Cybersecurity Awareness Month 2026: Patching Checklist

October 1, 2026 6 min. read

Direct Answer 

Cybersecurity Awareness Month runs every October. In 2026, the National Cybersecurity Alliance’s theme is “Don’t Make It Easy for Them,” and CISA’s theme is “Securing the Next 250.” For IT teams, one of the most practical ways to act on both is to close the third-party patching gap: know which non-Microsoft applications you run, prioritize known vulnerabilities, automate updates through the tools you already use, and prove coverage with reports. The four-week checklist below turns that into an October plan. 

Key Takeaways

  • Keeping software updated is one of the everyday habits the campaign has promoted for years, alongside strong passwords, multi-factor authentication and reporting scams.
  • Windows Update, WSUS and Intune update policies do not update most non-Microsoft applications, so browsers, PDF readers and runtimes need a separate process.
  • Prioritize with severity (CVSS), exploitation evidence (CISA KEV) and likelihood of exploitation (EPSS).
  • Automate publishing into Intune, Configuration Manager or WSUS, and measure what actually got installed.

What is Cybersecurity Awareness Month 2026?  

Cybersecurity Awareness Month is an annual campaign held every October. In the United States it is co-led by the Cybersecurity and Infrastructure Security Agency (CISA) and the National Cybersecurity Alliance (NCA). In Europe, ENISA and the European Commission coordinate European Cybersecurity Month during the same period.

The 2026 campaign has two themes. The NCA’s theme, “Don’t Make It Easy for Them,” focuses on simple habits that make attacks harder to carry out. CISA’s theme, “Securing the Next 250,” marks the 250th anniversary of the United States and focuses on the resilience of critical infrastructure and the organizations that support it.

Why software updates belong in an awareness campaign?

For an individual, “keep software updated” means accepting an update prompt. For an IT team, it means making sure that every managed device actually receives every relevant fix, including fixes for applications that Microsoft’s update services do not deliver.

Most Windows endpoints run a mix of Microsoft and non-Microsoft software: browsers, PDF readers, collaboration clients, compression tools, remote-access clients and developer runtimes. Each vendor releases security fixes on its own schedule. Without a central process, older versions remain installed after a fix is available, which is exactly the kind of opportunity the “Don’t Make It Easy for Them” theme asks organizations to remove.

The four-week third-party patching checklist

Week 1 — See what you run

  • Export installed software from Intune (Discovered apps), Configuration Manager inventory or the software inventory in Microsoft Defender Vulnerability Management.
  • Normalize application names and versions, and assign an owner to each business-critical application.
  • Uninstall applications that are no longer needed. Every removed application is one less thing to patch.
  • List devices that still run Windows 10 and confirm their Extended Security Updates (ESU) status.

Week 2 — Decide what matters first

  • Agree on written remediation targets for critical, high and medium vulnerabilities with your security team.
  • Use CVSS to understand severity, the CISA Known Exploited Vulnerabilities (KEV) catalog to identify vulnerabilities attackers already use, and EPSS to estimate the likelihood of exploitation.
  • Rank applications that are widely installed or that open untrusted content, such as browsers and document readers, ahead of niche tools.

Week 3 — Automate the routine

  • Choose one delivery path per platform: Intune Win32 apps with supersedence, Intune Enterprise App Management, Configuration Manager third-party updates, WSUS local publishing, or a publishing tool that covers these.
  • Deploy to a pilot group first, then to broader groups after a defined observation period.
  • Download installers only from the vendor’s official source and verify file integrity before publishing.
  • Use maintenance windows and clear user notifications to reduce disruption.

Week 4 — Prove it

  • Report installation status per application and per severity, not just the number of updates published.
  • Track the time between a vendor release and successful installation across your devices.
  • Record every exception with an owner, a reason and an expiry date.
  • Share a one-page summary with leadership and set a quarterly review so the work continues after October.
Test Typical owner Done
Inventory third-party applications on all managed devices Endpoint team
Remove unused or unsupported applications Endpoint team + app owners
Confirm Windows 10 ESU status and exit dates Endpoint team
Define remediation targets by severity Security team
Add KEV and EPSS to prioritization Security team
Automate publishing for the top 20 applications Endpoint team
Create pilot and broad deployment groups Endpoint team
Verify installer sources and integrity Endpoint team
Publish a compliance report per application Endpoint + Security team
Document exceptions with expiry dates Security team

Common mistakes to avoid

  • Patching only the operating system.Windows updates do not cover most third-party applications
  • Counting published updates as installed updates.Only device-level installation status shows real coverage.
  • Ignoring user-installed applications.Discovery data often reveals software IT did not deploy
  • Treating October as a one-off.Vendors release fixes every week, so the process needs to run all year.

Two October dates to plan for:  

October 13, 2026 is October’s Patch Tuesday and the last day of Year 1 of commercial Windows 10 Extended Security Updates. Organizations that keep Windows 10 devices need to decide on Year 2 coverage, and they still need to patch third-party applications on those devices. Our guide to the Windows 10 ESU deadline explains the details. 

Teams that still rely on WSUS should also review Microsoft’s September 2024 deprecation announcement and plan how third-party updates will be delivered as more workloads move to Intune.

How Easy2Patch helps:  

Easy2Patch publishes updates for third-party Windows applications into Microsoft Intune, Configuration Manager and WSUS without installing an additional agent on endpoints. It provides a catalog with CVE information, downloads installers from vendors’ original sources, verifies file integrity with hash checks and, with its Defender integration, can publish updates to Intune for applications that Microsoft Defender Vulnerability Management reports as vulnerable. 

Frequently Asked Questions

Cybersecurity Awareness Month takes place every October. In the United States it is co-led by the Cybersecurity and Infrastructure Security Agency (CISA) and the National Cybersecurity Alliance. In Europe, ENISA and the European Commission coordinate European Cybersecurity Month in the same month. Organizations use it for training, phishing simulations and security improvement projects.

There are two themes. The National Cybersecurity Alliance’s 2026 theme is “Don’t Make It Easy for Them,” which focuses on everyday habits that make attacks harder. CISA’s 2026 theme is “Securing the Next 250,” which marks the 250th anniversary of the United States and focuses on resilience for critical infrastructure and the organizations that support it.

Keeping software updated is one of the basic habits the campaign promotes. In organizations, many applications are not updated by Windows Update, WSUS or Intune update policies, so outdated browsers, PDF readers or runtimes can stay on devices long after fixes are available. Closing that gap turns an awareness message into a measurable security improvement.

Start with severity and exploitation evidence. Use CVSS scores to understand severity, the CISA Known Exploited Vulnerabilities catalog to identify vulnerabilities attackers already use, and EPSS to estimate the likelihood of exploitation. Then consider how widely an application is installed and whether it opens untrusted content, as browsers and document readers do

Yes. Intune can deploy updates as Win32 apps with supersedence, and Enterprise App Management can auto-update catalog apps for licensed tenants. Configuration Manager can publish third-party updates through its software update point and third-party catalogs. Third-party publishing tools automate packaging and publishing for both platforms, as well as for WSUS.

Conclusion

The 2026 message is simple: don’t make it easy for attackers. For IT teams, that means no forgotten applications, clear priorities, automated delivery and reports that show what was actually fixed. Use October to set up the process, then keep it running every week of the year.

Sources

Get started with our patch management software for free Advanced Patch Management Get 30 Days Premium Trial