Patch and vulnerability tracker / Microsoft Patch Tuesday

Microsoft Patch Tuesday August 2026: every CVE and patch, ranked by risk

The front page of Microsoft patching: every CVE and the update (KB) that fixes it, the day it ships. August 2026 shipped 67 updates fixing 751 CVEs, 108 of them Critical Severity and 1 already confirmed exploited in the wild. Senserva holds 26 months of releases this way, every month measured the same, so a spike is visible rather than asserted. Zero-days are called out by name, each release is ranked by what attackers actually exploit, and every KB links its own page with the download, the known issues Microsoft documents, a PowerShell installed-check, and the newer package that supersedes it when one has shipped. Patch Tuesday trends, the full history, calendar, and feeds live here, alongside the voices of the other Patch Tuesday trackers we follow. Next Patch Tuesday: September 8, 2026, in 9 days.

Data refreshed once a day: 5 AM and 3 PM US Central.

Senserva is a Microsoft Intelligent Security Association memberOpen the full patch tracker

This Patch TuesdayELEVATEDbecause 1 CVE is already being exploited in the wildNext: September 8, 2026 (9 days)

August 2026 at a glance

Microsoft shipped 67 updates fixing 751 CVEs this release.
67
Updates (KBs)
751
CVEs fixed
1
Exploited zero-day, new this release
4
On the CISA KEV list
0
Ransomware-linked
108
Critical, rated by Microsoft

Figures are Microsoft's own, from MSRC CVRF 2026-Aug, read on 2026-08-11. Microsoft's Severity split covers 743 of the 751; 8 carry no rating. Senserva tracks 358 of them against update articles we hold pages for; the difference is largely Azure Linux entries that ship no KB article.

See the historySubscribe (RSS)

SenservaSenserva Watch is free: alerts on the CVEs and patches you follow, and Three Free Unlimited Audits of every tenant you manage.Join Senserva Watch
The Senserva AI read pre-beta

This month opens with an actively exploited zero-day: CVE-2026-68820 in the Windows Ancillary Function Driver for WinSock. This is not a reassuring month, exploitation is already happening in the wild. Patch this first. Two more zero-days, CVE-2026-62832 (Windows User Profile Service) and CVE-2026-72971 (Windows Container Isolation FS Filter Driver), were publicly disclosed before fixes shipped and should be treated as high priority as well. Microsoft fixed 751 CVEs total, with 108 rated Critical. One CVE, CVE-2026-68820, also appears on the CISA KEV catalog, but that catalog measures something different from Microsoft's exploited count and a low KEV number never means nothing else is being exploited.

Compared to the trailing 12 month averages of 133 CVEs, 18 Critical, and 2 exploited, this release is far larger in scope and Critical volume, while confirmed exploitation sits close to typical levels. That combination argues for treating this as an above average workload month: prioritize the exploited and publicly disclosed zero-days immediately, then work through the Critical-rated fixes, rather than assuming the smaller KEV figure signals a quiet month.

Pre-beta. Generated by Senserva AI from the live release data on this page, 2026-08-30. Regenerated when the data changes. The human take is above.
Take this release to your AI

Composed from the live August 2026 release data above, refreshed once a day (5 AM US Central). Copy it into Claude, ChatGPT, or Copilot. Free, no sign-in.

What those we follow are saying

Verbatim headlines from the trusted Patch Tuesday sources, pulled live from their own feeds (as of 2026-08-30). Items that name a CVE are also linked from that CVE's row above. For our own opinion, read the Senserva take on the blog.

