Patch and vulnerability tracker / Microsoft Patch Tuesday

Microsoft Patch Tuesday July 2026: every CVE and patch, ranked by risk

The front page of Microsoft patching: every CVE and the update (KB) that fixes it, the day it ships. Zero-days are called out by name, each release is ranked by what attackers actually exploit, and every KB links its own page with the download, Microsoft's known issues, and a PowerShell installed-check. Patch Tuesday trends, the full history, calendar, and feeds live here, alongside the voices of the other Patch Tuesday trackers we follow. Next Patch Tuesday: August 11, 2026.

Data refreshed three times a day: 5 AM, 12:30 PM, and 7 PM US Central.

Senserva is a Microsoft Intelligent Security Association memberOpen the full patch tracker

This Patch TuesdayELEVATEDbecause 2 CVEs are already being exploited in the wild (July 2026 release)Next: August 11, 2026 (21 days)
July 2026 Patch Tuesday has shipped

The July 2026 release is a record 622 CVEs per Microsoft's official release note (about 570 in the core release by analyst count), including 56 rated Critical and three zero-days, two already being exploited in the wild (CVE-2026-56155 in AD FS and CVE-2026-56164 in SharePoint Server; CVE-2026-50661 in BitLocker is publicly disclosed). The full per-update breakdown lands on this page automatically as Microsoft publishes it. See the July 2026 page and our take on the blog (the opinion column; this page is the data).

Patch these first, per MSRC and CISA KEV:
  • CVE-2026-56155 Active Directory Federation Services (AD FS) Exploited in the wild
  • CVE-2026-56164 SharePoint Server Exploited in the wild
  • CVE-2026-50661 BitLocker Publicly disclosed
  • CVE-2026-50656 RoguePlanet elevation of privilege, July 9 out-of-band emergency fix Public proof-of-concept

The detailed sections below cover June 2026, the newest release with complete per-update data.

July 2026 released updates

Microsoft shipped 67 updates (KBs) in the July 2026 cycle, fixing 622 CVEs by its official count; 12 of the updates fix the actively exploited zero-days and sort to the top. The same zero-day appears on several rows because every Windows and SharePoint version gets its own update carrying the same fix; the release has 3 distinct zero-day CVEs. Straight from the MSRC release document (also on the July 2026 page); per-update risk ranking lands here automatically.

SenservaSenserva provides Three Free Unlimited Audits, including all tenants and full Claude MCP.Start my Audit
Take this release to your AI

Composed from the live July 2026 release data above, refreshed three times a day (5 AM, 12:30 PM, and 7 PM US Central). Copy it into Claude, ChatGPT, or Copilot. Free, no sign-in.

Senserva
Three Free Unlimited Audits
1 scan to find, 2 to review your fixes.
Setup and running in minutes. Your data stays local, in a results database only you hold.
Everything Siemserva by Senserva does: every missing patch ranked by real attacks, all 650+ security checks, and full reports.
All users · All settings · All patches · All tenants
Includes our advanced Claude MCP: everything you need to run full audits.

Free registration is all it takes, no card. Want it always on? Summer Special: unlimited use, up to 50 tenants, $600/mo or $6,500/yr.

What those we follow are saying

Verbatim headlines from the trusted Patch Tuesday sources, pulled live from their own feeds (as of 2026-07-21). Items that name a CVE are also linked from that CVE's row above. For our own opinion, read the Senserva take on the blog.

“SonicWall SMA zero-days were exploited weeks before disclosure”Help Net Security, 2026-07-21 · CVE-2026-15409, CVE-2026-15410
“Critical wp2shell WordPress flaws exploited to install webshells”BleepingComputer, 2026-07-21 · CVE-2026-63030, CVE-2026-60137
“'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover”Dark Reading, 2026-07-20 · CVE-2026-60137, CVE-2026-63030
“From a Single Alert to 1,000 Files: Inside an Exposed WebDAV Malware Delivery Lab”Rapid7, 2026-07-20 · CVE-2025-33053, CVE-2026-21513, CVE-2025-24054
“wp2shell (CVE-2026-63030, CVE-2026-60137): Frequently asked questions about remote code execution chain in WordPress Core”Tenable, 2026-07-20 · CVE-2026-63030, CVE-2026-60137, CVE-2026-41940, CVE-2020-25213

