HomePatch and vulnerability tracker › What's hot

The hottest Microsoft patches and CVEs right now, and what changed today

Hot Patches is Senserva's live shortlist of the Microsoft patches (KBs) and CVEs that matter most right now, ranked by the Senserva CVE Ranking, not a raw dump. Free, refreshed three times a day: 5 AM, 12:30 PM, and 7 PM US Central, and available as a Hot Patches JSON feed to build on.

Just this week's new exploitation is Exploited this week; the full references are the Microsoft patch tracker and the Microsoft CVE tracker.

See what just changed, and why it matters

CVEs and patches do not stand still: Severity gets rescored, CISA confirms exploitation, fixes get revised. These are the CVEs and Microsoft patches whose Senserva-tracked facts changed most recently. Click any row to see its dated change history.

Building a tool? The same ranking is a free JSON API: https://senserva.com/api/hot.json, with four ranked lists (all CVEs, Microsoft CVEs, non-Microsoft CVEs, and patches/KBs). No login or key. See the feeds and API page for the schema and rules. Free to use with attribution: "Patch Data Provided by Senserva".

This page updates three times a day, please link to it so others benefit from it and to keep current with its changes.

How to read it: higher on the list means hotter. In Motion means it is moving right now: newly confirmed exploited, tied to active ransomware, or climbing in search.

Hottest CVEs right now

The fifteen CVEs at the top of the Senserva CVE Ranking. Click any card for the full write-up and the fix.

Loading the hottest CVEs...
See the full top 100 CVEs

Hottest Microsoft patches (KBs) right now

The fifteen Microsoft updates at the top of the Senserva CVE Ranking, the ones to deploy first.

Loading the hottest KBs...
See the full top 100 KBs

Top 100 hottest CVEs

Sortable and filterable. Every row links to that CVE's page: what it is, who is exposed, and the update that fixes it.

Loading the hot CVE list...

Top 100 Hot Patches (Microsoft KBs)

The Microsoft updates behind the hottest CVEs, ranked to deploy in order.

Loading the hot KB list...

From "what's hot" to "what's missing on my devices"

This page shows what the whole world is dealing with. Senserva shows which of these hot CVEs and KBs are actually missing on your Microsoft 365, Intune, Defender, and Entra ID estate, then ranks your gaps the same way: actively exploited first. It reads every layer read-only and names the exact KB to deploy.

See your security gaps, free

Common questions

How is "hot" decided?

Each CVE and KB gets a score that blends real-world threat signal and search demand. Threat signal is CISA KEV (confirmed exploited in the wild) first, then known ransomware use, then FIRST.org EPSS exploit probability, then CVSS severity, with a recency boost so newly confirmed exploitation rises. When a credentialed Search Console pull is present, live search demand (how many people are looking the item up) is blended in too.

What does "In Motion" mean?

In Motion flags an item that is actively moving right now: either it was newly added to the CISA Known Exploited Vulnerabilities catalog in the last two to three weeks, it is tied to active ransomware campaigns, or it is climbing in live search demand. It is the short list to look at first.

How often does this update?

The underlying feeds (Microsoft MSRC, CISA KEV, FIRST.org EPSS) refresh three times a day: 5 AM, 12:30 PM, and 7 PM US Central, and this ranking is rebuilt with them, so a newly exploited CVE or a fresh out-of-band KB shows up here within hours.

Is there an API or feed for the hottest patches?

Yes. The same ranking is a free JSON API at https://senserva.com/api/hot.json: four ranked lists (all CVEs, Microsoft CVEs, non-Microsoft CVEs, and patches/KBs), each item with its rank, score, dates, and a link to the detail page. No login or key. RSS feeds and a Patch Tuesday calendar are on the feeds and API page. Free to use with attribution: "Patch Data Provided by Senserva".

Is it free?

Yes, free with no sign-in. Running Senserva adds the part a public ranking cannot: which of these hot CVEs and KBs are actually missing on your own devices, ranked so you fix the right things first.

Patch tracker questions, answered

How is the Microsoft Patch Tracker different from the MSRC Update Guide?

Microsoft's MSRC Update Guide is the authoritative list of what shipped. This tracker adds the prioritization it does not: every KB is ranked by CISA KEV (actively exploited) first, then FIRST.org EPSS exploit probability, then CVSS severity, with each KB tied to the CVEs it fixes and shown in live charts and a product-family risk heatmap. It is free, with no sign-in.

How often is the patch data updated?

Daily. The tracker auto-refreshes from Microsoft MSRC, CISA KEV, and FIRST.org EPSS, so the charts, heatmap, and table reflect the latest Patch Tuesday and out-of-band updates and the current exploitation signals.

What is Patch Tuesday?

