Microsoft's record patch release highlights need for risk-based vulnerability management
Microsoft's September 2026 Patch Tuesday set a new record with 973 vulnerabilities, including 113 rated Critical. Despite this, two actively exploited flaws, both rated Important, were not prioritized by the team that typically patches from Critical downward. The vulnerabilities, CVE-2026-81963 in the Windows Update Stack and CVE-2026-85880 in Windows ALPC, were later added to CISA's Known Exploited Vulnerabilities catalog.
Experts highlight the growing gap between patch release and exploitation timelines. Mandiant's M-Trends 2026 reports a mean time to exploit of negative seven days in 2025, meaning attacks often occur before patches are available. CrowdStrike's 2026 report shows eCrime breakout times have plummeted to an average of 29 minutes, with the fastest observed at just 27 seconds.
Merritt Baer, former deputy CISO at AWS, emphasizes the need for risk-based patching. 'Patching works, but a monthly cadence cannot cover Mandiant's negative-seven-day exploitation timeline,' she told VentureBeat. Baer advocates for continuous assessment and prioritization based on asset exposure and attacker reachability. City CISOs like Bryce Carter of Arlington, Texas, and Robert Branch of Virginia Beach, support this approach, focusing on patching the most critical vulnerabilities rather than applying every fix universally.
CISA's Binding Operational Directive 26-04 shifts from fixed remediation deadlines to a risk-based matrix, prioritizing vulnerabilities based on public exposure, exploitation status, automatability, and technical impact. Verizon's 2026 Data Breach Investigations Report found that only 26% of unique CISA KEV vulnerabilities were fully remediated, down from 38% the previous year, with a 43-day median to resolution. Baer stresses that board reporting should focus on exposure still open rather than tickets closed, highlighting the importance of tracking exploited-in-the-wild flaws on reachable assets.