“PaperCut NG/MF vulnerabilities exploited in zero-day attacks”Help Net Security, 2026-08-27 · CVE-2026-82078, CVE-2026-81578
“Edge infrastructure under siege: what two independent datasets reveal about who's exploiting your perimeter”Tenable, 2026-08-26 · CVE-2026-15409, CVE-2023-42793, CVE-2024-3400, CVE-2024-24919

Critical is rarer, and bigger

Every Microsoft update we track, grouped by the severity Microsoft assigned it, across 1,028 updates and 3,055 distinct CVEs (as of 2026-08-30). The count is UPDATES, not CVE fixes, and the difference matters: Important updates outnumber Critical ones, but a Critical update carries several times as many CVE fixes, because it is usually a cumulative one. So a Critical month is not just more urgent, it is a wider deployment. Counts per update are under each bar. The bars add up to 1,044 rather than 1,028 because 16 updates were rated at more than one severity.

Important740

9,381 CVE fixes, 12.7 per update

Critical234

16,645 CVE fixes, 71.1 per update

Moderate70

83 CVE fixes, 1.2 per update

Actively exploited this release

These are the August 2026 CVEs already being exploited in the wild (on the CISA KEV list). Patch them first, everywhere.

CVE-2026-50522CriticalMicrosoft SharePoint Remote Code Execution VulnerabilityCVSS 9.8

A Remote Code Execution vulnerability affecting Microsoft SharePoint Enterprise Server 2016.

Affects: Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition

References: Microsoft · NVD · Tenable · Patch Tuesday coverage

CVE-2026-55040CriticalMicrosoft SharePoint Server Security Feature Bypass VulnerabilityCVSS 9.1

A Security Feature Bypass vulnerability affecting Microsoft SharePoint Enterprise Server 2016.

Affects: Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition

References: Microsoft · NVD · Tenable · Patch Tuesday coverage

CVE-2026-68820HighWindows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityCVSS 7.0

An Elevation of Privilege vulnerability affecting Windows 10 Version 1809 for 32-bit Systems.

Affects: Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019

References: Microsoft · NVD · Tenable · Patch Tuesday coverage

Covering this CVE: Qualys · Tenable · Zero Day Initiative

CVE-2026-56164MediumMicrosoft SharePoint Server Elevation of Privilege VulnerabilityCVSS 5.3

An Elevation of Privilege vulnerability affecting Microsoft SharePoint Enterprise Server 2016.

Affects: Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition

References: Microsoft · NVD · Tenable · Patch Tuesday coverage

Highest-risk fixes this release

Not yet flagged as exploited, but critical-severity (CVSS 8.8+) and worth prioritizing.

CVE-2026-62878CriticalWindows DNS Server Remote Code Execution VulnerabilityCVSS 9.8

A Remote Code Execution vulnerability affecting Windows 10 Version 1809 for 32-bit Systems.

Affects: Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019

References: Microsoft · NVD · Tenable · Patch Tuesday coverage

Covering this CVE: Zero Day Initiative

CVE-2026-62893CriticalWindows Deployment Services TFTP Server Remote Code Execution VulnerabilityCVSS 9.8

A Remote Code Execution vulnerability affecting Windows 10 Version 1809 for 32-bit Systems.

Affects: Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019

References: Microsoft · NVD · Tenable · Patch Tuesday coverage

Covering this CVE: Zero Day Initiative

CVE-2026-65791CriticalWindows iSCSI Target Service Remote Code Execution VulnerabilityCVSS 9.8

A Remote Code Execution vulnerability affecting Windows 10 Version 1809 for 32-bit Systems.

Affects: Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019

References: Microsoft · NVD · Tenable · Patch Tuesday coverage

CVE-2026-62815CriticalMicrosoft QUIC Remote Code Execution VulnerabilityCVSS 9.8

A Remote Code Execution vulnerability affecting Windows Server 2022.

Affects: Windows Server 2022, Windows Server 2022 (Server Core installation), Windows Server 2025 (Server Core installation)

References: Microsoft · NVD · Tenable · Patch Tuesday coverage

Covering this CVE: Zero Day Initiative

CVE-2026-42990CriticalSQL Server ODBC driver Elevation of Privilege VulnerabilityCVSS 9.8

A Remote Code Execution vulnerability affecting Windows 10 Version 1809 for 32-bit Systems.

