Patch and vulnerability tracker / Microsoft Patch Tuesday

Microsoft Patch Tuesday October 2026: every CVE and patch, ranked by risk

The front page of Microsoft patching: every CVE and the update (KB) that fixes it, the day it ships. October 2026 shipped 4 updates fixing 1 CVEs, graded by Severity. Senserva holds 28 months of releases this way, every month measured the same, so a spike is visible rather than asserted.

Zero-days are called out by name, and each release is ranked by what attackers actually exploit. Every KB links its own page with the download, the known issues Microsoft documents, a PowerShell installed-check, and the newer package that supersedes it when one has shipped. Patch Tuesday trends, the full history, calendar, and feeds live here, alongside the voices of the other Patch Tuesday trackers we follow.

Next Patch Tuesday: October 13, 2026, in 3 days.

Data refreshed twice a day, morning and afternoon US Central.

Senserva is a Microsoft Intelligent Security Association memberOpen the full patch tracker

This Patch TuesdayMODERATEbecause no CVEs from this release are on CISA KEV yetNext: October 13, 2026 (3 days)
The Senserva AI read pre-beta

This month's release is small and narrow: 4 updates covering 1 CVE across Exchange Server builds (2019 CU14, 2019 CU15, 2016 CU23, and Subscription Edition RTM). Microsoft rates no CVEs as Critical severity, and none are listed as zero-days or as already being exploited. The CISA KEV catalog shows zero entries this month, but that measures older CVEs being actively exploited elsewhere, not whether anything new here is under attack, so it should not be read as a sign of a quiet threat landscape overall. Given the single CVE, patch priority is straightforward: apply the Exchange Server updates to whichever of the four builds you run, with no need to triage across competing fixes.

Compared to the trailing 12-month average of 232 CVEs, 3 exploited, and 19 rated Critical severity, this month is far below normal volume. That makes it an easy month operationally, but it does not reduce exposure from unpatched prior-month CVEs still active in the wild. Admins should treat this as a light maintenance cycle, not a reason to ease up on tracking exploitation activity from earlier releases.

Pre-beta. Generated by Senserva AI from the live release data on this page, 2026-10-04. Regenerated when the data changes. The human take is above.
Take this release to your AI

Composed from the live October 2026 release data above, refreshed twice a day (morning and afternoon US Central). Copy it into Claude, ChatGPT, or Copilot. Free, no sign-in.

What those we follow are saying

Verbatim headlines from the trusted Patch Tuesday sources, pulled live from their own feeds (as of 2026-10-10). Items that name a CVE are also linked from that CVE's row above. For our own opinion, read the Senserva take on the blog.

