Microsoft says the patching window is shrinking fast. Here is what that means for ordinary people.

Software flaws are being turned into working attacks within hours of being made public. Microsoft says companies can no longer patch their way out of the problem fast enough, and is pushing a new defensive approach to buy time.

ThreatVectr Newsdesk· 4 min read
Photoreal news-editorial style 16:9 image of a large server room with rows of illuminated rack-mounted servers casting cool blue and amber light across a polish
Share

Key points

  • Microsoft warned in a public blog post that attackers now begin exploiting newly disclosed software flaws within hours, while most companies still need weeks to safely deploy fixes.
  • A Gartner analyst confirmed the compression is real for high-risk, internet-facing systems, though the risk is not equal across every organisation.
  • Microsoft is proposing that companies add network-level defences, meaning protections applied at the level of internet traffic rather than inside individual computers, to limit exposure during the gap.
  • Analysts caution that the approach works best in mature organisations and carries its own risks if temporary blocks are never followed up with permanent patches.

When a software company discovers a flaw in its product, it publishes a notice and releases a fix. That notice is public. Anyone reading it, including criminals, learns the flaw exists.

For years, companies had weeks to install fixes before criminals figured out how to exploit those flaws. Microsoft says that window is now collapsing.

"When a vulnerability was disclosed, organizations had time to understand the issue, assess affected systems, test patches, coordinate change windows, and deploy fixes before widespread exploitation occurred," wrote Igor Sakhnov, a Microsoft corporate vice president. "Today that timeline is rapidly shrinking."

How fast is 'fast'?

For systems directly connected to the internet, exploitation can begin within hours of a flaw being made public. Companies, however, often still need weeks to test and install fixes without breaking other things.

Shriya Mehrotra, a director analyst at research firm Gartner, confirmed the pattern: "Attackers can exploit critical vulnerabilities within hours, while many enterprises still require weeks to test and deploy patches." She added that the pressure is sharpest for systems facing the open internet, rather than internal company tools.

Microsoft points to two drivers making this worse. Security researchers publish working proof-of-concept code, which is essentially a ready-made demonstration of how to exploit a flaw, and that code spreads globally online within hours. Artificial intelligence tools are also making it easier for criminals to study flaws and build working attacks faster than before.

What is Microsoft proposing?

Patching remains essential. Microsoft is not suggesting otherwise.

What the company is pushing is an additional defensive layer that works at the network level, meaning it filters or blocks suspicious traffic flowing in and out of a company's systems, without needing to touch the software on every individual machine. Think of it as a fast-acting security gate that can be updated centrally while slower, permanent repairs happen behind it.

Sakhnov described this as a "control plane" sitting around a company's systems. "When a workload cannot immediately defend itself, another layer must help provide protection," he wrote.

Mehrotra said the idea is not entirely new. It builds on established practices such as network segmentation, which means dividing a company's systems into separate zones so that a problem in one zone cannot spread freely, and temporary isolation of affected systems until patches are ready.

Will this actually work in practice?

For well-organised companies with a clear picture of their own systems, yes. For many large organisations, the honest answer is: not yet.

Bhupendra Chopra, co-founder at technology firm Kanerika, put it plainly. "Most large enterprises don't have one accurate view of their own systems. Asset records sit in different tools that don't talk to each other."

Analysts also flagged a quieter risk: temporary blocks that nobody ever removes. "A network rule blocks a risky path, nobody circles back to patch the underlying system, and eighteen months later that workaround is its own liability nobody remembers approving," Chopra said.

For ordinary people, the practical consequence is that the companies holding your data, your medical records, your bank details, your travel bookings, are operating in an environment where criminals move faster than defenders. Asking a supplier or service provider how quickly they apply security patches is no longer a paranoid question. It is a reasonable one.

The Microsoft post, first covered by CSO Online, does not announce a specific product. It frames the argument for an architectural shift that benefits Microsoft's own Azure cloud-networking services. That context is worth keeping in mind when reading the recommendations.

© 2026 Threat Vectr