Microsoft Patch Tuesday, ranked by what is actually exploited
Every Microsoft Patch Tuesday and out-of-band update, with the CVEs each one fixes ranked by real-world risk: actively exploited (CISA KEV) first, then EPSS exploit probability and CVSS severity. The latest release is below, followed by a month-by-month history. Next Patch Tuesday: July 14, 2026.
Latest: June 2026
Tracking 24 Patch Tuesdays, 905 updates and 79 actively-exploited CVEs in total.
Patch Tuesday history
Every month since we started tracking, newest first. Counts are unique per month; the exploited and ransomware columns come from CISA KEV.
| Month | Updates | CVEs | Exploited | Ransomware | Critical |
|---|---|---|---|---|---|
| June 2026 | 33 | 244 | 1 | 0 | 15 |
| May 2026 | 55 | 127 | 0 | 0 | 9 |
| April 2026 | 53 | 153 | 2 | 0 | 10 |
| March 2026 | 38 | 61 | 0 | 0 | 0 |
| February 2026 | 29 | 39 | 5 | 0 | 0 |
| January 2026 | 27 | 109 | 3 | 0 | 11 |
| December 2025 | 55 | 224 | 6 | 0 | 21 |
| November 2025 | 16 | 11 | 0 | 0 | 0 |
| October 2025 | 57 | 139 | 4 | 0 | 11 |
| September 2025 | 30 | 61 | 0 | 0 | 0 |
| August 2025 | 67 | 243 | 5 | 0 | 28 |
| July 2025 | 37 | 64 | 5 | 3 | 5 |
| June 2025 | 31 | 99 | 7 | 0 | 0 |
| May 2025 | 18 | 40 | 4 | 0 | 0 |
| April 2025 | 35 | 110 | 1 | 1 | 0 |
| March 2025 | 33 | 86 | 9 | 1 | 0 |
| February 2025 | 17 | 45 | 2 | 0 | 0 |
| January 2025 | 44 | 149 | 3 | 0 | 14 |
| December 2024 | 27 | 70 | 1 | 0 | 16 |
| November 2024 | 34 | 82 | 2 | 1 | 9 |
| October 2024 | 43 | 105 | 3 | 0 | 11 |
| September 2024 | 45 | 165 | 6 | 0 | 5 |
| August 2024 | 49 | 157 | 8 | 0 | 24 |
| July 2024 | 32 | 50 | 2 | 1 | 0 |
What is Patch Tuesday?
Patch Tuesday is the second Tuesday of each month, when Microsoft releases its scheduled security updates across Windows, Office, Exchange, and the rest of the Microsoft 365, Intune, Defender, and Entra ID stack. Out-of-band updates ship between Patch Tuesdays when a fix cannot wait. Senserva ranks each release by what attackers are actually exploiting, ties every CVE to the KB that fixes it, and, in your own tenant, tells you which of these updates are actually missing on your devices.
Frequently asked questions
What is Patch Tuesday?
Patch Tuesday is the second Tuesday of each month, when Microsoft releases its scheduled security updates for Windows, Office, Exchange, and the rest of the Microsoft stack. Critical fixes can also ship out-of-band between Patch Tuesdays. This page covers both.
When is the next Patch Tuesday?
The next Microsoft Patch Tuesday is July 14, 2026. It falls on the second Tuesday of every month.
What was in the latest Patch Tuesday?
The June 2026 release included 33 updates (KBs) fixing 244 CVEs, of which 1 are actively exploited (CISA KEV). The full ranked breakdown and every prior month are on this page.
How are the patches ranked?
By what is actually exploited, not just severity. Actively-exploited CVEs (CISA KEV) come first, then FIRST.org EPSS exploit probability, then CVSS severity. This surfaces the handful attackers are really using.
How often is this updated?
Automatically. The data refreshes daily from Microsoft MSRC, CISA KEV, and FIRST.org EPSS, and the history is preserved month by month so the archive only grows.