
Tyler Reguly, Fortra’s associate director of security R&D, pointed out that as long as Microsoft is playing catch-up on patching vulnerabilities, numbers have lost all meaning.
“This is not a Microsoft-specific problem,” he noted. “We see the same issue with Oracle and other large vendors that are being proactive. We need to remember that these large CVE counts are a good thing, as we’re reducing attack surface before attackers get a chance to find and utilize the vulnerabilities. Eventually, all those long-standing, hard to find vulnerabilities will be fixed, and Patch Tuesday will return to its typical cadence. Until that happens, prioritization is key, and gift cards for extra coffee for your admins would likely be appreciated.”
Bicer added that the scale of this month’s Microsoft releases requires security leaders to move beyond CVSS-driven patching and prioritize systems according to exploitability, network exposure, privilege requirements, business criticality, and the consequences of compromise. The most consequential risks, he said, are concentrated in remotely reachable infrastructure, identity and authentication services, database platforms, virtualization environments, and Windows components where successful exploitation could provide code execution or elevated privileges.
