Microsoft: Flaws Are Weaponized in Under 24 Hours

Microsoft published its annual security report on October 1, 2026. It says a vulnerability now goes from being discovered to being used in attacks in well under 24 hours, while companies can take 30 to 60 days to fix it. That matters to anyone who runs a website and updates it late.

What we know

  • What it is: Microsoft's 2026 Digital Defense Report. Its page shows a publish date of October 1, 2026 and is signed by Tanmay Ganacharya and Wes Malaby of Microsoft.
  • The headline number: the median time from a vulnerability being discovered in the wild to being weaponized has fallen, the report says, to "well below 24 hours."
  • How long fixes take: in enterprises, remediating a critical internet-facing vulnerability can take 30 to 60 days.
  • More flaws than before: nearly 40,000 vulnerabilities (CVEs) were published in the first half of 2026.
  • How attackers get in: in 30% of observed initial access, the user ran something themselves. Another 20% used valid accounts, meaning a real username and password.
  • The copy-and-paste trick: between February and early May 2026, Microsoft Defender saw attacker-supplied commands (the ClickFix technique) run on more than 1.1 million devices. That is roughly eight times more.
  • Old flaws still open: among detections tied to the five most common CVEs, 58% belong to a single one, disclosed in 2020.
  • AI: in one Microsoft evaluation, run in a controlled environment, an advanced AI system chained 32 stages of an attack.
  • Exposed applications: according to Help Net Security, exploits against public-facing applications were the way in for 24% of the intrusions Microsoft investigated between July 2025 and June 2026, up from 15% a year earlier.

What changes and what doesn't

The to-do list does not change. Updating, looking after passwords and keeping backups is still the foundation.

The deadline changes. If a flaw is exploited within hours and fixed within weeks, every day without an update counts.

Read the number with care. It is Microsoft's own measurement from its own data. The report page does not describe the sample or the method, it talks about enterprises, and it gives no figures by country. It does not mention WordPress or Drupal. And it is a median: it does not say every flaw is exploited within a day.

How to tell if it affects you

It affects you if your site runs on a content management system and updating it is nobody's job. Six checks:

  1. Date of the last update. Look at the CMS, its modules and its plugins. WordPress released version 7.1.2 on September 22, 2026. It fixes a critical vulnerability, and WordPress recommends updating immediately.
  2. Security advisories. WordPress and Drupal both publish them. Make sure they reach someone who can act the same day.
  3. What you expose to the internet. Admin panel, test subdomains, old installs. If it is not in use, close it.
  4. Accounts. Two-step verification on the admin panel, the hosting account and email. Remove users who no longer work with you.
  5. Pasted commands. No legitimate page asks you to copy a command and paste it into your computer. If one does, it is a scam.
  6. Backups. One exists, it is recent, and someone has tried restoring it.

How we apply it at DomHostSeo

We build sites on Drupal and WordPress, and our maintenance plans cover plugin, theme and core updates, backups and monitoring. This report settles the order: pending updates come first.

For this story we opened Microsoft's report page and the WordPress release note. The 24% figure was not on the page we read, so we attribute it to Help Net Security. It is the rule we described in Google: Fact-Check AI Content by Hand Before Publishing: the source first, then the story.

Sources

Updates: we will add here any detail from the full report that affects websites and content management systems.