When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works.

Microsoft is reportedly struggling to patch the flood of AI-discovered security bugs as Mythos uncovers flaws faster than teams can fix them.

Usama Jawad

Neowin
·

Jul 30, 2026 10:16 EDT

A Windows 11 logo surrounded by bugs

This month’s Patch Tuesday updates fixed a colossal 570 bugs across Windows 10 and Windows 11. However, Microsoft says that we should accept this as the new norm as it is integrating specialized AI tools in its Windows development pipeline in order to detect bugs. There were also rumors that Microsoft could be prepping an in-house tool in this regard, but details in this space are a bit scarce right now. Now, reports claim that Microsoft is struggling to fix software bugs quickly as there are just too many.

Citing an internal Microsoft meeting recording from mid-May, news outlet ProPublica claims that the sentiment at the firm is that Anthropic’s Claude Mythos Preview model has lived up to the hype. For those unaware, this model was privately released to 40 of Anthropic’s partners in an effort to boost the security posture of various products before they become known to malicious actors. It was distributed to Microsoft, Google, Apple, Amazon, and more under the Project Glasswing umbrella.

However, the integration of Mythos in software quality pipelines has introduced a new problem for Microsoft. Some might deem it as a good-to-have problem, but the situation is a bit more complicated. Essentially, Mythos is detecting hundreds of bugs, and the engineering team just doesn’t have the resources to fix them as soon as possible. For example, in April, Mythos discovered 90 critical and 141 important bugs in SharePoint alone.

In response, Microsoft’s engineering managers have been urging their teams to fix as many bugs as possible, with critical and important issues being prioritized. The slides shown during the meeting indicated that the firm would eventually tackle moderate severity flaws, but there was no mention of low severity security holes. The indication during the presentation was that the engineering team would be busy handling important security gaps for months, until August.

There are a few problems to understand here. The first is that this presentation shared statistics related only to SharePoint. Microsoft has a lot of major software products, including Windows, so the resource strain may be happening across the entire firm. The meeting also referenced hundreds of other discovered bugs across Teams, Microsoft 365, and Copilot which were yet to be patched.

Another problem is that just because a flaw is medium severity doesn’t necessarily mean that it’s less important than a critical flaw. For example, multiple medium severity flaws could be chained to initiate a critical exploit, just because Microsoft didn’t have the time or resources capable of closing those less-important gaps in time.

Red Windows 11 wallpaper

Then, the other issue is also that as more AI tools become accessible to malicious actors, Microsoft may have an even shorter window to patch these bugs. The company’s latest Patch Tuesday already fixed almost 600 vulnerabilities, but it will become even more difficult to keep up that pace while also ensuring that these issues aren’t discovered by bad actors. Also keep in mind that the source code for some Microsoft products has leaked over time so attackers could trigger exploits by analyzing that through AI too.

Finally, it’s important to remember that many of Microsoft’s products have been under development for decades. This means that they contain a lot of legacy code that may have been fine at the time of release, but has been building up technical debt that’s also becoming a source for vulnerabilities. It is a mammoth task to evaluate code end-to-end in old products.

Of course, all hope isn’t lost just yet. Microsoft confirmed to ProPublica that it is continuing to evaluate its triaging methodologies, staffing decisions, technology investments, and more in order to keep up with the evolving cybersecurity era today.