“Microsoft Teams to Warn Users About Malicious Links Hidden in QR Codes”Microsoft is extending Teams security to detect malicious links hidden inside QR codes and warn users after a message has been delivered.Cyber Security News, 2026-10-10
“Citrix Urges NetScaler ADC and Gateway Customers to Patch for New Critical RCE Vulnerability”Citrix has urged customers to patch a critical security flaw in NetScaler ADC and NetScaler Gateway that could allow remote code execution or cause a denial of service.Cyber Security News, 2026-10-09 · CVE-2026-107406
“React Server Components Flaw Lets Attackers Freeze Next.js Servers With a Single POST Request”js servers by sending a specially crafted POST request to a Server Function endpoint.Cyber Security News, 2026-10-09 · CVE-2026-23870
“Microsoft Says PKI, HSMs and Security Appliances Must Prepare for Post-Quantum Authentication”Microsoft is urging organizations to prepare their certificate systems for post-quantum authentication, warning that public key infrastructure (PKI), hardware security modules (HSMs), and security appliances need…Cyber Security News, 2026-10-09
“PoC Released for Telegram Desktop Flaw Enabling One-Click File Account Takeover”A public proof of concept has exposed a flaw in Telegram Desktop that could let attackers steal local files and take over accounts after a user clicks a crafted external link. 6 (High).Cyber Security News, 2026-10-09 · CVE-2026-107181
“Citrix Urges Immediate Patching of Critical NetScaler Vulnerability”The security defect, tracked as CVE-2026-107406, could lead to remote code execution or denial-of-service.SecurityWeek, 2026-10-09 · CVE-2026-107406
“Unpatched AhsayCBS Vulnerabilities Exploited in the Wild”The flaws, CVE-2026-105133 and CVE-2026-105134, allow attackers to bypass authentication and inject OS commands.SecurityWeek, 2026-10-09 · CVE-2026-105133, CVE-2026-105134
“October 2026 Patch Tuesday forecast: Time for an Office cleanup”September 2026 Patch Tuesday set an all-time record with 973 CVEs addressed across the Microsoft portfolio.Help Net Security, 2026-10-09 · CVE-2026-85880, CVE-2026-81963
“High-severity NVIDIA vulnerability lets unauthenticated attackers crash GPU monitoring”Hundreds of internet-exposed graphics processing unit (GPU) servers were open to a high-severity flaw in NVIDIA’s DCGM Exporter (CVE-2026-47483) that lets unauthenticated attackers crash the monitoring service and may…Help Net Security, 2026-10-09 · CVE-2026-47483
“Hackers get $1,262,000 for 98 zero-days at Pwn2Own Ireland”The Pwn2Own Ireland 2026 hacking contest has concluded, with hackers collecting $1,262,000 in rewards after exploiting 98 zero-day flaws.BleepingComputer, 2026-10-09
“Microsoft: Outdated Windows devices will stop receiving security updates”Microsoft says devices running unsupported versions of Windows will stop receiving security updates after next year's Windows Update certificate rotation.BleepingComputer, 2026-10-09
“Max severity SonicWall SMA1000 flaw now exploited in attacks”Attackers are exploiting a maximum-severity vulnerability in SonicWall SMA1000 appliances (CVE-2026-102255) that was patched on Tuesday, three days ago.BleepingComputer, 2026-10-09 · CVE-2026-102255
“Unpatched AhsayCBS flaws exploited to deploy webshells, mine crypto”Threat actors are exploiting one critical and one medium-severity vulnerability still unpatched in the AhsayCBS backup management platform to deploy webshells and cryptocurrency miners.BleepingComputer, 2026-10-09
“PoC Released for Critical LMCache Flaw Enabling Unauthenticated Remote Code Execution”A proof-of-concept (PoC) exploit has been released for a critical vulnerability in LMCache that can allow unauthenticated remote code execution on exposed distributed deployments. 9.Cyber Security News, 2026-10-08 · CVE-2026-105192

Critical is rarer, and bigger

Every Microsoft update we track, grouped by the severity Microsoft assigned it, across 1,092 updates and 3,971 distinct CVEs (as of 2026-10-08). The count is UPDATES, not CVE fixes, and the difference matters: Important updates outnumber Critical ones, but a Critical update carries several times as many CVE fixes, because it is usually a cumulative one. So a Critical month is not just more urgent, it is a wider deployment. Counts per update are under each bar. The bars add up to 1,109 rather than 1,092 because 17 updates were rated at more than one severity.

Important779

9,558 CVE fixes, 12.3 per update

Critical260

22,892 CVE fixes, 88.0 per update

Moderate70

83 CVE fixes, 1.2 per update

Actively exploited this release

These are the October 2026 CVEs already being exploited in the wild, flagged by Microsoft in its release document (CISA KEV usually catches up within days). Patch them first, everywhere.

No CVE from the October 2026 release is reported as exploited yet, by Microsoft or on the CISA KEV list. That can change within days of release, so check back, and patch the highest-risk items below in the meantime.

Highest-risk fixes this release

Not yet flagged as exploited, but critical-severity (CVSS 8.8+) and worth prioritizing.

CVE-2026-96940HighMicrosoft Exchange Server Elevation of Privilege VulnerabilityCVSS 8.8

An Elevation of Privilege vulnerability affecting Microsoft Exchange Server 2019 Cumulative Update 14.

Affects: Microsoft Exchange Server 2019 Cumulative Update 14, Microsoft Exchange Server 2016 Cumulative Update 23, Microsoft Exchange Server Subscription Edition RTM

References: Microsoft · NVD · Tenable · Patch Tuesday coverage

October 2026 breakdown

What Microsoft fixed this release, by impact type and by product. Expand any row for what it means and the CVEs behind it, each linked to its full page.

By impact type

Elevation of Privilege1

The attacker gains higher permissions than they were granted, for example from a standard user to administrator or SYSTEM. These are the workhorses of exploit chains.

