The Houston Area Patch Index Is Live. You Are Probably Patching in the Wrong Order.
Measuring The Gap Between Patch Release And Patch Installation – How To Prioritize Patches By Confirmed Exploitation
We tracked 38,446 vendor security advisories across 18 vendors since 2022. Here is which fixes actually matter for a Houston business.
The Houston Area Patch Index is a free CinchOps research dataset tracking every published security advisory from 18 major software vendors since January 2022, now covering 38,446 advisories.
We built it because the patching conversation changed in 2026 and most business owners have not been told. CinchOps provides managed IT support and patch management specifically for small and mid-sized businesses in the Houston metro, and the index exists because we needed the numbers ourselves before we could tell a client what to prioritize.
Every figure below comes from the same three public sources: CVE records from the CVE.org cvelistV5 repository, Microsoft advisory counts from the MSRC security update API, and exploitation status from the CISA Known Exploited Vulnerabilities catalog. No surveys, no self-reporting, no vendor participation. You can open the index and check any number in it against your own stack.
The headline finding is not that patch volume exploded, though it did. It is that the way almost everyone triages patches sends teams after the wrong 4,753 items.
Should You Prioritize Patches by Severity Score?
The most common triage rule in small business IT, tested against 38,446 advisories.
Severity tells you what could go wrong. Exploitation tells you what is going wrong. Of the 7,442 advisories published across our tracked vendors in 2026, 4,753 were rated critical or high, and 57 have been confirmed under active attack by CISA.
That is roughly 83 times less work for the fixes carrying real, observed risk. Across the entire dataset going back to 2022, only 1.41% of published advisories have ever been confirmed exploited in the wild.
What most people believe: a CVSS score of 9.8 means drop everything. What the data shows: a 9.8 that nobody has ever weaponized is a maintenance-window item, and a 7.2 sitting in CISA's Known Exploited Vulnerabilities catalog is an emergency.
One caution on the percentage itself. When the index says 65.3% of 2026 advisories are critical or high, that is a share of the advisories carrying a CVSS score at all. Unscored records are excluded from the denominator rather than quietly counted as harmless. That distinction matters when a vendor dashboard shows you a reassuring number built the other way.
Sorting by exploitation is not the same as ignoring severity. A critical-rated flaw in an internet-facing system still deserves a real maintenance window. The point is sequence, not permission to skip. Confirmed exploitation sets what gets done this week; severity sets what gets done this quarter.
- Check the catalog against your inventory weekly. Anything listed that touches your stack jumps the queue regardless of its score.
- Treat severity as the second sort, not the first. It orders the remaining work rather than defining the emergency.
- Record what you skipped and why. A deliberate deferral you can explain is a decision. An undocumented one is a finding in your next insurance questionnaire.
How Long Do You Have Before a Patched Flaw Gets Attacked?
The timing assumption behind quarterly maintenance windows, measured against 353 confirmed cases.
72% of the flaws that get exploited are under confirmed attack within 30 days of the fix shipping, and 95% within a year. We measured the gap between publication date and the date CISA confirmed exploitation across 353 cases in the index.
The years-long exposure stories get written up because they are dramatic. They are also the tail, not the pattern. Flaws first attacked more than three years after their fix account for roughly 1% of confirmed cases in the dataset.
A business patching monthly sits inside that window for most confirmed cases. A business patching quarterly, or whenever someone finds a free evening, sits outside it for the majority. In 30 years doing this, the pattern we see over and over with Houston businesses is not a company that refused to patch. It is a company that patched on a schedule set before the schedule mattered.
Not sure how many of these touch your stack?
Select the vendors you actually run in the index and it calculates the patch load your team is absorbing.
Open the Patch IndexDoes a High CVE Count Mean a Vendor Is Insecure?
Why the index deliberately refuses to rank vendors by advisory volume.
A high advisory count usually reflects more transparency, not worse security. A vendor publishing hundreds of fixes is telling you what it found. A vendor publishing none may simply have no public disclosure program.
This is why the Houston Area Patch Index measures workload landing on your IT team rather than grading vendor engineering. Six vendors were excluded from the charts entirely for insufficient signal, and that exclusion is a data-quality decision, not a verdict on their products.
What most people believe: pick the vendor with fewer CVEs. What the data shows: silence is not safety. You cannot patch what a vendor never tells you about, and buying on advisory count rewards the companies that disclose least.
- Microsoft leads confirmed exploitation with 134 advisories in CISA's catalog across the window, ahead of Apple at 35 and Cisco at 32.
- Volume and risk are different measurements. Oracle published 1,552 advisories in 2026 and carries 12 confirmed exploited across the whole dataset.
- Small vendors are not low risk. Ivanti published 26 advisories in 2026 and carries 22 confirmed exploited since 2022, nearly one confirmed attack for every advisory it shipped this year.
