Microsoft Patch Tuesday July 2026: every CVE and patch, ranked by risk
The front page of Microsoft patching: every CVE and the update (KB) that fixes it, the day it ships. July 2026 shipped 69 updates fixing 533 CVEs, 24 of them Critical Severity and 4 already confirmed exploited in the wild. Senserva holds 25 months of releases this way, every month measured the same, so a spike is visible rather than asserted. Zero-days are called out by name, each release is ranked by what attackers actually exploit, and every KB links its own page with the download, the known issues Microsoft documents, a PowerShell installed-check, and the newer package that supersedes it when one has shipped. Patch Tuesday trends, the full history, calendar, and feeds live here, alongside the voices of the other Patch Tuesday trackers we follow. Next Patch Tuesday: September 8, 2026, in 28 days.
Data refreshed twice a day: 5 AM and 3 PM US Central.
Senserva is a Microsoft Intelligent Security Association memberOpen the full patch tracker
July 2026 at a glance
This month brings 533 CVEs across 69 updates, with 24 rated Critical severity. Four are flagged as actively exploited in the CISA KEV catalog, and the listed exploited entries center on SharePoint. Patch the two SharePoint Remote Code Execution flaws first, CVE-2026-50522 and CVE-2026-58644, both rated CVSS 9.8. Follow with the other exploited items: CVE-2026-56155 in Active Directory Federation Services (CVSS 7.8), CVE-2026-56164 SharePoint Elevation of Privilege (CVSS 5.3), and CVE-2026-32202 Windows Shell Spoofing (CVSS 4.3). The most-affected products are .NET on Windows and Mac, plus Windows 10 Version 1809 and Windows Server 2019.
Compared to the trailing 12-month averages of 99 CVEs, 2 exploited, and 16 Critical, this release is heavier than usual on volume, exploited count, and Critical severity items. No CVEs are ransomware-linked this month. The above-average exploited and Critical counts mean you should prioritize the known-exploited SharePoint and ADFS fixes immediately, then work through the broader Critical severity list, giving attention to your .NET and Windows Server 2019 footprint.
Composed from the live July 2026 release data above, refreshed twice a day (5 AM and 3 PM US Central). Copy it into Claude, ChatGPT, or Copilot. Free, no sign-in.
What those we follow are saying
Verbatim headlines from the trusted Patch Tuesday sources, pulled live from their own feeds (as of 2026-08-11). Items that name a CVE are also linked from that CVE's row above. For our own opinion, read the Senserva take on the blog.
Critical is rarer, and bigger
Every Microsoft update we track, grouped by the severity Microsoft assigned it, across 967 updates and 2,708 distinct CVEs (as of 2026-08-10). The count is UPDATES, not CVE fixes, and the difference matters: Important updates outnumber Critical ones, but a Critical update carries several times as many CVE fixes, because it is usually a cumulative one. So a Critical month is not just more urgent, it is a wider deployment. Counts per update are under each bar. The bars add up to 983 rather than 967 because 16 updates were rated at more than one severity.
8,964 CVE fixes, 12.7 per update
13,493 CVE fixes, 64.6 per update
79 CVE fixes, 1.2 per update
Actively exploited this release
These are the July 2026 CVEs already being exploited in the wild (on the CISA KEV list). Patch them first, everywhere.
CVE-2026-50522CriticalMicrosoft SharePoint Remote Code Execution VulnerabilityCVSS 9.8
A Remote Code Execution vulnerability affecting Microsoft SharePoint Enterprise Server 2016.
Affects: Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition
References: Microsoft · NVD · Tenable · Patch Tuesday coverage
Covering this CVE: Zero Day Initiative
CVE-2026-58644CriticalMicrosoft SharePoint Remote Code Execution VulnerabilityCVSS 9.8
A Remote Code Execution vulnerability affecting Microsoft SharePoint Enterprise Server 2016.
Affects: Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition
References: Microsoft · NVD · Tenable · Patch Tuesday coverage
Covering this CVE: Zero Day Initiative
CVE-2026-56155HighActive Directory Federation Services Elevation of Privilege VulnerabilityCVSS 7.8
An Elevation of Privilege vulnerability affecting Windows 10 Version 1809 for 32-bit Systems.
