The two flaws attackers were already exploiting when Microsoft's September 8 Patch Tuesday landed were both rated Important by Microsoft. Both are local elevation-of-privilege vulnerabilities. An attacker who can run low-privilege code on the machine can elevate to SYSTEM privileges.
SANS Internet Storm Center counted 973 CVEs in the release, 113 rated Critical. The release was also Microsoft’s largest Patch Tuesday on record. A team that works the batch from Critical downward reaches neither exploited flaw first. CISA added both, CVE-2026-81963 in the Windows Update Stack and CVE-2026-85880 in Windows ALPC, to the Known Exploited Vulnerabilities catalog on September 8.
Mandiant's M-Trends 2026 puts the mean time to exploit in 2025 at an estimated negative seven days. A negative mean does not mean every vulnerability was exploited before a patch existed; it means exploitation occurred, on average, seven days before patch release.
CrowdStrike's 2026 Global Threat Report shows how little time defenders may have after initial access. Average eCrime breakout time, from initial access to lateral movement, fell to 29 minutes in 2025. The fastest observed breakout took 27 seconds.
"Patching works, but a monthly cadence cannot cover Mandiant's negative-seven-day exploitation timeline," Merritt Baer, former deputy CISO at AWS and advisor to Upwind Security and G2i, told VentureBeat in a recent interview. "AI accelerates discovery and exploit development, further compressing the time defenders have to act. You need controls that reduce exposure and detect compromise before a patch exists."
Monthly patching still handles routine maintenance. The change is that active exploitation and exposure can move a vulnerability ahead of the scheduled cycle.
What risk-based patching looks like in practice
Baer's operating model runs on two tracks at once. "Keep scheduled maintenance, but continuously assess exposure and authorize action outside that schedule," she said. "Know your assets and owners; patch, restrict access or isolate systems based on risk, then verify the fix and check for compromise." On what sets the order, her answer is one sentence. "With 973 CVEs in a single drop, priority depends on what you run, what attackers can reach and exploit, and what a compromise would let them do."
Two city CISOs described the same split in a September 8 GovTech report on the summer surge in Microsoft's patch volumes. Bryce Carter, CISO of Arlington, Texas, said the reflex of rolling every fix to everyone no longer applies. "We really have to risk-weight things today," Carter said. "I care less about the number of things you can patch. I care more about patching the right things." Robert Branch, CISO for Virginia Beach, put the queue as a question. "How many of those are really critical?" His 10-person team brought in temporary outside staff to work the volume through mid-October. An Exchange flaw rated high sat lower on his list because the city's servers were not internet-facing.
CISA drew the same line for federal agencies on June 10 with Binding Operational Directive 26-04, which replaces fixed remediation deadlines with a risk-based matrix built on four factors: public exposure, exploitation status, automatability and technical impact. The highest-risk cases get three calendar days, with forensic triage also required in some cases to check for prior compromise. In initial analysis at one large civilian agency, as AFCEA's Signal reported, about 1% of vulnerabilities needed the three-day tier. More than 60% could wait for the next system update.
"As a CISO, you either have a mature prioritization and patching program that burns down vulnerabilities relevant to your environment, or you don't," Baer said. That model presumes an asset inventory with owners. A directive does not supply one.
Board reporting moves from tickets closed to exposure still open
Verizon's 2026 Data Breach Investigations Report found that organizations fully remediated 26% of the unique CISA KEV vulnerabilities found in their environments, down from 38% the year before, with a 43-day median to full resolution.
"Treating '26% remediated' as a verdict on security is made-up math without understanding the denominator and the exposure that remains," Baer said. "Board reporting should explain your approach, show overall progress and gaps, and address whether your program is keeping pace as AI shortens the time to exploit."
"Compliance deadlines influence the queue, but closing the most tickets doesn't necessarily remove the most risk," Baer explained. Taken together, Baer's criteria point to a different board view: exploited-in-the-wild flaws that remain open on reachable assets, how long each stayed open after credible exploitation evidence, and what was restricted or isolated when a patch could not ship. That shows whether exposure is shrinking or accumulating.
What to run before October 13
Microsoft's October Patch Tuesday lands on the 13th. Before it arrives, Baer's framework and CISA's risk model leave security teams with three questions:
Is the monthly cycle still running on schedule? Nine hundred and seventy-three, including 113 rated Critical, test the machinery, but that answer alone does not establish remaining exposure.
How long did exploited flaws on exposed assets stay open, and what covered them before the patch? Start with flaws backed by credible evidence of exploitation and map them to reachable assets. Where a patch could not ship, record the compensating control; after remediation, verify the fix and check for compromise.
What is the exposure now, and is it holding or widening? Report that trend, not just the number of tickets closed.
Where affected systems remain unpatched, September's two exploited flaws belong among the first entries on that report. The October drop is scheduled. Exploitation is not.
