OpenAI, Anthropic, Amazon Web Services, Google, Microsoft, and 100 companies and organizations published an open letter warning of a narrowing window for patching vulnerabilities ahead of an expected tsunami of AI-enabled attacks that actively exploit them first. The industry is taking the threat seriously by pumping out unprecedented numbers of patches in their software. Welcome to the new normal Dustin Childs, a researcher at the Zero Day Initiative, calls the spikes the “new normal” and also cautions that despite them, the damage that’s likely to result from AI-assisted attacks could eventually be substantial. “On the one hand, congrats to the security gnomes at Microsoft for being able to patch bugs at this rate,” Childs wrote Tuesday . “On the other hand, AI-assisted vulnerability discovery shows no signs of slowing down. However, we have not seen a correlating spike in active exploits—yet.” Counting the precise number of vulnerabilities fixed in a monthly patch release for Microsoft is never an exact science. In some cases, the bugs were previously addressed or affected non-Microsoft products. By Childs’s count, Tuesday’s release patches 972 vulnerabilities, and 997 when counting the porting of fixes for the Chromium browser incorporated into Edge. Of the new vulnerabilities, 112 of them are rated critical, with the remainder carrying the important designation. Already this year, Microsoft has fixed 2,760 vulnerabilities, more than double the number from last year. At this rate, Microsoft will complete the year having fixed more bugs than all of 2023, 2024, and 2025 combined. Notable vulnerabilities in this month’s release include two zero-days, CVE-2026-81963 and CVE-2026-85880 in the Windows update service and the Windows Advanced Local Procedure, respectively. There’s no public information about who is exploiting them or how broadly. Other notable vulnerabilities Childs called out are: CVE-2026-55007 in Exchange Server. A remote, unauthenticated attacker could get code execution on an affected Exchange server by doing nothing more than sending an email with a malicious Visio attachment. CVE-2026-80097: A local privilege escalation in Microsoft Authenticator. “This is the worst type of privilege escalation as it uses a bug in the authentication system itself,” Childs said. CVE-2026-69465: Roughly 17 distinct vulnerabilities in Microsoft Office SharePoint allowing remote code execution. CVE-2026-65669: One of 60 SQL Server privilege escalation vulnerabilities this month. This particular one is exploited when a user submits instructions through SQL Copilot. CVE-2026-69525: A remote code execution flaw in Remote Desktop Services with a 9.8 severity rating. The researcher said he found so many of Tuesday’s vulnerabilities that were wormable that he stopped counting at 20. These vulnerabilities don’t require any user interaction to be exploited and hence can spread from machine to machine on their own, triggering a possible chain reaction that’s difficult to stop. The effectiveness of AI-assisted vulnerability hunting is filled with controversy. Critics question the expense and number of false positives when using LLMs. They also question the motives of companies trying to recoup the billions of dollars they’re pouring into developing the very AI engines being used to find and patch the flaws. The counterargument is that the results—AI-assisted hunting finding record numbers of severe bugs across the industry—speak for themselves. Mozilla, for instance, said in May that its researchers using Mythos found a record 271 vulnerabilities, with almost none of them being false positives. The true, long-term effectiveness of AI-assisted bug hunting won’t be known for a time that will likely be measured in a year or more. What’s clear now is that critics should maintain curiosity and remain open to the possibility that vulnerability discovery has entered a new and unprecedented phase. Skeptics who discount the possibility do so at their own peril. Dan Goodin Senior Security Editor Dan Goodin Senior Security Editor Dan Goodin is Senior Security Editor at Ars Technica, where he oversees coverage of malware, computer espionage, botnets, hardware hacking, encryption, and passwords. In his spare time, he enjoys gardening, cooking, and following the independent music scene. Dan is based in San Francisco. Follow him at here on Mastodon and here on Bluesky. Contact him on Signal at DanArs.82. 24 Comments