The trend

6224673111560February 2025: 45 CVEs fixed, 2 with known attacksFeb25March 2025: 86 CVEs fixed, 9 with known attacksApril 2025: 110 CVEs fixed, 1 with known attacksApr25May 2025: 40 CVEs fixed, 4 with known attacksJune 2025: 99 CVEs fixed, 7 with known attacksJun25July 2025: 64 CVEs fixed, 5 with known attacksAugust 2025: 243 CVEs fixed, 5 with known attacksAug25September 2025: 61 CVEs fixed, 0 with known attacksOctober 2025: 138 CVEs fixed, 4 with known attacksOct25November 2025: 11 CVEs fixed, 0 with known attacksDecember 2025: 223 CVEs fixed, 6 with known attacksDec25January 2026: 109 CVEs fixed, 3 with known attacksFebruary 2026: 39 CVEs fixed, 5 with known attacksFeb26March 2026: 61 CVEs fixed, 0 with known attacksApril 2026: 153 CVEs fixed, 2 with known attacksApr26May 2026: 127 CVEs fixed, 1 with known attacksJune 2026: 211 CVEs fixed, 1 with known attacksJun26July 2026: 622 CVEs fixed, 2 with known attacksFebruary 2025: 2 CVEs with known attacks addedMarch 2025: 9 CVEs with known attacks addedApril 2025: 1 CVEs with known attacks addedMay 2025: 4 CVEs with known attacks addedJune 2025: 7 CVEs with known attacks addedJuly 2025: 5 CVEs with known attacks addedAugust 2025: 5 CVEs with known attacks addedSeptember 2025: 0 CVEs with known attacks addedOctober 2025: 4 CVEs with known attacks addedNovember 2025: 0 CVEs with known attacks addedDecember 2025: 6 CVEs with known attacks addedJanuary 2026: 3 CVEs with known attacks addedFebruary 2026: 5 CVEs with known attacks addedMarch 2026: 0 CVEs with known attacks addedApril 2026: 2 CVEs with known attacks addedMay 2026: 1 CVEs with known attacks addedJune 2026: 1 CVEs with known attacks addedJuly 2026: 2 CVEs with known attacks added
CVEs fixed CVEs with known attacks added

July 2026 breakdown

What Microsoft shipped this release, by product, straight from the MSRC release document. The per-CVE impact breakdown and full per-update ranking land here automatically as Microsoft publishes its per-update data.

Most-affected products

Microsoft Office 2016 (32-bit edition)4

Updates shipped for this product in the cycle, per the MSRC release document.

4 CVEs this release, highest CVSS first:

Microsoft Office 2016 (64-bit edition)4

Updates shipped for this product in the cycle, per the MSRC release document.

4 CVEs this release, highest CVSS first:

Microsoft SharePoint Enterprise Server 20163

Updates shipped for this product in the cycle, per the MSRC release document.

3 CVEs this release, highest CVSS first:

Microsoft SharePoint Server 20193

Updates shipped for this product in the cycle, per the MSRC release document.

3 CVEs this release, highest CVSS first:

Windows 11 Version 26H1 for ARM64-based Systems3

Updates shipped for this product in the cycle, per the MSRC release document.

3 CVEs this release, highest CVSS first:

Windows Server 20123

Updates shipped for this product in the cycle, per the MSRC release document.

3 CVEs this release, highest CVSS first:

Windows Server 2012 (Server Core installation)3

Updates shipped for this product in the cycle, per the MSRC release document.

3 CVEs this release, highest CVSS first:

Windows Server 2012 R23

Updates shipped for this product in the cycle, per the MSRC release document.

3 CVEs this release, highest CVSS first:

Windows Server 2012 R2 (Server Core installation)3

Updates shipped for this product in the cycle, per the MSRC release document.

3 CVEs this release, highest CVSS first:

Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 26H1 for ARM64-based Systems2

Updates shipped for this product in the cycle, per the MSRC release document.