Affects: Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019

References: Microsoft · NVD · Tenable · Patch Tuesday coverage

CVE-2026-44815CriticalDHCP Client Service Remote Code Execution VulnerabilityCVSS 9.8

A Remote Code Execution vulnerability affecting Windows 10 Version 1809 for 32-bit Systems.

Affects: Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019

References: Microsoft · NVD · Tenable · Patch Tuesday coverage

CVE-2026-45657CriticalWindows Kernel Remote Code Execution VulnerabilityCVSS 9.8

A Remote Code Execution vulnerability affecting Windows Server 2022.

Affects: Windows Server 2022, Windows Server 2022 (Server Core installation), Windows Server 2025 (Server Core installation)

References: Microsoft · NVD · Tenable · Patch Tuesday coverage

CVE-2026-47291CriticalHTTP.sys Remote Code Execution VulnerabilityCVSS 9.8

A Remote Code Execution vulnerability affecting Windows 10 Version 1809 for 32-bit Systems.

Affects: Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019

References: Microsoft · NVD · Tenable · Patch Tuesday coverage

CVE-2026-42904CriticalWindows TCP/IP Elevation of Privilege VulnerabilityCVSS 9.6

An Elevation of Privilege vulnerability affecting Windows Server 2022.

Affects: Windows Server 2022, Windows Server 2022 (Server Core installation), Windows 10 Version 21H2 for 32-bit Systems

References: Microsoft · NVD · Tenable · Patch Tuesday coverage

CVE-2026-70306CriticalMicrosoft Office SharePoint Spoofing VulnerabilityCVSS 9.3

A Spoofing vulnerability affecting Microsoft SharePoint Enterprise Server 2016.

Affects: Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition

References: Microsoft · NVD · Tenable · Patch Tuesday coverage

CVE-2025-10263CriticalARM: CVE-2025-10263 Completion of affected memory accesses might not be guaranteed by comp...CVSS 9.3

An Elevation of Privilege vulnerability affecting Windows 11 Version 26H1 for ARM64-based Systems.

Affects: Windows 11 Version 26H1 for ARM64-based Systems, Windows 10 Version 21H2 for ARM64-based Systems, Windows 10 Version 22H2 for ARM64-based Systems

References: Microsoft · NVD · Tenable · Patch Tuesday coverage

CVE-2026-45602CriticalWindows Dynamic Host Configuration Protocol (DHCP) Tampering VulnerabilityCVSS 9.1

A Tampering vulnerability affecting Windows 10 Version 1809 for 32-bit Systems.

Affects: Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019

References: Microsoft · NVD · Tenable · Patch Tuesday coverage

August 2026 breakdown

What Microsoft fixed this release, by impact type and by product. Expand any row for what it means and the CVEs behind it, each linked to its full page.

By impact type

Elevation of Privilege249
Remote Code Execution162
Information Disclosure103
Other24
Denial of Service24
Security Feature Bypass23
Spoofing14

The attacker impersonates a user, system, or piece of content to trick a victim. Common in phishing and man-in-the-middle scenarios.

14 CVEs this release, highest CVSS first:

CVE-2026-70306 9.3CVE-2026-56179 8.3CVE-2026-57105 8.0CVE-2026-55021 7.3CVE-2026-55034 7.3CVE-2026-55126 7.3CVE-2026-64900 7.3CVE-2026-62914 7.3CVE-2026-54108 6.5CVE-2026-50508 6.5CVE-2026-58639 6.5CVE-2026-62839 6.5CVE-2026-63516 6.5CVE-2026-56157 5.4

Tampering5

The attacker modifies data or code without authorization, undermining the integrity of the system.