1 CVE this release, highest CVSS first:

CVE-2026-96940 8.8

Most-affected products

Microsoft Exchange Server 2019 Cumulative Update 141

1 CVE this release, highest CVSS first:

CVE-2026-96940 8.8

Microsoft Exchange Server 2016 Cumulative Update 231

1 CVE this release, highest CVSS first:

CVE-2026-96940 8.8

Microsoft Exchange Server Subscription Edition RTM1

1 CVE this release, highest CVSS first:

CVE-2026-96940 8.8

Microsoft Exchange Server 2019 Cumulative Update 151

1 CVE this release, highest CVSS first:

CVE-2026-96940 8.8

By the numbers

Upcoming Patch Tuesday dates

Microsoft ships updates on the second Tuesday of each month. Add them to your calendar in one click.

Add all upcoming dates to your calendar (.ics)

Patch Tuesday history

Every month since we started tracking, newest first. Tracking 28 releases, 1,271 updates and 70 actively-exploited CVEs in total.

9176884592290July 2024: 49 CVEs, 0 Critical, 1 exploited, 0 ransomware-linkedJul24August 2024: 71 CVEs, 15 Critical, 6 exploited, 0 ransomware-linkedSeptember 2024: 71 CVEs, 1 Critical, 4 exploited, 0 ransomware-linkedOctober 2024: 103 CVEs, 10 Critical, 3 exploited, 1 ransomware-linkedOct24November 2024: 78 CVEs, 9 Critical, 2 exploited, 1 ransomware-linkedDecember 2024: 69 CVEs, 23 Critical, 1 exploited, 0 ransomware-linkedJanuary 2025: 148 CVEs, 15 Critical, 3 exploited, 0 ransomware-linkedJan25February 2025: 45 CVEs, 0 Critical, 2 exploited, 0 ransomware-linkedMarch 2025: 58 CVEs, 0 Critical, 7 exploited, 1 ransomware-linkedApril 2025: 107 CVEs, 0 Critical, 1 exploited, 1 ransomware-linkedApr25May 2025: 54 CVEs, 0 Critical, 5 exploited, 0 ransomware-linkedJune 2025: 75 CVEs, 0 Critical, 2 exploited, 0 ransomware-linkedJuly 2025: 118 CVEs, 17 Critical, 3 exploited, 3 ransomware-linkedJul25August 2025: 140 CVEs, 36 Critical, 0 exploited, 0 ransomware-linkedSeptember 2025: 77 CVEs, 0 Critical, 0 exploited, 0 ransomware-linkedOctober 2025: 152 CVEs, 17 Critical, 4 exploited, 0 ransomware-linkedOct25November 2025: 43 CVEs, 24 Critical, 2 exploited, 1 ransomware-linkedDecember 2025: 107 CVEs, 21 Critical, 1 exploited, 0 ransomware-linkedJanuary 2026: 108 CVEs, 11 Critical, 3 exploited, 0 ransomware-linkedJan26February 2026: 40 CVEs, 1 Critical, 6 exploited, 0 ransomware-linkedMarch 2026: 61 CVEs, 0 Critical, 0 exploited, 0 ransomware-linkedApril 2026: 151 CVEs, 20 Critical, 3 exploited, 0 ransomware-linkedApr26May 2026: 98 CVEs, 16 Critical, 2 exploited, 1 ransomware-linkedJune 2026: 161 CVEs, 21 Critical, 0 exploited, 0 ransomware-linkedJuly 2026: 589 CVEs, 34 Critical, 5 exploited, 0 ransomware-linkedJul26August 2026: 354 CVEs, 16 Critical, 2 exploited, 0 ransomware-linkedSeptember 2026: 917 CVEs, 28 Critical, 2 exploited, 0 ransomware-linkedOctober 2026: 1 CVEs, 0 Critical, 0 exploited, 0 ransomware-linkedOct26
CVEs fixed Actively exploited Critical Ransomware-linked
MonthUpdatesCVEsExploitedRansomwareCritical
October 202641000
September 2026601,16920118
August 20266775110108
July 2026695895034
June 2026321610021
May 202666982116
April 2026631513020
March 20263961000
February 20263040601
January 2026271083011
December 2025551071021
November 202544432124
October 2025651524017
September 20253877000
August 2025751400036
July 2025511183317
June 20254775200
May 20253454500
April 202535107110
March 20253358710
February 20252545200
January 2025471483015
December 202445691023
November 20243578219
October 2024451033110
September 20244571401
August 202449716015
July 20243249100

Month-by-month recap

Expand any month for a plain-English summary of that Patch Tuesday.

