SQ Magazine The Threat Index Dashboard
This dashboard records Microsoft's security-update cycles since January 2025. Each row gives the cycle month, how many vulnerabilities shipped an installable update, how many were rated critical, and how many were reported as exploited at release.
19 records next Patch Tuesday 11 Aug 2026 updated through 1 Jul 2026
Latest change Methodology, per-cycle anchors, and record callouts added; the intro now states the tracker covers Microsoft cycles since January 2025. (24 Jul 2026) All changes
CVEs per cycle, Jan 2025 to Jul 2026
| Cycle | Vendor | CVEs | Critical | Zero-days (exploited at release) | Bulletin |
|---|---|---|---|---|---|
| Jul 2026 | Microsoft | 530 | 52 | 3 Exploited | Advisory ↗ |
| Jun 2026 | Microsoft | 171 | 28 | 0 | Advisory ↗ |
| May 2026 | Microsoft | 95 | 15 | 1 Exploited | Advisory ↗ |
| Apr 2026 | Microsoft | 152 | 6 | 2 Exploited | Advisory ↗ |
| Mar 2026 | Microsoft | 61 | 2 | 0 | Advisory ↗ |
| Feb 2026 | Microsoft | 38 | 0 | 5 Exploited | Advisory ↗ |
| Jan 2026 | Microsoft | 108 | 7 | 2 Exploited | Advisory ↗ |
| Dec 2025 | Microsoft | 54 | 2 | 1 Exploited | Advisory ↗ |
| Nov 2025 | Microsoft | 51 | 3 | 1 Exploited | Advisory ↗ |
| Oct 2025 | Microsoft | 155 | 7 | 3 Exploited | Advisory ↗ |
| Sep 2025 | Microsoft | 77 | 8 | 0 | Advisory ↗ |
| Aug 2025 | Microsoft | 94 | 9 | 0 | Advisory ↗ |
| Jul 2025 | Microsoft | 125 | 14 | 1 Exploited | Advisory ↗ |
| Jun 2025 | Microsoft | 57 | 9 | 1 Exploited | Advisory ↗ |
| May 2025 | Microsoft | 58 | 5 | 5 Exploited | Advisory ↗ |
| Apr 2025 | Microsoft | 107 | 11 | 1 Exploited | Advisory ↗ |
| Mar 2025 | Microsoft | 48 | 5 | 6 Exploited | Advisory ↗ |
| Feb 2025 | Microsoft | 45 | 3 | 2 Exploited | Advisory ↗ |
| Jan 2025 | Microsoft | 148 | 10 | 3 Exploited | Advisory ↗ |
No records match the current filters.
Every cycle passes the same checks before it appears, on the vendor’s own schedule.
Counts come from Microsoft’s own MSRC security-update guide, parsed per cycle and linked on every row. Chromium CVEs mirrored into Edge and server-side cloud fixes are excluded, because an administrator never installs them.
Each row is one vendor cycle, dated by its Patch Tuesday. The header names the next one.
Each cycle is re-checked after release; exploited-at-release flags and revised counts follow the vendor’s bulletin updates.
This is informational content, not patching guidance for your environment. Counts reflect the vendor’s bulletin at release and can be revised. Prioritize using the linked advisory and your own asset inventory.