5 CVEs this release, highest CVSS first:

CVE-2026-45602 9.1CVE-2026-62750 6.5CVE-2026-63512 6.5CVE-2026-61928 5.5CVE-2026-72971 5.5

Most-affected products

Windows 10 Version 1809 for x64-based Systems23
Microsoft .NET Framework 4.8 on Windows Server 2016 (Server Core installation)18
Microsoft .NET Framework 4.8 on Windows 10 Version 1607 for x64-based Systems18
Microsoft .NET Framework 4.8 on Windows Server 201618
Windows Server 202212
Windows Server 2022 (Server Core installation)12
Windows 10 Version 1809 for 32-bit Systems11
Windows Server 201911

By the numbers

Upcoming Patch Tuesday dates

Microsoft ships updates on the second Tuesday of each month. Add them to your calendar in one click.

Add all upcoming dates to your calendar (.ics)

Patch Tuesday history

Every month since we started tracking, newest first. Tracking 26 releases, 1,247 updates and 67 actively-exploited CVEs in total.

5404052701350July 2024: 49 CVEs, 0 Critical, 1 exploited, 0 ransomware-linkedJul24August 2024: 71 CVEs, 15 Critical, 6 exploited, 0 ransomware-linkedSeptember 2024: 71 CVEs, 1 Critical, 4 exploited, 0 ransomware-linkedOctober 2024: 104 CVEs, 34 Critical, 4 exploited, 1 ransomware-linkedOct24November 2024: 78 CVEs, 9 Critical, 2 exploited, 1 ransomware-linkedDecember 2024: 69 CVEs, 23 Critical, 1 exploited, 0 ransomware-linkedJanuary 2025: 148 CVEs, 15 Critical, 3 exploited, 0 ransomware-linkedJan25February 2025: 45 CVEs, 0 Critical, 2 exploited, 0 ransomware-linkedMarch 2025: 50 CVEs, 0 Critical, 7 exploited, 1 ransomware-linkedApril 2025: 107 CVEs, 0 Critical, 1 exploited, 1 ransomware-linkedApr25May 2025: 58 CVEs, 0 Critical, 5 exploited, 0 ransomware-linkedJune 2025: 58 CVEs, 0 Critical, 2 exploited, 0 ransomware-linkedJuly 2025: 125 CVEs, 17 Critical, 3 exploited, 3 ransomware-linkedJul25August 2025: 98 CVEs, 36 Critical, 0 exploited, 0 ransomware-linkedSeptember 2025: 77 CVEs, 0 Critical, 0 exploited, 0 ransomware-linkedOctober 2025: 153 CVEs, 17 Critical, 4 exploited, 0 ransomware-linkedOct25November 2025: 51 CVEs, 30 Critical, 2 exploited, 1 ransomware-linkedDecember 2025: 63 CVEs, 21 Critical, 1 exploited, 0 ransomware-linkedJanuary 2026: 108 CVEs, 11 Critical, 3 exploited, 0 ransomware-linkedJan26February 2026: 39 CVEs, 0 Critical, 5 exploited, 0 ransomware-linkedMarch 2026: 61 CVEs, 0 Critical, 0 exploited, 0 ransomware-linkedApril 2026: 152 CVEs, 21 Critical, 3 exploited, 0 ransomware-linkedApr26May 2026: 96 CVEs, 19 Critical, 2 exploited, 1 ransomware-linkedJune 2026: 162 CVEs, 22 Critical, 0 exploited, 0 ransomware-linkedJuly 2026: 540 CVEs, 34 Critical, 5 exploited, 0 ransomware-linkedJul26August 2026: 358 CVEs, 25 Critical, 1 exploited, 0 ransomware-linked
CVEs fixed Actively exploited Critical Ransomware-linked
MonthUpdatesCVEsExploitedRansomwareCritical
August 2026723581025
July 2026695405034
June 2026331620022
May 202669962119
April 2026641523021
March 20263961000
February 20262939500
January 2026271083011
December 202555631021
November 202552512130
October 2025651534017
September 20253877000
August 202584980036
July 2025511253317
June 20254758200
May 20253458500
April 202535107110
March 20253350710
February 20252545200
January 2025471483015
December 202445691023
November 20243578219
October 2024721044134
September 20244671401
August 202449716015
July 20243249100

Month-by-month recap

Expand any month for a plain-English summary of that Patch Tuesday.