October 20261 CVEs fixed

The October 2026 Microsoft Patch Tuesday shipped 4 updates (KB articles) fixing 1 CVE, 0 of them rated Critical severity. None from this release were on the CISA KEV exploited list at the time.

September 20261,169 CVEs fixed2 exploited

The September 2026 Microsoft Patch Tuesday shipped 60 updates (KB articles) fixing 1,169 CVEs, 118 of them rated Critical severity. Those are Microsoft's own counts; Senserva tracks 917 of them against update articles we hold pages for. 2 were already being exploited in the wild (on the CISA KEV list) and needed patching first.

August 2026751 CVEs fixed1 exploited

The August 2026 Microsoft Patch Tuesday shipped 67 updates (KB articles) fixing 751 CVEs, 108 of them rated Critical severity. Those are Microsoft's own counts; Senserva tracks 354 of them against update articles we hold pages for. 2 were already being exploited in the wild (on the CISA KEV list) and needed patching first.

July 2026589 CVEs fixed5 exploited

The July 2026 Microsoft Patch Tuesday shipped 69 updates (KB articles) fixing 589 CVEs, 34 of them rated Critical severity. 5 were already being exploited in the wild (on the CISA KEV list) and needed patching first.

June 2026161 CVEs fixed

The June 2026 Microsoft Patch Tuesday shipped 32 updates (KB articles) fixing 161 CVEs, 21 of them rated Critical severity. None from this release were on the CISA KEV exploited list at the time.

May 202698 CVEs fixed2 exploited

The May 2026 Microsoft Patch Tuesday shipped 66 updates (KB articles) fixing 98 CVEs, 16 of them rated Critical severity. 2 were already being exploited in the wild (on the CISA KEV list) and needed patching first. 1 was linked to ransomware activity.

April 2026151 CVEs fixed3 exploited

The April 2026 Microsoft Patch Tuesday shipped 63 updates (KB articles) fixing 151 CVEs, 20 of them rated Critical severity. 3 were already being exploited in the wild (on the CISA KEV list) and needed patching first.

March 202661 CVEs fixed

The March 2026 Microsoft Patch Tuesday shipped 39 updates (KB articles) fixing 61 CVEs, 0 of them rated Critical severity. None from this release were on the CISA KEV exploited list at the time.

February 202640 CVEs fixed6 exploited

The February 2026 Microsoft Patch Tuesday shipped 30 updates (KB articles) fixing 40 CVEs, 1 of them rated Critical severity. 6 were already being exploited in the wild (on the CISA KEV list) and needed patching first.

January 2026108 CVEs fixed3 exploited

The January 2026 Microsoft Patch Tuesday shipped 27 updates (KB articles) fixing 108 CVEs, 11 of them rated Critical severity. 3 were already being exploited in the wild (on the CISA KEV list) and needed patching first.

December 2025107 CVEs fixed1 exploited

The December 2025 Microsoft Patch Tuesday shipped 55 updates (KB articles) fixing 107 CVEs, 21 of them rated Critical severity. 1 was already being exploited in the wild (on the CISA KEV list) and needed patching first.

November 202543 CVEs fixed2 exploited

The November 2025 Microsoft Patch Tuesday shipped 44 updates (KB articles) fixing 43 CVEs, 24 of them rated Critical severity. 2 were already being exploited in the wild (on the CISA KEV list) and needed patching first. 1 was linked to ransomware activity.

October 2025152 CVEs fixed4 exploited

The October 2025 Microsoft Patch Tuesday shipped 65 updates (KB articles) fixing 152 CVEs, 17 of them rated Critical severity. 4 were already being exploited in the wild (on the CISA KEV list) and needed patching first.

September 202577 CVEs fixed

The September 2025 Microsoft Patch Tuesday shipped 38 updates (KB articles) fixing 77 CVEs, 0 of them rated Critical severity. None from this release were on the CISA KEV exploited list at the time.

