Patch and vulnerability tracker / Microsoft Patch Tuesday

Microsoft Patch Tuesday, ranked by what is actually exploited

Every Microsoft Patch Tuesday and out-of-band update, with the CVEs each one fixes ranked by real-world risk: actively exploited (CISA KEV) first, then EPSS exploit probability and CVSS severity. The latest release is below, followed by a month-by-month history. Next Patch Tuesday: July 14, 2026.

Latest: June 2026

Microsoft shipped 33 updates fixing 244 CVEs this release.
33
Updates (KBs)
244
CVEs fixed
1
Actively exploited
0
Ransomware-linked
15
Critical updates
Actively exploited this release:

Open the full patch tracker

Tracking 24 Patch Tuesdays, 905 updates and 79 actively-exploited CVEs in total.

Patch Tuesday history

Every month since we started tracking, newest first. Counts are unique per month; the exploited and ransomware columns come from CISA KEV.

MonthUpdatesCVEsExploitedRansomwareCritical
June 2026332441015
May 202655127009
April 2026531532010
March 20263861000
February 20262939500
January 2026271093011
December 2025552246021
November 20251611000
October 2025571394011
September 20253061000
August 2025672435028
July 20253764535
June 20253199700
May 20251840400
April 202535110110
March 20253386910
February 20251745200
January 2025441493014
December 202427701016
November 20243482219
October 2024431053011
September 202445165605
August 2024491578024
July 20243250210

What is Patch Tuesday?

Patch Tuesday is the second Tuesday of each month, when Microsoft releases its scheduled security updates across Windows, Office, Exchange, and the rest of the Microsoft 365, Intune, Defender, and Entra ID stack. Out-of-band updates ship between Patch Tuesdays when a fix cannot wait. Senserva ranks each release by what attackers are actually exploiting, ties every CVE to the KB that fixes it, and, in your own tenant, tells you which of these updates are actually missing on your devices.

Frequently asked questions

What is Patch Tuesday?

Patch Tuesday is the second Tuesday of each month, when Microsoft releases its scheduled security updates for Windows, Office, Exchange, and the rest of the Microsoft stack. Critical fixes can also ship out-of-band between Patch Tuesdays. This page covers both.

When is the next Patch Tuesday?

The next Microsoft Patch Tuesday is July 14, 2026. It falls on the second Tuesday of every month.

What was in the latest Patch Tuesday?

The June 2026 release included 33 updates (KBs) fixing 244 CVEs, of which 1 are actively exploited (CISA KEV). The full ranked breakdown and every prior month are on this page.

How are the patches ranked?

By what is actually exploited, not just severity. Actively-exploited CVEs (CISA KEV) come first, then FIRST.org EPSS exploit probability, then CVSS severity. This surfaces the handful attackers are really using.

How often is this updated?

Automatically. The data refreshes daily from Microsoft MSRC, CISA KEV, and FIRST.org EPSS, and the history is preserved month by month so the archive only grows.