August 2026358 CVEs fixed1 exploited

The August 2026 Microsoft Patch Tuesday shipped 67 updates (KB articles) fixing 751 CVEs, 108 of them rated Critical severity. Those are Microsoft's own counts; Senserva tracks 358 of them against update articles we hold pages for. 1 was already being exploited in the wild (on the CISA KEV list) and needed patching first.

July 2026540 CVEs fixed5 exploited

The July 2026 Microsoft Patch Tuesday shipped 69 updates (KB articles) fixing 540 CVEs, 34 of them rated Critical severity. 5 were already being exploited in the wild (on the CISA KEV list) and needed patching first.

June 2026162 CVEs fixed

The June 2026 Microsoft Patch Tuesday shipped 33 updates (KB articles) fixing 162 CVEs, 22 of them rated Critical severity. None from this release were on the CISA KEV exploited list at the time.

May 202696 CVEs fixed2 exploited

The May 2026 Microsoft Patch Tuesday shipped 69 updates (KB articles) fixing 96 CVEs, 19 of them rated Critical severity. 2 were already being exploited in the wild (on the CISA KEV list) and needed patching first. 1 was linked to ransomware activity.

April 2026152 CVEs fixed3 exploited

The April 2026 Microsoft Patch Tuesday shipped 64 updates (KB articles) fixing 152 CVEs, 21 of them rated Critical severity. 3 were already being exploited in the wild (on the CISA KEV list) and needed patching first.

March 202661 CVEs fixed

The March 2026 Microsoft Patch Tuesday shipped 39 updates (KB articles) fixing 61 CVEs, 0 of them rated Critical severity. None from this release were on the CISA KEV exploited list at the time.

February 202639 CVEs fixed5 exploited

The February 2026 Microsoft Patch Tuesday shipped 29 updates (KB articles) fixing 39 CVEs, 0 of them rated Critical severity. 5 were already being exploited in the wild (on the CISA KEV list) and needed patching first.

January 2026108 CVEs fixed3 exploited

The January 2026 Microsoft Patch Tuesday shipped 27 updates (KB articles) fixing 108 CVEs, 11 of them rated Critical severity. 3 were already being exploited in the wild (on the CISA KEV list) and needed patching first.

December 202563 CVEs fixed1 exploited

The December 2025 Microsoft Patch Tuesday shipped 55 updates (KB articles) fixing 63 CVEs, 21 of them rated Critical severity. 1 was already being exploited in the wild (on the CISA KEV list) and needed patching first.

November 202551 CVEs fixed2 exploited

The November 2025 Microsoft Patch Tuesday shipped 52 updates (KB articles) fixing 51 CVEs, 30 of them rated Critical severity. 2 were already being exploited in the wild (on the CISA KEV list) and needed patching first. 1 was linked to ransomware activity.

October 2025153 CVEs fixed4 exploited

The October 2025 Microsoft Patch Tuesday shipped 65 updates (KB articles) fixing 153 CVEs, 17 of them rated Critical severity. 4 were already being exploited in the wild (on the CISA KEV list) and needed patching first.

September 202577 CVEs fixed

The September 2025 Microsoft Patch Tuesday shipped 38 updates (KB articles) fixing 77 CVEs, 0 of them rated Critical severity. None from this release were on the CISA KEV exploited list at the time.

August 202598 CVEs fixed

The August 2025 Microsoft Patch Tuesday shipped 84 updates (KB articles) fixing 98 CVEs, 36 of them rated Critical severity. None from this release were on the CISA KEV exploited list at the time.

July 2025125 CVEs fixed3 exploited

The July 2025 Microsoft Patch Tuesday shipped 51 updates (KB articles) fixing 125 CVEs, 17 of them rated Critical severity. 3 were already being exploited in the wild (on the CISA KEV list) and needed patching first. 3 were linked to ransomware activity.