August 2025140 CVEs fixed

The August 2025 Microsoft Patch Tuesday shipped 75 updates (KB articles) fixing 140 CVEs, 36 of them rated Critical severity. None from this release were on the CISA KEV exploited list at the time.

July 2025118 CVEs fixed3 exploited

The July 2025 Microsoft Patch Tuesday shipped 51 updates (KB articles) fixing 118 CVEs, 17 of them rated Critical severity. 3 were already being exploited in the wild (on the CISA KEV list) and needed patching first. 3 were linked to ransomware activity.

June 202575 CVEs fixed2 exploited

The June 2025 Microsoft Patch Tuesday shipped 47 updates (KB articles) fixing 75 CVEs, 0 of them rated Critical severity. 2 were already being exploited in the wild (on the CISA KEV list) and needed patching first.

May 202554 CVEs fixed5 exploited

The May 2025 Microsoft Patch Tuesday shipped 34 updates (KB articles) fixing 54 CVEs, 0 of them rated Critical severity. 5 were already being exploited in the wild (on the CISA KEV list) and needed patching first.

April 2025107 CVEs fixed1 exploited

The April 2025 Microsoft Patch Tuesday shipped 35 updates (KB articles) fixing 107 CVEs, 0 of them rated Critical severity. 1 was already being exploited in the wild (on the CISA KEV list) and needed patching first. 1 was linked to ransomware activity.

March 202558 CVEs fixed7 exploited

The March 2025 Microsoft Patch Tuesday shipped 33 updates (KB articles) fixing 58 CVEs, 0 of them rated Critical severity. 7 were already being exploited in the wild (on the CISA KEV list) and needed patching first. 1 was linked to ransomware activity.

February 202545 CVEs fixed2 exploited

The February 2025 Microsoft Patch Tuesday shipped 25 updates (KB articles) fixing 45 CVEs, 0 of them rated Critical severity. 2 were already being exploited in the wild (on the CISA KEV list) and needed patching first.

January 2025148 CVEs fixed3 exploited

The January 2025 Microsoft Patch Tuesday shipped 47 updates (KB articles) fixing 148 CVEs, 15 of them rated Critical severity. 3 were already being exploited in the wild (on the CISA KEV list) and needed patching first.

December 202469 CVEs fixed1 exploited

The December 2024 Microsoft Patch Tuesday shipped 45 updates (KB articles) fixing 69 CVEs, 23 of them rated Critical severity. 1 was already being exploited in the wild (on the CISA KEV list) and needed patching first.

November 202478 CVEs fixed2 exploited

The November 2024 Microsoft Patch Tuesday shipped 35 updates (KB articles) fixing 78 CVEs, 9 of them rated Critical severity. 2 were already being exploited in the wild (on the CISA KEV list) and needed patching first. 1 was linked to ransomware activity.

October 2024103 CVEs fixed3 exploited

The October 2024 Microsoft Patch Tuesday shipped 45 updates (KB articles) fixing 103 CVEs, 10 of them rated Critical severity. 3 were already being exploited in the wild (on the CISA KEV list) and needed patching first. 1 was linked to ransomware activity.

September 202471 CVEs fixed4 exploited

The September 2024 Microsoft Patch Tuesday shipped 45 updates (KB articles) fixing 71 CVEs, 1 of them rated Critical severity. 4 were already being exploited in the wild (on the CISA KEV list) and needed patching first.

August 202471 CVEs fixed6 exploited

The August 2024 Microsoft Patch Tuesday shipped 49 updates (KB articles) fixing 71 CVEs, 15 of them rated Critical severity. 6 were already being exploited in the wild (on the CISA KEV list) and needed patching first.

July 202449 CVEs fixed1 exploited

The July 2024 Microsoft Patch Tuesday shipped 32 updates (KB articles) fixing 49 CVEs, 0 of them rated Critical severity. 1 was already being exploited in the wild (on the CISA KEV list) and needed patching first.

Trusted Patch Tuesday resources

The analyses the security community reads each month. Cross-reference these with the ranked view above.