Patch Tuesday is the second Tuesday of each month, when Microsoft releases its scheduled security updates. Critical fixes can also ship out-of-band between Patch Tuesdays. This tracker covers both.

What do CISA KEV and EPSS mean for patch prioritization?

CISA KEV is the catalog of CVEs confirmed to be actively exploited in the wild. EPSS is a daily probability that a CVE will be exploited soon. Ranking patches by KEV then EPSS, on top of CVSS severity, surfaces what attackers are actually using, a better fix-first order than CVSS alone.

What is a KB, and how does it relate to a CVE?

A KB (Knowledge Base) number identifies a Microsoft update package. Each KB fixes one or more CVEs. The tracker cross-references every KB to the CVEs it resolves, and every CVE to the KB that fixes it.

Is the patch tracker free?

Yes, it is free to use with no sign-in. Running Senserva adds the part a public tracker cannot: which of these patches and CVEs are actually missing on your own devices, ranked so you fix the right things first.

Can I use this patch data with my own AI?

Yes. The page includes a free copy-paste AI prompt, generated from the live table each day, that carries the riskiest KBs with their severity, EPSS scores, and CISA KEV status into Claude, ChatGPT, or Copilot, so you can build a deployment plan in your own words.

From Mark Shavlik, the original creator of Shavlik patch management (HfNetChk, NetChk Protect), and his team. Senserva is a Microsoft Intelligent Security Association (MISA) member.

Fixing what this tracker finds

This page is the public picture. The short walkthrough below shows the same ranking applied to your own tenant: which of these updates are actually missing on your devices, fixed with approval.

Senserva patching for Microsoft 365

Open the watch page for this video, or read about Senserva patching.

Sponsored by Senserva

Siemserva by Senserva reports patch status for your own devices: which ones are missing the updates on this page, ranked by what attackers actually exploit.

  • Patch status in one scan: which devices are affected, which are not
  • Missing updates ranked by CISA KEV and EPSS, so you fix the right things first
  • Data from Intune, Microsoft Defender, Windows Autopatch, and Azure Update Manager, with more sources on the way
  • Third-party app patching too: updates published to Intune by PatchMyPC, Scappman, Robopack, or any vendor, read vendor-neutrally
  • Optional AI Enhanced Reporting: plain-language summaries and recommended next steps written into your reports
  • Then go further: 650+ security checks find the drift management gaps across Microsoft 365, Intune, Defender, and Entra ID, with compliance evidence and Senserva Trustworthy AI remediation
Senserva patching for Microsoft 365
Two minutes, click to play

Patching in action in two minutes. Watch page · All videos.

3 actively exploited CVEs are unmitigated on devices in this tenant, per CISA KEV.View fix-first list ↓
312
Devices scanned
Intune + Autopatch + Defender
3
Exploited updates missing
CISA KEV, unmitigated
905
Microsoft updates tracked
Refreshed daily, MSRC + NVD
650+
Security checks in scan
Patch, config, identity, logs

Triage order for this list

Same order in the dashboard, the report, and every AI answer
1st · overrides everything
Actively exploited (KEV)
e.g. KB5040219, CVE-2026-31210
2nd · tiebreaker
Severity (Critical → Low)
MSRC + EPSS probability
3rd · tiebreaker
Days waiting
Oldest unresolved first

Ranked missing updates, fix-first order

27 findings · showing top 2
#UpdateCVESeveritySourceDevicesWaiting
1KB5040219
Windows 11 23H2 cumulative
CVE-2026-31210
KEV EPSS 0.94
CriticalDefender4119 daysAdd to fix-first
2KB5040088
.NET Framework security update
CVE-2026-29981
KEV
CriticalIntune1712 daysAdd to fix-first
Estimated dashboard, sample data for illustration

Ask Senserva

via Claude + MCP
Which devices are still missing the fix for CVE-2026-31210?
41 devices are missing KB5040219, which resolves CVE-2026-31210. This CVE is on CISA KEV, so CISA BOD 22-01 calls for remediation within 14 days. You are at 19 days and counting.
source: scan_db · defender_posture · kev_join, not model memory
Get Devices Found Get Devices Missing
Senserva is a Microsoft Intelligent Security Association member. Get Going with Senserva Senserva patching Built for IT admins and security teams, with audit-ready data for compliance.

Reference: the Microsoft patching guide, how Intune, Windows Autopatch, Defender, and Azure Update Manager fit together, and where third-party patch vendors fit in.

Data notice: the trackers, feeds, and API are provided as is, for informational purposes only, without warranty of any kind. Senserva, LLC does not guarantee the accuracy, completeness, or timeliness of third-party data and accepts no liability for actions taken based on it; verify against the primary source before acting. All use of this data is subject to the Senserva EULA.