June 202558 CVEs fixed2 exploited

The June 2025 Microsoft Patch Tuesday shipped 47 updates (KB articles) fixing 58 CVEs, 0 of them rated Critical severity. 2 were already being exploited in the wild (on the CISA KEV list) and needed patching first.

May 202558 CVEs fixed5 exploited

The May 2025 Microsoft Patch Tuesday shipped 34 updates (KB articles) fixing 58 CVEs, 0 of them rated Critical severity. 5 were already being exploited in the wild (on the CISA KEV list) and needed patching first.

April 2025107 CVEs fixed1 exploited

The April 2025 Microsoft Patch Tuesday shipped 35 updates (KB articles) fixing 107 CVEs, 0 of them rated Critical severity. 1 was already being exploited in the wild (on the CISA KEV list) and needed patching first. 1 was linked to ransomware activity.

March 202550 CVEs fixed7 exploited

The March 2025 Microsoft Patch Tuesday shipped 33 updates (KB articles) fixing 50 CVEs, 0 of them rated Critical severity. 7 were already being exploited in the wild (on the CISA KEV list) and needed patching first. 1 was linked to ransomware activity.

February 202545 CVEs fixed2 exploited

The February 2025 Microsoft Patch Tuesday shipped 25 updates (KB articles) fixing 45 CVEs, 0 of them rated Critical severity. 2 were already being exploited in the wild (on the CISA KEV list) and needed patching first.

January 2025148 CVEs fixed3 exploited

The January 2025 Microsoft Patch Tuesday shipped 47 updates (KB articles) fixing 148 CVEs, 15 of them rated Critical severity. 3 were already being exploited in the wild (on the CISA KEV list) and needed patching first.

December 202469 CVEs fixed1 exploited

The December 2024 Microsoft Patch Tuesday shipped 45 updates (KB articles) fixing 69 CVEs, 23 of them rated Critical severity. 1 was already being exploited in the wild (on the CISA KEV list) and needed patching first.

November 202478 CVEs fixed2 exploited

The November 2024 Microsoft Patch Tuesday shipped 35 updates (KB articles) fixing 78 CVEs, 9 of them rated Critical severity. 2 were already being exploited in the wild (on the CISA KEV list) and needed patching first. 1 was linked to ransomware activity.

October 2024104 CVEs fixed4 exploited

The October 2024 Microsoft Patch Tuesday shipped 72 updates (KB articles) fixing 104 CVEs, 34 of them rated Critical severity. 4 were already being exploited in the wild (on the CISA KEV list) and needed patching first. 1 was linked to ransomware activity.

September 202471 CVEs fixed4 exploited

The September 2024 Microsoft Patch Tuesday shipped 46 updates (KB articles) fixing 71 CVEs, 1 of them rated Critical severity. 4 were already being exploited in the wild (on the CISA KEV list) and needed patching first.

August 202471 CVEs fixed6 exploited

The August 2024 Microsoft Patch Tuesday shipped 49 updates (KB articles) fixing 71 CVEs, 15 of them rated Critical severity. 6 were already being exploited in the wild (on the CISA KEV list) and needed patching first.

July 202449 CVEs fixed1 exploited

The July 2024 Microsoft Patch Tuesday shipped 32 updates (KB articles) fixing 49 CVEs, 0 of them rated Critical severity. 1 was already being exploited in the wild (on the CISA KEV list) and needed patching first.

Trusted Patch Tuesday resources

The analyses the security community reads each month. Cross-reference these with the ranked view above.

