Microsoft Cut Its Patch Window From 14 Days To 3. Bad Actors Are Why.
.png?width=1200&height=630&name=IMAGES-4%20(19).png)
On Tuesday September 8th, Microsoft published roughly 970 security fixes, the largest release the company has ever made. Once again, attackers had assembled a kit to exploit some of those vulnerabilities back in August, before the patch was even released.
2 exploits out of 970 might sound like good odds, but here is why it is not.
The morning after Microsoft’s release, a security firm named Proofpoint reported that one of those actively exploited vulnerabilities was already built into a ready-made exploit kit, paired with a vulnerability in Google Chrome. A targeted person opens a malicious web page, and the Chrome vulnerability runs the attacker’s code inside the browser. Then the Microsoft vulnerability turns that exploit into control of the entire machine. Four separate espionage groups picked up that exploit kit within days of one another, and one of them is even attacking aerospace and defense contractors.
Although you might not be an aerospace supplier, the reason this matters to you anyway is how that exploit kit was assembled.
The Chrome half of it was already patched. Chrome is built on shared open-source code, so its repairs are published where anyone can read them, even bad actors, and they are published before the patch reaches your machine. That patch went public on the 7th of August, almost a month before it landed on people’s machines on September 3rd. So for nearly 4 weeks the fix was readable yet undelivered, and as expected, a malicious actor spent those weeks working backwards from the fix to the vulnerability.
That is how software built on shared code gets repaired. A trusted system, being abused. And it is true of far more products than Chrome. Once again, the thing you trust is the thing being exploited. The gap between a patch being written and the day it finally gets installed is the window attackers are operating in now.
That is the change Microsoft made, and Microsoft said why. Attackers are turning published fixes into working attacks faster than businesses can install them, let alone facilitate the restart necessary to actually implement the fix.
3 things are worth doing this month.
First, your patch cycle needs revisiting. Most businesses wrote their update policy to match the old 2 weeks, and never revisited it. If yours still says 2 weeks, it is following advice the vendor has withdrawn. Whoever runs your IT is the person to raise that with this week.
Second, ask when your machines were last restarted. This is the half almost everybody misses. An update can download, install, and report itself finished, and still do nothing at all until the machine restarts. Chrome only completes its update when the browser closes, so a browser left open for 3 weeks is running the version from before any of this. Windows is the same for most of what shipped on Tuesday. Restarting is part of installing the update, not a courtesy afterwards.
Third, expect 2 reboots. If your computers use the newer update method that avoids restarts, this month needs one anyway, and so does October. Microsoft has confirmed both.
One rule to remember: restart what you just patched, or the patch never happened.
NexusTek is a CMMC L2-certified managed service provider serving small and mid-sized businesses across the United States.
Sources: Microsoft Security Update Guide, September 2026. Google Chrome Stable Channel update, September 3rd 2026. Proofpoint Threat Insight, September 9th 2026.