2 CVEs this release, highest CVSS first:

Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 version 26H1 for x64-based Systems2

Updates shipped for this product in the cycle, per the MSRC release document.

2 CVEs this release, highest CVSS first:

Microsoft SharePoint Server Subscription Edition2

Updates shipped for this product in the cycle, per the MSRC release document.

2 CVEs this release, highest CVSS first:

By the numbers

  • 622 CVEs by Microsoft's official count (Security Update Guide)
  • 67 updates (KB articles) shipped in the cycle
  • 56 rated Critical
  • 2 actively exploited (CISA KEV)
  • 3 zero-days, plus an out-of-band emergency fix earlier in the cycle

Upcoming Patch Tuesday dates

Microsoft ships updates on the second Tuesday of each month. Add them to your calendar in one click.

Add all upcoming dates to your calendar (.ics)

Patch Tuesday history

Every month since we started tracking, newest first. Tracking 25 releases, 898 updates and 78 actively-exploited CVEs in total.

6224673111560July 2024: 50 CVEs, 0 Critical, 2 exploited, 1 ransomware-linkedJul24August 2024: 71 CVEs, 15 Critical, 6 exploited, 0 ransomware-linkedSeptember 2024: 80 CVEs, 4 Critical, 4 exploited, 0 ransomware-linkedOctober 2024: 105 CVEs, 11 Critical, 3 exploited, 0 ransomware-linkedOct24November 2024: 82 CVEs, 9 Critical, 2 exploited, 1 ransomware-linkedDecember 2024: 69 CVEs, 16 Critical, 1 exploited, 0 ransomware-linkedJanuary 2025: 149 CVEs, 14 Critical, 3 exploited, 0 ransomware-linkedJan25February 2025: 45 CVEs, 0 Critical, 2 exploited, 0 ransomware-linkedMarch 2025: 86 CVEs, 0 Critical, 9 exploited, 1 ransomware-linkedApril 2025: 110 CVEs, 0 Critical, 1 exploited, 1 ransomware-linkedApr25May 2025: 40 CVEs, 0 Critical, 4 exploited, 0 ransomware-linkedJune 2025: 99 CVEs, 0 Critical, 7 exploited, 0 ransomware-linkedJuly 2025: 64 CVEs, 5 Critical, 5 exploited, 3 ransomware-linkedJul25August 2025: 243 CVEs, 28 Critical, 5 exploited, 0 ransomware-linkedSeptember 2025: 61 CVEs, 0 Critical, 0 exploited, 0 ransomware-linkedOctober 2025: 138 CVEs, 11 Critical, 4 exploited, 0 ransomware-linkedOct25November 2025: 11 CVEs, 0 Critical, 0 exploited, 0 ransomware-linkedDecember 2025: 223 CVEs, 21 Critical, 6 exploited, 0 ransomware-linkedJanuary 2026: 109 CVEs, 11 Critical, 3 exploited, 0 ransomware-linkedJan26February 2026: 39 CVEs, 0 Critical, 5 exploited, 0 ransomware-linkedMarch 2026: 61 CVEs, 0 Critical, 0 exploited, 0 ransomware-linkedApril 2026: 153 CVEs, 10 Critical, 2 exploited, 0 ransomware-linkedApr26May 2026: 127 CVEs, 9 Critical, 1 exploited, 0 ransomware-linkedJune 2026: 211 CVEs, 11 Critical, 1 exploited, 0 ransomware-linkedJuly 2026: 622 CVEs, 56 Critical, 2 exploited, 0 ransomware-linkedJul26
CVEs fixed Actively exploited Critical Ransomware-linked
MonthUpdatesCVEsExploitedRansomwareCritical
July 2026 official count-6222056
June 2026262111011
May 202655127109
April 2026531532010
March 20263861000
February 20262939500
January 2026271093011
December 2025552236021
November 20251611000
October 2025571384011
September 20253061000
August 2025672435028
July 20253764535
June 20253199700
May 20251840400
April 202535110110
March 20253386910
February 20251745200
January 2025441493014
December 202427691016
November 20243482219
October 2024431053011
September 20244580404
August 202449716015
July 20243250210

Month-by-month recap

Expand any month for a plain-English summary of that Patch Tuesday.