Affects: Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019
References: Microsoft · NVD · Tenable · Patch Tuesday coverage
Covering this CVE: Zero Day Initiative
CVE-2026-56164MediumMicrosoft SharePoint Server Elevation of Privilege VulnerabilityCVSS 5.3
An Elevation of Privilege vulnerability affecting Microsoft SharePoint Enterprise Server 2016.
Affects: Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition
References: Microsoft · NVD · Tenable · Patch Tuesday coverage
Covering this CVE: Zero Day Initiative
CVE-2026-32202MediumWindows Shell Spoofing VulnerabilityCVSS 4.3
A Spoofing vulnerability affecting Windows 10 Version 1809 for 32-bit Systems.
Affects: Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019
References: Microsoft · NVD · Tenable · Patch Tuesday coverage
Highest-risk fixes this release
Not yet flagged as exploited, but critical-severity (CVSS 8.8+) and worth prioritizing.
CVE-2026-57092CriticalMicrosoft Windows VMSwitch Elevation of Privilege VulnerabilityCVSS 9.9
An Elevation of Privilege vulnerability affecting Windows 10 Version 1809 for 32-bit Systems.
Affects: Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019
References: Microsoft · NVD · Tenable · Patch Tuesday coverage
Covering this CVE: Zero Day Initiative
CVE-2026-42990CriticalSQL Server ODBC driver Elevation of Privilege VulnerabilityCVSS 9.8
A Remote Code Execution vulnerability affecting Windows 10 Version 1809 for 32-bit Systems.
Affects: Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019
References: Microsoft · NVD · Tenable · Patch Tuesday coverage
CVE-2026-49172CriticalWindows FTP Service Remote Code Execution VulnerabilityCVSS 9.8
A Remote Code Execution vulnerability affecting Windows 11 Version 25H2 for x64-based Systems.
Affects: Windows 11 Version 25H2 for x64-based Systems, Windows Server 2025, Windows 10 Version 21H2 for ARM64-based Systems
References: Microsoft · NVD · Tenable · Patch Tuesday coverage
CVE-2026-50447CriticalWindows Message Queuing Service (MSMQ) Remote Code Execution VulnerabilityCVSS 9.8
A Remote Code Execution vulnerability affecting Windows 10 Version 1809 for 32-bit Systems.
Affects: Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019
References: Microsoft · NVD · Tenable · Patch Tuesday coverage
CVE-2026-50518CriticalWindows DHCP Server Remote Code Execution VulnerabilityCVSS 9.8
A Remote Code Execution vulnerability affecting Windows 10 Version 1809 for 32-bit Systems.
Affects: Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019
References: Microsoft · NVD · Tenable · Patch Tuesday coverage
Covering this CVE: Zero Day Initiative
CVE-2026-56159CriticalDHCP Server Service Remote Code Execution VulnerabilityCVSS 9.8
A Remote Code Execution vulnerability affecting Windows 10 Version 1809 for 32-bit Systems.
Affects: Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019
References: Microsoft · NVD · Tenable · Patch Tuesday coverage
CVE-2026-56190CriticalRemote Desktop Protocol Remote Code Execution VulnerabilityCVSS 9.8
A Remote Code Execution vulnerability affecting Windows 10 Version 1809 for 32-bit Systems.
Affects: Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019
References: Microsoft · NVD · Tenable · Patch Tuesday coverage
Covering this CVE: Zero Day Initiative
CVE-2026-56188CriticalWindows Server Network driver Remote Code Execution VulnerabilityCVSS 9.8
A Remote Code Execution vulnerability affecting Windows 10 Version 1809 for 32-bit Systems.
Affects: Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019
References: Microsoft · NVD · Tenable · Patch Tuesday coverage
Covering this CVE: Zero Day Initiative
CVE-2026-54990CriticalRemote Desktop Client Remote Code Execution VulnerabilityCVSS 9.8
A Remote Code Execution vulnerability affecting Windows Server 2025 (Server Core installation).
Affects: Windows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems
References: Microsoft · NVD · Tenable · Patch Tuesday coverage
CVE-2026-45657CriticalWindows Kernel Remote Code Execution VulnerabilityCVSS 9.8
A Remote Code Execution vulnerability affecting Windows Server 2022.
