All posts

We Published the Intelligence Half

Senserva Watch

Join Senserva Watch and get Three Free Unlimited Audits with our full Claude MCP, a fresh audit credit every quarter, alerts when a CVE or KB you follow changes, the Patch Tuesday wire on release day, and 20% off when you buy.

Join Senserva Watch

One email address. No tenant connection, no agent, no call.

Senserva Watch Live, showing tracked patch counts, the August 2026 Patch Tuesday summary, and the do-this-first list of actively exploited vulnerabilities.

A follow-up to Patch and Vulnerability Intelligence in Microsoft Environments: the ranking pipeline described in that post is now a public website, a live dashboard, and a free alert membership.

The half that is not tenant-specific

July's post described a vulnerability program as a join between two data sets. On one side, an inventory of what is deployed and what is missing, which comes out of Defender and Intune. On the other, evidence of what attackers are actually doing, which comes out of MSRC, CISA KEV, EPSS, SSVC, public exploit indexes, and endoflife.date. Join them, rank by exploitation evidence, and the updates become a short day-one list.

Posture data is necessarily tenant-specific. There is no way to tell you what your environment is missing without looking at it. But the intelligence half is not tenant-specific at all. Whether a given CVE is on KEV, what its EPSS score did last week, and which KB closes it are the same facts for every reader of this blog. We have published that half as the Microsoft Patch Tracker.

It is the ranking applied to the entire Microsoft catalog and rendered as a table you can sort and filter. As of this writing, that is 1,027 security updates fixing 2,964 CVEs, of which 309 close something under active attack per CISA KEV, and 211 are rated Critical. Rows come back ordered by confirmed exploitation first, then ransomware association, then EPSS, then Severity and recency.

Around it sit the narrower views that answer narrower questions: what was exploited this week, what is being exploited outside the Microsoft world, which open source fixes landed, and what is already past its support date, with the edition-aware Windows lifecycle handling that bit us in July and got a full paragraph of warning in that post. Everything refreshes twice a day, at 5 AM and 3 PM US Central.

The page people actually arrive on

There are now more than ten thousand per-item pages, one for every CVE and every KB, and they turned out to be how most people reach us. Someone is mid-change-window with a KB number in hand, and what they need is not a ranking. They need the CVEs it fixes, the known issues Microsoft has documented against it, a way to check whether it is already installed, and the download link.

So that is what the page is: the Severity and EPSS and KEV flags at the top, Microsoft's own known issues underneath, a copy-paste PowerShell installed-check, the Update Catalog link, and a prepared prompt for anyone who would rather hand the whole thing to an AI than read it.

What shape is this month in?

Ranked tables answer questions about individual updates. The question in a Monday meeting is a different one, and Senserva Watch Live is where we answer it. KEV additions by month, back to the start of tracking, make the case for exploitation-led ranking. A ninety-day heat strip of our daily risk score makes a bad week look like one. Risk-weighted load by Microsoft product family is the view most likely to change a plan, because it is frequently not the family the team is patching. Evidence coverage per framework handles the compliance side of the room.

Underneath it are the same feeds the July post catalogued, plus two that are new to the pipeline: Google and Bing search demand, and Hacker News. Search demand is not a threat signal and we do not rank on it. It is an audience signal, and it answers a different question: which patches everyone else is worried about this week, as opposed to which ones are being exploited. Most of the time the two lists overlap heavily. When they diverge, the divergence is usually worth ten minutes of somebody's attention.

One email when something moves

Senserva Watch is the other new addition, and it puts these updates in your inbox. You follow the CVEs and KBs that matter to your environment, and you get one email when one of them actually moves, whether that is a KEV addition, an EPSS jump, or a new update that supersedes the one you were tracking. The Patch Tuesday wire goes out on release day. Membership also carries the audit side, three free unlimited runs with a fresh credit each quarter, and the Senserva MCP server for Claude alongside each one.

The log of every mass alert we send is public, including as a JSON feed, with the date, the CVEs and KBs covered, and the full text of the message.

The data is a free feed too

All of it is available as JSON and RSS, documented on the feeds page, no key required. The table on the tracker loads from the same endpoint you can call. If you use them, please cache rather than poll: the data only changes twice a day.

The ranking will keep changing as the feeds do, and it is documented at Senserva CVE Ranking as it stands today. Member API keys and bulk exports are rolling out, and the Watcher family comes next, local patching first.

If you read the July post and wanted to build this for yourself, every source is still listed there and still free. If you would rather just have the answer, it is on the tracker twice a day.

All posts

Patching across Intune, Windows Autopatch, Defender, Azure, and your endpoint managers: see Senserva patching in action.