There is a real question buried under the bad one. Instead of asking which vendor publishes fewer flaws, ask which vendors in your stack show up repeatedly in the exploited catalog, because that is where an attacker has already done the engineering work. In the index that list is short and stable: edge devices, browsers, and remote-access tooling.
Every business owner I talk to thinks the goal is patching everything faster. It is not. The goal is getting the handful attackers are actually using applied within days, and letting the rest follow a normal rhythm. Chasing five thousand critical-rated items with a three-person IT team is not diligence, it is a calf scramble.
Is the 2026 Patch Surge a Microsoft Problem?
What the index shows once you look past Patch Tuesday.
Advisory volume in 2026 is running about 2.6 times the 2025 pace across every tracked vendor, not just Microsoft. Severity climbed with it: the critical-plus-high share of scored advisories sat between 53% and 57% for four straight years, then reached 65.3% in 2026.
Microsoft published 644 advisories in July 2026, the largest single month in the dataset, against a range of 38 to 181 for the previous 53 months. That number earned the headlines. The rest of the field moved just as sharply.
The driver is AI-assisted vulnerability discovery reaching production. Microsoft credits its own in-house scanner, MDASH, announced in May 2026, and Windows chief Pavan Davuluri wrote on July 9, 2026 that update volumes will keep trending larger. Separately, Anthropic's Project Glasswing launched April 7, 2026, putting security-focused AI in the hands of member organizations. These are competing systems, not one program, and Microsoft has credited MDASH rather than its Glasswing access for its own volume.
For a Houston business the mechanism matters less than the arithmetic. If patching took your IT team one working day a month in 2025, the same coverage now needs roughly two and a half. Nobody we know budgeted for that in their 2026 plan, and the vendors are not slowing down.
Two of those growth numbers deserve a caveat before anyone quotes them. Oracle ships most of its advisories in quarterly Critical Patch Updates, so its year-over-year figure is lumpy by design rather than a sudden collapse in code quality. Chrome's jump reflects both real discovery volume and a change in how thoroughly its records are scored. The industry-wide 2.6 times pace holds with or without either one.
Patching prioritized by what attackers are actually using
CinchOps runs patch inventory, testing, deployment, and verification against the CISA exploited-vulnerabilities catalog, so the 57 jump the queue instead of waiting their turn behind the 4,753. Part of our cybersecurity services for Houston businesses.
See how we prioritize →How CinchOps Can Help Houston Businesses Patch What Matters
CinchOps is a managed IT services provider based in Katy, Texas, serving small and mid-sized businesses across the Houston metro area. CinchOps specializes in cybersecurity, network security, managed IT support, VoIP, and SD-WAN for businesses with 10-200 employees.
We handle patching on a flat monthly rate per endpoint, with no contracts, no hidden fees, and no cancellation penalties. Endpoints track headcount, so the number you pay for is the number you actually run. Patch verification is the part most providers skip: deploying a fix and confirming it applied are two different jobs, and only one of them shows up in a breach report.
- Managed IT support covering inventory, testing, deployment, and verification.
- Cybersecurity services that rank fixes by confirmed exploitation first.
- Business continuity and disaster recovery with geo-redundant backups outside the Gulf Coast flood zone, so a bad patch is a restore rather than a rebuild.
- IT support in Houston and Katy, with help desk response under 15 minutes.
- Industry work across construction, CPA firms, law firms, and oil and gas.
The index is free and we are not gating it. Use it to see what your own stack generates, then ask whoever handles your patching one question: what is our average number of days between a fix being published and being installed? If nobody can answer, that is the number to fix first. Happy to walk through yours, talk to CinchOps.
Frequently Asked Questions
What is the Houston Area Patch Index?
The Houston Area Patch Index is a free CinchOps research dataset tracking 38,446 security advisories from 18 major software vendors since January 2022. It measures advisory volume, severity mix, and how long it takes before attackers are confirmed to be exploiting a flaw.
What does patch management cost in Houston?
CinchOps handles patch management on a flat monthly rate per endpoint, with no contracts, hidden fees, or cancellation penalties. Endpoints track headcount, so cost scales with the machines you actually run. Inventory, testing, deployment, and verification are included rather than billed separately.
Should I patch by CVSS severity or by known exploitation?
Start with confirmed exploitation. In 2026 the index counted 4,753 advisories rated critical or high against 57 confirmed under attack by CISA. Anything in the CISA Known Exploited Vulnerabilities catalog that touches your stack should jump the queue regardless of its severity score.
How quickly do attackers exploit a newly published patch?
Across 353 confirmed cases in the index, 72% were under confirmed attack within 30 days of the fix becoming available and 95% within a year. Monthly patching sits inside that window for most cases. Quarterly patching sits outside it for the majority.
Why did patch volume jump so much in 2026?
AI-assisted vulnerability discovery reached production. Microsoft credits its in-house MDASH scanner, announced May 2026, and warned volumes will keep rising. Advisory counts across all 18 tracked vendors are running about 2.6 times the 2025 pace, so this is industry-wide rather than one vendor.
