Skip to content
Back to Guavy Wire
Stocks

Microsoft's record patch release highlights need for risk-based vulnerability management

Instruments
MSFT
Share

Microsoft's September 2026 Patch Tuesday set a new record with 973 vulnerabilities, including 113 rated Critical. Despite this, two actively exploited flaws, both rated Important, were not prioritized by the team that typically patches from Critical downward. The vulnerabilities, CVE-2026-81963 in the Windows Update Stack and CVE-2026-85880 in Windows ALPC, were later added to CISA's Known Exploited Vulnerabilities catalog.

Experts highlight the growing gap between patch release and exploitation timelines. Mandiant's M-Trends 2026 reports a mean time to exploit of negative seven days in 2025, meaning attacks often occur before patches are available. CrowdStrike's 2026 report shows eCrime breakout times have plummeted to an average of 29 minutes, with the fastest observed at just 27 seconds.

Merritt Baer, former deputy CISO at AWS, emphasizes the need for risk-based patching. 'Patching works, but a monthly cadence cannot cover Mandiant's negative-seven-day exploitation timeline,' she told VentureBeat. Baer advocates for continuous assessment and prioritization based on asset exposure and attacker reachability. City CISOs like Bryce Carter of Arlington, Texas, and Robert Branch of Virginia Beach, support this approach, focusing on patching the most critical vulnerabilities rather than applying every fix universally.

CISA's Binding Operational Directive 26-04 shifts from fixed remediation deadlines to a risk-based matrix, prioritizing vulnerabilities based on public exposure, exploitation status, automatability, and technical impact. Verizon's 2026 Data Breach Investigations Report found that only 26% of unique CISA KEV vulnerabilities were fully remediated, down from 38% the previous year, with a 43-day median to resolution. Baer stresses that board reporting should focus on exposure still open rather than tickets closed, highlighting the importance of tracking exploited-in-the-wild flaws on reachable assets.

More on Stocks

Disclaimer: Guavy is a data and market intelligence provider, not an investment adviser. The information, signals, and market analysis provided by the Guavy API and related services are for informational purposes only and are not intended as financial advice, investment recommendations, or an endorsement of any particular trading strategy. Trading in volatile markets, including cryptocurrency, carries significant risk and may not be suitable for all investors. Past performance is not indicative of future results. Users should consult with a qualified financial professional before making any investment decisions. Guavy makes no guarantee of trading profits or financial returns.

Market sentiment intelligence for apps, funds & agents

Location

729 55 Ave SW
Calgary AB T2V 0G4
Canada

© 2026 Guavy Inc