Microsoft Security Update GuideThe authoritative source: every CVE Microsoft fixed this month, affected products, and KBs.
CISA Known Exploited VulnerabilitiesThe U.S. catalog of CVEs confirmed exploited in the wild. Patch these first.
Zero Day Initiative: Security Update ReviewIn-depth monthly analysis from the researchers behind Pwn2Own.
Tenable Patch Tuesday analysisMonthly breakdowns of the CVEs that matter and why.
Rapid7 Patch TuesdayPatch Tuesday roundups with exploitation and attacker context.
Qualys Threat ResearchPatch Tuesday roundups and prioritization guidance.
SANS Internet Storm CenterCommunity Patch Tuesday dashboard and per-CVE detail.
CrowdStrike Patch Tuesday analysisMonthly Patch Tuesday breakdowns with adversary and exploitation context.
Krebs on SecurityPlain-English monthly Patch Tuesday coverage.
BleepingComputerNews coverage of each Patch Tuesday and emerging exploits.

Frequently asked questions

What is Patch Tuesday?

Patch Tuesday is the second Tuesday of each month, when Microsoft releases its scheduled security updates across Windows, Office, Exchange, SharePoint, and the rest of the Microsoft 365, Intune, Defender, and Entra ID stack. Out-of-band updates ship between Patch Tuesdays when a fix cannot wait, and this page covers both. Senserva ranks each release by what attackers are actually exploiting, ties every CVE to the KB that fixes it, and, in your own tenant, tells you which of these updates are actually missing on your devices.

When is the next Patch Tuesday?

The next Microsoft Patch Tuesday is October 13, 2026. It falls on the second Tuesday of every month; upcoming dates are listed on this page.

What was in the latest Patch Tuesday?

The October 2026 release included 4 updates (KBs) fixing 1 CVEs, of which 0 are actively exploited (CISA KEV). The exploited CVEs, the highest-risk CVEs, and the full history are on this page.

Which Patch Tuesday updates should I install first?

Install the actively-exploited (CISA KEV) fixes first, then the highest EPSS and CVSS ones, then the rest. This page ranks every release that way, and Senserva applies the same order to the updates actually missing on your own devices.

What is a zero-day on Patch Tuesday?

A zero-day is a vulnerability already being exploited (or publicly disclosed) before a patch was available. Those are the CVEs to patch immediately; this page calls out the actively-exploited ones each month.

How often is this page updated?

Automatically, every day. The data refreshes from Microsoft MSRC, CISA KEV, and FIRST.org EPSS, and the month-by-month history is preserved so the archive only grows.

Is this Patch Tuesday tracker free?

Yes, free with no sign-in. Running Senserva adds the part a public page cannot: which of these updates are actually missing on your devices, ranked, so you fix the right things first.

Can I use this Patch Tuesday data with my own AI?

Yes. A free copy-paste AI prompt just under the exploited-CVE list is composed from this release: the update and CVE counts, and the actively-exploited CVE names with their CVSS scores. Paste it into Claude, ChatGPT, or Copilot to get a first-24-hours plan and a team briefing in your own words.

The Microsoft CVE and patch resource center

Everything here is free, refreshed twice a day (morning and afternoon US Central), and cross-linked. Start with this month, then drill into any CVE, KB, product, or month since tracking began.

Data access: Patch Tuesday RSS · JSON patch API · calendar (.ics). Plus a page for every CVE and KB, linked throughout. JSON and RSS feeds included, no login required: all feeds and the API.

AI patch management: put your own AI on this data

Now see your own patch state.

Senserva reads your Microsoft 365, Intune, Defender, and Entra ID environment and turns this release into your list: every update still missing, on every device, ranked by what attackers are actually exploiting. The 650+ configuration checks come with it.

1Find it2Fix it3Prove it
Start my free patch auditAll you do is register.

Reference: the Microsoft patching guide, how Intune, Windows Autopatch, Defender, and Azure Update Manager fit together, and where third-party patch vendors fit in.

Data notice: this page, the feeds, and the API are provided as is, for informational purposes only, without warranty of any kind. Senserva, LLC does not guarantee the accuracy, completeness, or timeliness of third-party data and accepts no liability for actions taken based on it; verify against the primary source before acting. All use of this data is subject to the Senserva EULA.

Patching across Intune, Windows Autopatch, Defender, Azure, and your endpoint managers: see Senserva patching in action.