Affects: Windows Server 2022, Windows Server 2022 (Server Core installation), Windows Server 2025 (Server Core installation)
References: Microsoft · NVD · Tenable · Patch Tuesday coverage
CVE-2026-47291CriticalHTTP.sys Remote Code Execution VulnerabilityCVSS 9.8
A Remote Code Execution vulnerability affecting Windows 10 Version 1809 for 32-bit Systems.
Affects: Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019
References: Microsoft · NVD · Tenable · Patch Tuesday coverage
Covering this CVE: Zero Day Initiative
CVE-2026-44815CriticalDHCP Client Service Remote Code Execution VulnerabilityCVSS 9.8
A Remote Code Execution vulnerability affecting Windows 10 Version 1809 for 32-bit Systems.
Affects: Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019
References: Microsoft · NVD · Tenable · Patch Tuesday coverage
July 2026 breakdown
What Microsoft fixed this release, by impact type and by product. Expand any row for what it means and the CVEs behind it, each linked to its full page.
By impact type
Elevation of Privilege330
The attacker gains higher permissions than they were granted, for example from a standard user to administrator or SYSTEM. These are the workhorses of exploit chains.
330 CVEs this release, highest CVSS first:
CVE-2026-57092 9.9CVE-2026-42990 9.8CVE-2026-42904 9.6CVE-2026-49798 9.3CVE-2026-55052 8.8CVE-2026-58277 8.8CVE-2026-54107 8.8CVE-2026-49795 8.8CVE-2026-50369 8.8CVE-2026-50444 8.8CVE-2026-50477 8.8CVE-2026-50489 8.8CVE-2026-50666 8.8CVE-2026-50670 8.8CVE-2026-54121 8.8CVE-2026-50692 8.8CVE-2026-56194 8.8CVE-2026-56647 8.8CVE-2026-58534 8.8CVE-2026-50360 8.8CVE-2026-50398 8.8CVE-2026-50385 8.8CVE-2026-50413 8.8CVE-2026-50687 8.8+306 more
Remote Code Execution172
The attacker runs their own code on the target, usually the most serious class of vulnerability. Prioritize internet-facing and unpatched systems first.
172 CVEs this release, highest CVSS first:
CVE-2026-50522 9.8CVE-2026-49172 9.8CVE-2026-50447 9.8CVE-2026-50518 9.8CVE-2026-56159 9.8CVE-2026-56190 9.8CVE-2026-56188 9.8CVE-2026-54990 9.8CVE-2026-58644 9.8CVE-2026-45657 9.8CVE-2026-47291 9.8CVE-2026-44815 9.8CVE-2026-41096 9.8CVE-2026-50380 9.6CVE-2026-54982 8.8CVE-2026-54999 8.8CVE-2026-58608 8.8CVE-2026-48564 8.8CVE-2026-49178 8.8CVE-2026-50370 8.8CVE-2026-50382 8.8CVE-2026-50474 8.8CVE-2026-57090 8.8CVE-2026-57094 8.8+148 more
Information Disclosure122
The flaw leaks data that should be protected, such as memory contents, file data, or authentication tokens. Leaked credentials often feed the next stage of an attack.
122 CVEs this release, highest CVSS first:
CVE-2026-50429 8.2CVE-2026-56186 8.1CVE-2026-45503 8.1CVE-2026-50665 7.8CVE-2026-50463 7.5CVE-2026-50470 7.5CVE-2026-50496 7.5CVE-2026-45639 7.5CVE-2026-42908 7.5CVE-2026-40406 7.5CVE-2026-49165 7.1CVE-2026-50428 7.1CVE-2026-58529 7.1CVE-2026-55122 7.1CVE-2026-56193 7.1CVE-2026-58528 6.8CVE-2026-45608 6.8CVE-2026-50678 6.6CVE-2026-55051 6.5CVE-2026-55003 6.5CVE-2026-57979 6.5CVE-2026-34348 6.5CVE-2026-50376 6.5CVE-2026-50445 6.5+98 more
Denial of Service46
The attacker crashes or hangs a service, taking it offline. Lower confidentiality impact, but a real availability risk for exposed services.