July 2026622 CVEs fixed2 exploited

The July 2026 Microsoft Patch Tuesday has shipped: a record 622 CVEs per Microsoft's official release note (about 570 in the core release by analyst count), including 56 rated Critical and three zero-days, two already being exploited in the wild (CVE-2026-56155 in AD FS and CVE-2026-56164 in SharePoint Server; CVE-2026-50661 in BitLocker is publicly disclosed). The per-update breakdown lands automatically as Microsoft publishes it.

June 2026211 CVEs fixed1 exploited

The June 2026 Microsoft Patch Tuesday shipped 26 updates (KB articles) fixing 211 CVEs, 11 of them rated Critical severity. 1 was already being exploited in the wild (on the CISA KEV list) and needed patching first.

May 2026127 CVEs fixed1 exploited

The May 2026 Microsoft Patch Tuesday shipped 55 updates (KB articles) fixing 127 CVEs, 9 of them rated Critical severity. 1 was already being exploited in the wild (on the CISA KEV list) and needed patching first.

April 2026153 CVEs fixed2 exploited

The April 2026 Microsoft Patch Tuesday shipped 53 updates (KB articles) fixing 153 CVEs, 10 of them rated Critical severity. 2 were already being exploited in the wild (on the CISA KEV list) and needed patching first.

March 202661 CVEs fixed

The March 2026 Microsoft Patch Tuesday shipped 38 updates (KB articles) fixing 61 CVEs, 0 of them rated Critical severity. None from this release were on the CISA KEV exploited list at the time.

February 202639 CVEs fixed5 exploited

The February 2026 Microsoft Patch Tuesday shipped 29 updates (KB articles) fixing 39 CVEs, 0 of them rated Critical severity. 5 were already being exploited in the wild (on the CISA KEV list) and needed patching first.

January 2026109 CVEs fixed3 exploited

The January 2026 Microsoft Patch Tuesday shipped 27 updates (KB articles) fixing 109 CVEs, 11 of them rated Critical severity. 3 were already being exploited in the wild (on the CISA KEV list) and needed patching first.

December 2025223 CVEs fixed6 exploited

The December 2025 Microsoft Patch Tuesday shipped 55 updates (KB articles) fixing 223 CVEs, 21 of them rated Critical severity. 6 were already being exploited in the wild (on the CISA KEV list) and needed patching first.

November 202511 CVEs fixed

The November 2025 Microsoft Patch Tuesday shipped 16 updates (KB articles) fixing 11 CVEs, 0 of them rated Critical severity. None from this release were on the CISA KEV exploited list at the time.

October 2025138 CVEs fixed4 exploited

The October 2025 Microsoft Patch Tuesday shipped 57 updates (KB articles) fixing 138 CVEs, 11 of them rated Critical severity. 4 were already being exploited in the wild (on the CISA KEV list) and needed patching first.

September 202561 CVEs fixed

The September 2025 Microsoft Patch Tuesday shipped 30 updates (KB articles) fixing 61 CVEs, 0 of them rated Critical severity. None from this release were on the CISA KEV exploited list at the time.

August 2025243 CVEs fixed5 exploited

The August 2025 Microsoft Patch Tuesday shipped 67 updates (KB articles) fixing 243 CVEs, 28 of them rated Critical severity. 5 were already being exploited in the wild (on the CISA KEV list) and needed patching first.

July 202564 CVEs fixed5 exploited

The July 2025 Microsoft Patch Tuesday shipped 37 updates (KB articles) fixing 64 CVEs, 5 of them rated Critical severity. 5 were already being exploited in the wild (on the CISA KEV list) and needed patching first. 3 were linked to ransomware activity.

June 202599 CVEs fixed7 exploited

The June 2025 Microsoft Patch Tuesday shipped 31 updates (KB articles) fixing 99 CVEs, 0 of them rated Critical severity. 7 were already being exploited in the wild (on the CISA KEV list) and needed patching first.

