When hundreds of security updates compete for attention, the real challenge is deciding what needs to be patched first — and when patching alone is no longer enough.
By Daniel Ferreira Porta
Patching is one of cybersecurity’s most basic defensive practices.
A vulnerability is discovered. A fix becomes available. The organization installs it. The ticket is closed.
But two practical problems remain.
First, organizations rarely have the capacity to patch everything at once.
Second, a patch fixes the vulnerability now. It does not tell you whether the system was compromised before the fix was installed.
Recent threat intelligence makes both problems increasingly important.
When Everything Is Critical, What Comes First?
The DANRESA Cybersecurity Threat Intelligence Bulletin — Week of September 14, 2026 analyzed an unusually large Microsoft security update cycle: 974 vulnerabilities, according to Microsoft’s MSRC data reviewed in the bulletin.
Among them were two Windows vulnerabilities rated CVSS 7.8 that were already being actively exploited. The same cycle also contained vulnerabilities with higher severity scores.
That illustrates an important operational lesson:
The highest CVSS score is not automatically the first patch your organization should deploy.
Severity matters.
But so do exploitation, exposure, and business impact.
The 4-Question Patch Rule
When your patch queue is larger than your available maintenance window, start with four questions.
1. Is It Being Actively Exploited?
This should be one of the strongest prioritization signals. A theoretical vulnerability and a vulnerability already being used in real attacks represent different operational conditions.
Known active exploitation moves the patch forward.
2. Is the System Exposed to the Internet?
An Internet-facing VPN, firewall, gateway, remote-access platform, management console, or public application gives attackers a more direct path to the vulnerable technology.
The easier the vulnerable asset is to reach, the shorter your acceptable remediation window should become.
3. What Happens if That Asset Is Compromised?
Not every system has the same business impact. Ask what the attacker could reach next.
Does the system manage other security devices? Does it provide privileged access? Does it process sensitive information? Does the business depend on it? Could compromise provide access to many other systems?
Patch priority should reflect blast radius, not only vulnerability severity.
4. Was It Exposed While Exploitation Was Already Happening?
The same DANRESA bulletin analyzed a critical Adobe Commerce vulnerability for which exploitation was observed beginning on September 4, while the vendor patch became available on September 7.
For an affected system exposed during that period, installing the patch is essential. But it does not answer whether exploitation already occurred.
That changes the action from:
Patch
to:
Patch + Investigate.
A Practical Patch Priority Roadmap
| Priority | What You Know | What to Do |
|---|---|---|
| P1 | Active exploitation + Internet exposure + critical asset | Patch immediately + investigate for compromise |
| P2 | Active exploitation, but exposure is limited | Patch urgently + review exposure and relevant logs |
| P3 | No known exploitation, but Internet-facing or business-critical | Prioritize in the next available patch window |
| P4 | No known exploitation + internal + lower business impact | Manage through the normal patch cycle |
This is not a replacement for vulnerability management, change control, or an organization’s risk methodology.
It is a practical triage rule for answering the question:
Where do we start?
And After the Patch?
A patch closes a vulnerability. It does not erase the exposure window that existed before the patch.
Think of discovering a defective lock on an office door.
Replacing the lock is necessary. But if you learn that people were already exploiting that exact defect to enter buildings, you would probably also check whether someone entered yours.
Cybersecurity works the same way.
The patch closes the door. Investigation helps determine whether someone already crossed it.
Stay Cyber Aware
When dozens or hundreds of patches compete for attention, do not ask only:
“Which vulnerability has the highest score?”
Ask:
Is it being exploited?
Is it exposed?
How critical is the asset?
Could compromise have already happened?
That produces a much more useful rule:
Active exploitation + Internet exposure + high business impact = Patch First.
And when the system was exposed while exploitation was already occurring:
Patch + Investigate.
Because effective patch management is not about installing every update at the same speed.
It is about reducing the most important exposure first.
Cyber Intelligence Reference
This article was developed from findings analyzed in the DANRESA Cybersecurity Threat Intelligence Bulletin — Week of September 14, 2026, covering September 7–13, 2026. The bulletin documented active exploitation affecting multiple enterprise technologies and reinforced the importance of prioritizing remediation according to exploitation status, exposure, and asset criticality rather than vulnerability severity alone.
Daniel Porta
CISO | Cyber Resilience Architect | Enterprise & Workforce Resilience
Founder – Cyber Resilience Initiatives