46 CVEs this release, highest CVSS first:
CVE-2026-54983 7.5CVE-2026-50695 7.5CVE-2026-50696 7.5CVE-2026-54119 7.5CVE-2026-40378 7.5CVE-2026-49787 7.5CVE-2026-49788 7.5CVE-2026-50304 7.5CVE-2026-50368 7.5CVE-2026-50355 7.5CVE-2026-50411 7.5CVE-2026-50647 7.5CVE-2026-58627 7.5CVE-2026-50424 7.5CVE-2026-47302 7.5CVE-2026-50652 7.5CVE-2026-50653 7.5CVE-2026-50525 7.5CVE-2026-50527 7.5CVE-2026-50648 7.5CVE-2026-49160 7.5CVE-2025-21330 7.5CVE-2024-49075 7.5CVE-2026-35424 7.5+22 more
Spoofing40
The attacker impersonates a user, system, or piece of content to trick a victim. Common in phishing and man-in-the-middle scenarios.
40 CVEs this release, highest CVSS first:
CVE-2026-55008 9.6CVE-2026-56181 8.3CVE-2026-47631 8.1CVE-2026-55021 7.3CVE-2026-55034 7.3CVE-2026-55126 7.3CVE-2026-45481 7.3CVE-2026-47634 7.3CVE-2026-54108 6.5CVE-2026-50659 6.5CVE-2026-50508 6.5CVE-2026-45501 6.5CVE-2026-45500 6.1CVE-2026-56157 5.4CVE-2026-45453 5.4CVE-2026-47636 5.4CVE-2026-47639 5.4CVE-2026-33113 5.4CVE-2026-45464 5.4CVE-2026-45465 5.4CVE-2026-48560 5.4CVE-2026-50684 4.8CVE-2026-55016 4.6CVE-2026-55019 4.6+16 more
Security Feature Bypass31
The attacker gets around a built-in protection such as SmartScreen, authentication, or an exploit mitigation. Usually dangerous in combination with another flaw.
31 CVEs this release, highest CVSS first:
CVE-2026-55040 9.1CVE-2026-50528 8.2CVE-2026-47304 8.1CVE-2026-45588 7.9CVE-2026-48568 7.9CVE-2026-48570 7.9CVE-2026-48573 7.9CVE-2026-48575 7.9CVE-2026-48576 7.9CVE-2026-48578 7.9CVE-2026-45654 7.9CVE-2026-47656 7.9CVE-2026-49783 7.8CVE-2026-45656 7.8CVE-2026-8863 7.8CVE-2026-45658 7.8CVE-2026-50507 6.8CVE-2026-45585 6.8CVE-2026-41097 6.7CVE-2026-35422 6.5CVE-2026-57097 6.4CVE-2026-50661 6.1CVE-2026-58638 6.0CVE-2026-58614 5.5+7 more
Tampering7
The attacker modifies data or code without authorization, undermining the integrity of the system.
7 CVEs this release, highest CVSS first:
CVE-2026-45602 9.1CVE-2026-50328 7.5CVE-2026-55144 7.1CVE-2026-50465 7.1CVE-2026-50526 7.0CVE-2026-49174 6.1CVE-2026-50495 6.1
Other4
Other or uncategorized impact types in this release.
4 CVEs this release, highest CVSS first:
CVE-2025-10263 9.3CVE-2026-42829 7.8CVE-2026-50418 5.1CVE-2025-54518
Most-affected products
.NET 8.0 installed on Windows22
22 CVEs this release, highest CVSS first:
CVE-2026-47300 8.8CVE-2026-47303 8.8CVE-2026-50528 8.2CVE-2026-47304 8.1CVE-2026-50646 7.8CVE-2026-50649 7.8CVE-2026-50650 7.8CVE-2026-47302 7.5CVE-2026-50652 7.5CVE-2026-50653 7.5CVE-2026-50304 7.5CVE-2026-50368 7.5CVE-2026-50355 7.5CVE-2026-50411 7.5CVE-2026-50525 7.5CVE-2026-50527 7.5CVE-2026-50647 7.5CVE-2026-50648 7.5CVE-2026-50524 7.5CVE-2026-56170 7.5CVE-2026-50651 7.5CVE-2026-57108 7.5CVE-2026-50526 7.0CVE-2026-50659 6.5+1 more
.NET 10.0 installed on Windows18
18 CVEs this release, highest CVSS first:
CVE-2026-47304 8.1CVE-2026-50646 7.8CVE-2026-50649 7.8CVE-2026-50650 7.8CVE-2026-47302 7.5CVE-2026-50652 7.5CVE-2026-50653 7.5CVE-2026-50304 7.5CVE-2026-50368 7.5CVE-2026-50355 7.5CVE-2026-50411 7.5CVE-2026-50525 7.5CVE-2026-50527 7.5CVE-2026-50647 7.5CVE-2026-50648 7.5CVE-2026-50659 6.5CVE-2026-50324 5.9
.NET 8.0 installed on Mac OS18
18 CVEs this release, highest CVSS first:
CVE-2026-47304 8.1CVE-2026-50646 7.8CVE-2026-50649 7.8CVE-2026-50650 7.8CVE-2026-47302 7.5CVE-2026-50652 7.5CVE-2026-50653 7.5CVE-2026-50304 7.5CVE-2026-50368 7.5CVE-2026-50355 7.5CVE-2026-50411 7.5CVE-2026-50525 7.5CVE-2026-50527 7.5CVE-2026-50647 7.5CVE-2026-50648 7.5CVE-2026-50659 6.5CVE-2026-50324 5.9
Windows 10 Version 1809 for 32-bit Systems14
14 CVEs this release, highest CVSS first:
CVE-2026-57092 9.9CVE-2026-42990 9.8CVE-2026-49172 9.8CVE-2026-50447 9.8CVE-2026-50518 9.8CVE-2026-56159 9.8CVE-2026-56190 9.8CVE-2026-56188 9.8CVE-2026-54990 9.8CVE-2026-45657 9.8CVE-2026-47291 9.8CVE-2026-44815 9.8CVE-2026-41096 9.8CVE-2026-50380 9.6CVE-2026-42904 9.6CVE-2026-49798 9.3CVE-2025-10263 9.3CVE-2026-45602 9.1CVE-2026-54107 8.8CVE-2026-54982 8.8CVE-2026-54999 8.8CVE-2026-58608 8.8CVE-2026-48564 8.8CVE-2026-49178 8.8+577 more
Windows 10 Version 1809 for x64-based Systems14
14 CVEs this release, highest CVSS first:
CVE-2026-57092 9.9CVE-2026-42990 9.8CVE-2026-49172 9.8CVE-2026-50447 9.8CVE-2026-50518 9.8CVE-2026-56159 9.8CVE-2026-56190 9.8CVE-2026-56188 9.8CVE-2026-54990 9.8CVE-2026-45657 9.8CVE-2026-47291 9.8CVE-2026-44815 9.8CVE-2026-41096 9.8CVE-2026-50380 9.6CVE-2026-42904 9.6CVE-2026-49798 9.3CVE-2025-10263 9.3CVE-2026-45602 9.1CVE-2026-54107 8.8CVE-2026-54982 8.8CVE-2026-54999 8.8CVE-2026-58608 8.8CVE-2026-48564 8.8CVE-2026-49178 8.8+577 more
Windows Server 201914
14 CVEs this release, highest CVSS first:
CVE-2026-57092 9.9CVE-2026-42990 9.8CVE-2026-49172 9.8CVE-2026-50447 9.8CVE-2026-50518 9.8CVE-2026-56159 9.8CVE-2026-56190 9.8CVE-2026-56188 9.8CVE-2026-54990 9.8CVE-2026-45657 9.8CVE-2026-47291 9.8CVE-2026-44815 9.8CVE-2026-41096 9.8CVE-2026-50380 9.6CVE-2026-42904 9.6CVE-2026-49798 9.3CVE-2025-10263 9.3CVE-2026-45602 9.1CVE-2026-54107 8.8CVE-2026-54982 8.8CVE-2026-54999 8.8CVE-2026-58608 8.8CVE-2026-48564 8.8CVE-2026-49178 8.8+577 more
Microsoft SQL Server 2022 for x64-based Systems (CU 25)10
10 CVEs this release, highest CVSS first:
CVE-2026-54118 8.8CVE-2026-55002 8.8CVE-2026-47295 8.8CVE-2026-54117 8.8CVE-2026-47296 7.5CVE-2026-50468 6.5CVE-2026-54116 6.5
Microsoft SQL Server 2025 for x64-based Systems (CU6)10
10 CVEs this release, highest CVSS first:
CVE-2026-54118 8.8CVE-2026-55002 8.8CVE-2026-47295 8.8CVE-2026-54117 8.8CVE-2026-47296 7.5CVE-2026-50468 6.5CVE-2026-54116 6.5
By the numbers
- 69 updates (KB articles), on the Microsoft Security Update Guide
- 533 CVEs fixed
- 24 Critical-severity updates
- 4 actively exploited (CISA KEV)
- 0 ransomware-linked
Upcoming Patch Tuesday dates
Microsoft ships updates on the second Tuesday of each month. Add them to your calendar in one click.