Microsoft Security Update GuideThe authoritative source: every CVE Microsoft fixed this month, affected products, and KBs.
CISA Known Exploited VulnerabilitiesThe U.S. catalog of CVEs confirmed exploited in the wild. Patch these first.
Zero Day Initiative: Security Update ReviewIn-depth monthly analysis from the researchers behind Pwn2Own.
Tenable Patch Tuesday analysisMonthly breakdowns of the CVEs that matter and why.
Rapid7 Patch TuesdayPatch Tuesday roundups with exploitation and attacker context.
Qualys Threat ResearchPatch Tuesday roundups and prioritization guidance.
SANS Internet Storm CenterCommunity Patch Tuesday dashboard and per-CVE detail.
CrowdStrike Patch Tuesday analysisMonthly Patch Tuesday breakdowns with adversary and exploitation context.
Krebs on SecurityPlain-English monthly Patch Tuesday coverage.
BleepingComputerNews coverage of each Patch Tuesday and emerging exploits.

Frequently asked questions

What is Patch Tuesday?

Patch Tuesday is the second Tuesday of each month, when Microsoft releases its scheduled security updates across Windows, Office, Exchange, SharePoint, and the rest of the Microsoft 365, Intune, Defender, and Entra ID stack. Out-of-band updates ship between Patch Tuesdays when a fix cannot wait, and this page covers both. Senserva ranks each release by what attackers are actually exploiting, ties every CVE to the KB that fixes it, and, in your own tenant, tells you which of these updates are actually missing on your devices.

When is the next Patch Tuesday?

The next Microsoft Patch Tuesday is September 8, 2026. It falls on the second Tuesday of every month; upcoming dates are listed on this page.

What was in the latest Patch Tuesday?

The August 2026 release included 67 updates (KBs) fixing 751 CVEs, of which 4 are actively exploited (CISA KEV). The exploited CVEs, the highest-risk CVEs, and the full history are on this page.

Which Patch Tuesday updates should I install first?

Install the actively-exploited (CISA KEV) fixes first, then the highest EPSS and CVSS ones, then the rest. This page ranks every release that way, and Senserva applies the same order to the updates actually missing on your own devices.

What is a zero-day on Patch Tuesday?

A zero-day is a vulnerability already being exploited (or publicly disclosed) before a patch was available. Those are the CVEs to patch immediately; this page calls out the actively-exploited ones each month.

How often is this page updated?

Automatically, every day. The data refreshes from Microsoft MSRC, CISA KEV, and FIRST.org EPSS, and the month-by-month history is preserved so the archive only grows.

Is this Patch Tuesday tracker free?

Yes, free with no sign-in. Running Senserva adds the part a public page cannot: which of these updates are actually missing on your devices, ranked, so you fix the right things first.

Can I use this Patch Tuesday data with my own AI?

Yes. A free copy-paste AI prompt just under the exploited-CVE list is composed from this release: the update and CVE counts, and the actively-exploited CVE names with their CVSS scores. Paste it into Claude, ChatGPT, or Copilot to get a first-24-hours plan and a team briefing in your own words.

The Microsoft CVE and patch resource center

Everything here is free, refreshed once a day (5 AM US Central), and cross-linked. Start with this month, then drill into any CVE, KB, product, or month since tracking began.

Data access: Patch Tuesday RSS · JSON patch API · calendar (.ics). Plus a page for every CVE and KB, linked throughout. JSON and RSS feeds included, no login required: all feeds and the API.

AI patch management: put your own AI on this data

Scan your own tenant free

Now see the same thing in your own tenant.

Siemserva by Senserva reads your Microsoft 365, Intune, Defender, and Entra ID environment and returns every missing update ranked by what is actually being exploited, alongside all 650+ configuration checks.

1Find it2Fix it3Prove it
Start my free auditAll you do is register.

Reference: the Microsoft patching guide, how Intune, Windows Autopatch, Defender, and Azure Update Manager fit together, and where third-party patch vendors fit in.

Data notice: this page, the feeds, and the API are provided as is, for informational purposes only, without warranty of any kind. Senserva, LLC does not guarantee the accuracy, completeness, or timeliness of third-party data and accepts no liability for actions taken based on it; verify against the primary source before acting. All use of this data is subject to the Senserva EULA.

Patching across Intune, Windows Autopatch, Defender, Azure, and your endpoint managers: see Senserva patching in action.