SQ Magazine The Threat Index Dashboard

Patch Tuesday Dashboard

This dashboard records Microsoft's security-update cycles since January 2025. Each row gives the cycle month, how many vulnerabilities shipped an installable update, how many were rated critical, and how many were reported as exploited at release.

19 records next Patch Tuesday 11 Aug 2026 updated through 1 Jul 2026

Latest change Methodology, per-cycle anchors, and record callouts added; the intro now states the tracker covers Microsoft cycles since January 2025. (24 Jul 2026) All changes

Cycles tracked
19
Latest cycle CVEs
530
Zero-days in 2026
13
Tracking since
Jan 2025

CVEs per cycle, Jan 2025 to Jul 2026

Monthly vendor patch cycles. Counts are taken from each vendor's own security bulletin, linked per row.
Cycle Vendor CVEs Critical Zero-days (exploited at release) Bulletin
Jul 2026 Microsoft 530 52 3 Exploited Advisory ↗
Jun 2026 Microsoft 171 28 0 Advisory ↗
May 2026 Microsoft 95 15 1 Exploited Advisory ↗
Apr 2026 Microsoft 152 6 2 Exploited Advisory ↗
Mar 2026 Microsoft 61 2 0 Advisory ↗
Feb 2026 Microsoft 38 0 5 Exploited Advisory ↗
Jan 2026 Microsoft 108 7 2 Exploited Advisory ↗
Dec 2025 Microsoft 54 2 1 Exploited Advisory ↗
Nov 2025 Microsoft 51 3 1 Exploited Advisory ↗
Oct 2025 Microsoft 155 7 3 Exploited Advisory ↗
Sep 2025 Microsoft 77 8 0 Advisory ↗
Aug 2025 Microsoft 94 9 0 Advisory ↗
Jul 2025 Microsoft 125 14 1 Exploited Advisory ↗
Jun 2025 Microsoft 57 9 1 Exploited Advisory ↗
May 2025 Microsoft 58 5 5 Exploited Advisory ↗
Apr 2025 Microsoft 107 11 1 Exploited Advisory ↗
Mar 2025 Microsoft 48 5 6 Exploited Advisory ↗
Feb 2025 Microsoft 45 3 2 Exploited Advisory ↗
Jan 2025 Microsoft 148 10 3 Exploited Advisory ↗

Verification ledger

2 most recent of 2 logged updates
  • Methodology, per-cycle anchors, and record callouts added; the intro now states the tracker covers Microsoft cycles since January 2025. 24 Jul 2026
  • Tracker launched with 19 Microsoft cycles covering January 2025 through July 2026. 22 Jul 2026

How this tracker is maintained

Every cycle passes the same checks before it appears, on the vendor’s own schedule.

  1. Sourced

    Counts come from Microsoft’s own MSRC security-update guide, parsed per cycle and linked on every row. Chromium CVEs mirrored into Edge and server-side cloud fixes are excluded, because an administrator never installs them.

  2. Dated

    Each row is one vendor cycle, dated by its Patch Tuesday. The header names the next one.

  3. Re-checked

    Each cycle is re-checked after release; exploited-at-release flags and revised counts follow the vendor’s bulletin updates.

Why do these counts differ from news reports?
Most outlets count every CVE identifier in the bulletin. This tracker counts vulnerabilities that ship an installable update, which is the number an administrator actually patches.
Which vendors are covered?
Microsoft today. Other vendors publish on the same Tuesday and may join later; every row states its vendor either way.
Can I cite this?
Yes. Use “Cite this tracker” and cite the cycle month alongside any count.

This is informational content, not patching guidance for your environment. Counts reflect the vendor’s bulletin at release and can be revised. Prioritize using the linked advisory and your own asset inventory.