- September 8, 2026GoogleOutlook.ics
- October 13, 2026GoogleOutlook.ics
- November 10, 2026GoogleOutlook.ics
- December 8, 2026GoogleOutlook.ics
- January 12, 2027GoogleOutlook.ics
- February 9, 2027GoogleOutlook.ics
- March 9, 2027GoogleOutlook.ics
- April 13, 2027GoogleOutlook.ics
- May 11, 2027GoogleOutlook.ics
- June 8, 2027GoogleOutlook.ics
- July 13, 2027GoogleOutlook.ics
- August 10, 2027GoogleOutlook.ics
Patch Tuesday history
Every month since we started tracking, newest first. Tracking 25 releases, 1,180 updates and 64 actively-exploited CVEs in total.
| Month | Updates | CVEs | Exploited | Ransomware | Critical |
|---|---|---|---|---|---|
| July 2026 | 69 | 533 | 4 | 0 | 24 |
| June 2026 | 37 | 172 | 0 | 0 | 22 |
| May 2026 | 69 | 95 | 2 | 1 | 19 |
| April 2026 | 64 | 152 | 2 | 0 | 21 |
| March 2026 | 39 | 61 | 0 | 0 | 0 |
| February 2026 | 29 | 38 | 5 | 0 | 0 |
| January 2026 | 27 | 108 | 3 | 0 | 11 |
| December 2025 | 55 | 54 | 1 | 0 | 21 |
| November 2025 | 52 | 51 | 2 | 0 | 30 |
| October 2025 | 66 | 155 | 4 | 0 | 17 |
| September 2025 | 38 | 77 | 0 | 0 | 0 |
| August 2025 | 84 | 95 | 0 | 0 | 36 |
| July 2025 | 51 | 125 | 3 | 3 | 17 |
| June 2025 | 47 | 57 | 2 | 0 | 0 |
| May 2025 | 34 | 58 | 5 | 0 | 0 |
| April 2025 | 35 | 107 | 1 | 1 | 0 |
| March 2025 | 33 | 48 | 7 | 1 | 0 |
| February 2025 | 25 | 45 | 2 | 0 | 0 |
| January 2025 | 47 | 148 | 3 | 0 | 15 |
| December 2024 | 45 | 69 | 1 | 0 | 23 |
| November 2024 | 35 | 78 | 2 | 1 | 9 |
| October 2024 | 72 | 104 | 4 | 1 | 34 |
| September 2024 | 46 | 71 | 4 | 0 | 1 |
| August 2024 | 49 | 71 | 6 | 0 | 15 |
| July 2024 | 32 | 49 | 1 | 0 | 0 |
Month-by-month recap
Expand any month for a plain-English summary of that Patch Tuesday.
July 2026533 CVEs fixed4 exploited
The July 2026 Microsoft Patch Tuesday shipped 69 updates (KB articles) fixing 533 CVEs, 24 of them rated Critical severity. 4 were already being exploited in the wild (on the CISA KEV list) and needed patching first.
June 2026172 CVEs fixed
The June 2026 Microsoft Patch Tuesday shipped 37 updates (KB articles) fixing 172 CVEs, 22 of them rated Critical severity. None from this release were on the CISA KEV exploited list at the time.
May 202695 CVEs fixed2 exploited
The May 2026 Microsoft Patch Tuesday shipped 69 updates (KB articles) fixing 95 CVEs, 19 of them rated Critical severity. 2 were already being exploited in the wild (on the CISA KEV list) and needed patching first. 1 was linked to ransomware activity.
April 2026152 CVEs fixed2 exploited
The April 2026 Microsoft Patch Tuesday shipped 64 updates (KB articles) fixing 152 CVEs, 21 of them rated Critical severity. 2 were already being exploited in the wild (on the CISA KEV list) and needed patching first.
March 202661 CVEs fixed
The March 2026 Microsoft Patch Tuesday shipped 39 updates (KB articles) fixing 61 CVEs, 0 of them rated Critical severity. None from this release were on the CISA KEV exploited list at the time.