May 202540 CVEs fixed4 exploited

The May 2025 Microsoft Patch Tuesday shipped 18 updates (KB articles) fixing 40 CVEs, 0 of them rated Critical severity. 4 were already being exploited in the wild (on the CISA KEV list) and needed patching first.

April 2025110 CVEs fixed1 exploited

The April 2025 Microsoft Patch Tuesday shipped 35 updates (KB articles) fixing 110 CVEs, 0 of them rated Critical severity. 1 was already being exploited in the wild (on the CISA KEV list) and needed patching first. 1 was linked to ransomware activity.

March 202586 CVEs fixed9 exploited

The March 2025 Microsoft Patch Tuesday shipped 33 updates (KB articles) fixing 86 CVEs, 0 of them rated Critical severity. 9 were already being exploited in the wild (on the CISA KEV list) and needed patching first. 1 was linked to ransomware activity.

February 202545 CVEs fixed2 exploited

The February 2025 Microsoft Patch Tuesday shipped 17 updates (KB articles) fixing 45 CVEs, 0 of them rated Critical severity. 2 were already being exploited in the wild (on the CISA KEV list) and needed patching first.

January 2025149 CVEs fixed3 exploited

The January 2025 Microsoft Patch Tuesday shipped 44 updates (KB articles) fixing 149 CVEs, 14 of them rated Critical severity. 3 were already being exploited in the wild (on the CISA KEV list) and needed patching first.

December 202469 CVEs fixed1 exploited

The December 2024 Microsoft Patch Tuesday shipped 27 updates (KB articles) fixing 69 CVEs, 16 of them rated Critical severity. 1 was already being exploited in the wild (on the CISA KEV list) and needed patching first.

November 202482 CVEs fixed2 exploited

The November 2024 Microsoft Patch Tuesday shipped 34 updates (KB articles) fixing 82 CVEs, 9 of them rated Critical severity. 2 were already being exploited in the wild (on the CISA KEV list) and needed patching first. 1 was linked to ransomware activity.

October 2024105 CVEs fixed3 exploited

The October 2024 Microsoft Patch Tuesday shipped 43 updates (KB articles) fixing 105 CVEs, 11 of them rated Critical severity. 3 were already being exploited in the wild (on the CISA KEV list) and needed patching first.

September 202480 CVEs fixed4 exploited

The September 2024 Microsoft Patch Tuesday shipped 45 updates (KB articles) fixing 80 CVEs, 4 of them rated Critical severity. 4 were already being exploited in the wild (on the CISA KEV list) and needed patching first.

August 202471 CVEs fixed6 exploited

The August 2024 Microsoft Patch Tuesday shipped 49 updates (KB articles) fixing 71 CVEs, 15 of them rated Critical severity. 6 were already being exploited in the wild (on the CISA KEV list) and needed patching first.

July 202450 CVEs fixed2 exploited

The July 2024 Microsoft Patch Tuesday shipped 32 updates (KB articles) fixing 50 CVEs, 0 of them rated Critical severity. 2 were already being exploited in the wild (on the CISA KEV list) and needed patching first. 1 was linked to ransomware activity.

Trusted Patch Tuesday resources

The analyses the security community reads each month. Cross-reference these with the ranked view above.

Microsoft Security Update GuideThe authoritative source: every CVE Microsoft fixed this month, affected products, and KBs.
CISA Known Exploited VulnerabilitiesThe U.S. catalog of CVEs confirmed exploited in the wild. Patch these first.
Zero Day Initiative: Security Update ReviewIn-depth monthly analysis from the researchers behind Pwn2Own.
Tenable Patch Tuesday analysisMonthly breakdowns of the CVEs that matter and why.
Rapid7 Patch TuesdayPatch Tuesday roundups with exploitation and attacker context.
Qualys Threat ResearchPatch Tuesday roundups and prioritization guidance.
SANS Internet Storm CenterCommunity Patch Tuesday dashboard and per-CVE detail.
CrowdStrike Patch Tuesday analysisMonthly Patch Tuesday breakdowns with adversary and exploitation context.
Krebs on SecurityPlain-English monthly Patch Tuesday coverage.
BleepingComputerNews coverage of each Patch Tuesday and emerging exploits.