February 202638 CVEs fixed5 exploited
The February 2026 Microsoft Patch Tuesday shipped 29 updates (KB articles) fixing 38 CVEs, 0 of them rated Critical severity. 5 were already being exploited in the wild (on the CISA KEV list) and needed patching first.
January 2026108 CVEs fixed3 exploited
The January 2026 Microsoft Patch Tuesday shipped 27 updates (KB articles) fixing 108 CVEs, 11 of them rated Critical severity. 3 were already being exploited in the wild (on the CISA KEV list) and needed patching first.
December 202554 CVEs fixed1 exploited
The December 2025 Microsoft Patch Tuesday shipped 55 updates (KB articles) fixing 54 CVEs, 21 of them rated Critical severity. 1 was already being exploited in the wild (on the CISA KEV list) and needed patching first.
November 202551 CVEs fixed2 exploited
The November 2025 Microsoft Patch Tuesday shipped 52 updates (KB articles) fixing 51 CVEs, 30 of them rated Critical severity. 2 were already being exploited in the wild (on the CISA KEV list) and needed patching first.
October 2025155 CVEs fixed4 exploited
The October 2025 Microsoft Patch Tuesday shipped 66 updates (KB articles) fixing 155 CVEs, 17 of them rated Critical severity. 4 were already being exploited in the wild (on the CISA KEV list) and needed patching first.
September 202577 CVEs fixed
The September 2025 Microsoft Patch Tuesday shipped 38 updates (KB articles) fixing 77 CVEs, 0 of them rated Critical severity. None from this release were on the CISA KEV exploited list at the time.
August 202595 CVEs fixed
The August 2025 Microsoft Patch Tuesday shipped 84 updates (KB articles) fixing 95 CVEs, 36 of them rated Critical severity. None from this release were on the CISA KEV exploited list at the time.
July 2025125 CVEs fixed3 exploited
The July 2025 Microsoft Patch Tuesday shipped 51 updates (KB articles) fixing 125 CVEs, 17 of them rated Critical severity. 3 were already being exploited in the wild (on the CISA KEV list) and needed patching first. 3 were linked to ransomware activity.
June 202557 CVEs fixed2 exploited
The June 2025 Microsoft Patch Tuesday shipped 47 updates (KB articles) fixing 57 CVEs, 0 of them rated Critical severity. 2 were already being exploited in the wild (on the CISA KEV list) and needed patching first.
May 202558 CVEs fixed5 exploited
The May 2025 Microsoft Patch Tuesday shipped 34 updates (KB articles) fixing 58 CVEs, 0 of them rated Critical severity. 5 were already being exploited in the wild (on the CISA KEV list) and needed patching first.
April 2025107 CVEs fixed1 exploited
The April 2025 Microsoft Patch Tuesday shipped 35 updates (KB articles) fixing 107 CVEs, 0 of them rated Critical severity. 1 was already being exploited in the wild (on the CISA KEV list) and needed patching first. 1 was linked to ransomware activity.
March 202548 CVEs fixed7 exploited
The March 2025 Microsoft Patch Tuesday shipped 33 updates (KB articles) fixing 48 CVEs, 0 of them rated Critical severity. 7 were already being exploited in the wild (on the CISA KEV list) and needed patching first. 1 was linked to ransomware activity.
February 202545 CVEs fixed2 exploited
The February 2025 Microsoft Patch Tuesday shipped 25 updates (KB articles) fixing 45 CVEs, 0 of them rated Critical severity. 2 were already being exploited in the wild (on the CISA KEV list) and needed patching first.
January 2025148 CVEs fixed3 exploited
The January 2025 Microsoft Patch Tuesday shipped 47 updates (KB articles) fixing 148 CVEs, 15 of them rated Critical severity. 3 were already being exploited in the wild (on the CISA KEV list) and needed patching first.
December 202469 CVEs fixed1 exploited
The December 2024 Microsoft Patch Tuesday shipped 45 updates (KB articles) fixing 69 CVEs, 23 of them rated Critical severity. 1 was already being exploited in the wild (on the CISA KEV list) and needed patching first.
November 202478 CVEs fixed2 exploited
The November 2024 Microsoft Patch Tuesday shipped 35 updates (KB articles) fixing 78 CVEs, 9 of them rated Critical severity. 2 were already being exploited in the wild (on the CISA KEV list) and needed patching first. 1 was linked to ransomware activity.