Frequently asked questions

What is Patch Tuesday?

Patch Tuesday is the second Tuesday of each month, when Microsoft releases its scheduled security updates across Windows, Office, Exchange, SharePoint, and the rest of the Microsoft 365, Intune, Defender, and Entra ID stack. Out-of-band updates ship between Patch Tuesdays when a fix cannot wait, and this page covers both. Senserva ranks each release by what attackers are actually exploiting, ties every CVE to the KB that fixes it, and, in your own tenant, tells you which of these updates are actually missing on your devices.

When is the next Patch Tuesday?

The next Microsoft Patch Tuesday is August 11, 2026. It falls on the second Tuesday of every month; upcoming dates are listed on this page.

What was in the latest Patch Tuesday?

The July 2026 release is a record 622 CVEs per Microsoft's official release note (about 570 in the core release by analyst count), including 56 rated Critical and three zero-days, two already being exploited in the wild (CVE-2026-56155 in AD FS and CVE-2026-56164 in SharePoint Server; CVE-2026-50661 in BitLocker is publicly disclosed). The full per-update breakdown lands on this page automatically as Microsoft publishes it. The June 2026 release included 26 updates (KBs) fixing 211 CVEs, of which 1 are actively exploited (CISA KEV). The exploited CVEs, the highest-risk CVEs, and the full history are on this page.

Which Patch Tuesday updates should I install first?

Install the actively-exploited (CISA KEV) fixes first, then the highest EPSS and CVSS ones, then the rest. This page ranks every release that way, and Senserva applies the same order to the updates actually missing on your own devices.

What is a zero-day on Patch Tuesday?

A zero-day is a vulnerability already being exploited (or publicly disclosed) before a patch was available. Those are the CVEs to patch immediately; this page calls out the actively-exploited ones each month.

How often is this page updated?

Automatically, every day. The data refreshes from Microsoft MSRC, CISA KEV, and FIRST.org EPSS, and the month-by-month history is preserved so the archive only grows.

Is this Patch Tuesday tracker free?

Yes, free with no sign-in. Running Senserva adds the part a public page cannot: which of these updates are actually missing on your devices, ranked, so you fix the right things first.

Can I use this Patch Tuesday data with my own AI?

Yes. A free copy-paste AI prompt just under the exploited-CVE list is composed from this release: the update and CVE counts, and the actively-exploited CVE names with their CVSS scores. Paste it into Claude, ChatGPT, or Copilot to get a first-24-hours plan and a team briefing in your own words.

The Microsoft CVE and patch resource center

Everything here is free, refreshed three times a day (5 AM, 12:30 PM, and 7 PM US Central), and cross-linked. Start with this month, then drill into any CVE, KB, product, or month since tracking began.

Data access: Patch Tuesday RSS · JSON patch API · calendar (.ics). Plus a page for every CVE and KB, linked throughout. JSON and RSS feeds included, no login required: all feeds and the API.

AI patch management: put your own AI on this data

Scan your own tenant free

Reference: the Microsoft patching guide, how Intune, Windows Autopatch, Defender, and Azure Update Manager fit together, and where third-party patch vendors fit in.

Data notice: this page, the feeds, and the API are provided as is, for informational purposes only, without warranty of any kind. Senserva, LLC does not guarantee the accuracy, completeness, or timeliness of third-party data and accepts no liability for actions taken based on it; verify against the primary source before acting. All use of this data is subject to the Senserva EULA.

Patching across Intune, Windows Autopatch, Defender, Azure, and your endpoint managers: see Senserva patching in action.

Senserva
Three Free Unlimited Audits
1 scan to find, 2 to review your fixes.
Setup and running in minutes. Your data stays local, in a results database only you hold.
Everything Siemserva by Senserva does: every missing patch ranked by real attacks, all 650+ security checks, and full reports.
All users · All settings · All patches · All tenants
Includes our advanced Claude MCP: everything you need to run full audits.
Start my Audit Watch a guided first scan

Free registration is all it takes, no card. Want it always on? Summer Special: unlimited use, up to 50 tenants, $600/mo or $6,500/yr.