October 2024104 CVEs fixed4 exploited
The October 2024 Microsoft Patch Tuesday shipped 72 updates (KB articles) fixing 104 CVEs, 34 of them rated Critical severity. 4 were already being exploited in the wild (on the CISA KEV list) and needed patching first. 1 was linked to ransomware activity.
September 202471 CVEs fixed4 exploited
The September 2024 Microsoft Patch Tuesday shipped 46 updates (KB articles) fixing 71 CVEs, 1 of them rated Critical severity. 4 were already being exploited in the wild (on the CISA KEV list) and needed patching first.
August 202471 CVEs fixed6 exploited
The August 2024 Microsoft Patch Tuesday shipped 49 updates (KB articles) fixing 71 CVEs, 15 of them rated Critical severity. 6 were already being exploited in the wild (on the CISA KEV list) and needed patching first.
July 202449 CVEs fixed1 exploited
The July 2024 Microsoft Patch Tuesday shipped 32 updates (KB articles) fixing 49 CVEs, 0 of them rated Critical severity. 1 was already being exploited in the wild (on the CISA KEV list) and needed patching first.
Trusted Patch Tuesday resources
The analyses the security community reads each month. Cross-reference these with the ranked view above.
Frequently asked questions
What is Patch Tuesday?
Patch Tuesday is the second Tuesday of each month, when Microsoft releases its scheduled security updates across Windows, Office, Exchange, SharePoint, and the rest of the Microsoft 365, Intune, Defender, and Entra ID stack. Out-of-band updates ship between Patch Tuesdays when a fix cannot wait, and this page covers both. Senserva ranks each release by what attackers are actually exploiting, ties every CVE to the KB that fixes it, and, in your own tenant, tells you which of these updates are actually missing on your devices.
When is the next Patch Tuesday?
The next Microsoft Patch Tuesday is September 8, 2026. It falls on the second Tuesday of every month; upcoming dates are listed on this page.
What was in the latest Patch Tuesday?
The July 2026 release included 69 updates (KBs) fixing 533 CVEs, of which 4 are actively exploited (CISA KEV). The exploited CVEs, the highest-risk CVEs, and the full history are on this page.
Which Patch Tuesday updates should I install first?
Install the actively-exploited (CISA KEV) fixes first, then the highest EPSS and CVSS ones, then the rest. This page ranks every release that way, and Senserva applies the same order to the updates actually missing on your own devices.
What is a zero-day on Patch Tuesday?
A zero-day is a vulnerability already being exploited (or publicly disclosed) before a patch was available. Those are the CVEs to patch immediately; this page calls out the actively-exploited ones each month.
How often is this page updated?
Automatically, every day. The data refreshes from Microsoft MSRC, CISA KEV, and FIRST.org EPSS, and the month-by-month history is preserved so the archive only grows.
Is this Patch Tuesday tracker free?
Yes, free with no sign-in. Running Senserva adds the part a public page cannot: which of these updates are actually missing on your devices, ranked, so you fix the right things first.
Can I use this Patch Tuesday data with my own AI?
Yes. A free copy-paste AI prompt just under the exploited-CVE list is composed from this release: the update and CVE counts, and the actively-exploited CVE names with their CVSS scores. Paste it into Claude, ChatGPT, or Copilot to get a first-24-hours plan and a team briefing in your own words.
The Microsoft CVE and patch resource center
Everything here is free, refreshed twice a day (5 AM and 3 PM US Central), and cross-linked. Start with this month, then drill into any CVE, KB, product, or month since tracking began.
Data access: Patch Tuesday RSS · JSON patch API · calendar (.ics). Plus a page for every CVE and KB, linked throughout. JSON and RSS feeds included, no login required: all feeds and the API.
Reference: the Microsoft patching guide, how Intune, Windows Autopatch, Defender, and Azure Update Manager fit together, and where third-party patch vendors fit in.
Data notice: this page, the feeds, and the API are provided as is, for informational purposes only, without warranty of any kind. Senserva, LLC does not guarantee the accuracy, completeness, or timeliness of third-party data and accepts no liability for actions taken based on it; verify against the primary source before acting. All use of this data is subject to the Senserva EULA.