All three datasets on one timeline
The global CVE firehose, Microsoft's Patch Tuesday, and US breach counts, together. They measure different things at different scales — all published CVEs (tens of thousands a year), one vendor's monthly releases (hundreds), and reported US data compromises (thousands) — so this uses two axes: CVEs on the left, the two smaller series sharing the right. All three are climbing; all three broke pattern between 2023 and 2026.
Global CVEs vs Patch Tuesday vs US breaches, per year
Left axis (amber): all CVEs published worldwide. Right axis: Microsoft Patch Tuesday CVEs per calendar year (teal, dashed) and ITRC US data compromises (red, solid) on a shared scale. 2026 is partial for CVE/Patch Tuesday and omitted for breaches (Q1 only published).
How the three relate
Microsoft's slice of the whole
Microsoft's 1,146 Patch Tuesday CVEs in 2025 were about 2.4% of the 48,185 published worldwide. One major vendor is a small fraction of the global firehose — most CVE volume comes from the sprawling third-party ecosystem (WordPress plugins, the Linux kernel, thousands of smaller projects).
rose, then broke pattern
Global CVEs jumped 38% in 2024 and 21% in 2025. Microsoft's monthly range held flat for eighteen months, then spiked in 2026 (April 163, June 200, July 569). And US breach counts moved first — the 78% step-up landed in 2023 and held. Three different measures, all off their baselines within the same three-year window.
but they aren't the same signal
The global rise is dominated by more issuers (CNAs) and disclosure completeness. Microsoft's rise is a single vendor's own release cadence. Reading them as one "AI is causing more bugs" trend conflates two very different mechanisms — which is exactly the mistake this site exists to avoid.
The honest combined read
Put together, the three datasets say the same careful thing: disclosure volume, Microsoft's own releases, and reported US breaches all broke their baselines in the 2023–2026 window. That correlation is real and worth watching — and the breach data adds the one consequence-side signal: vuln exploitation became the #1 breach entry vector in 2026. What none of these show — separately or combined — is that AI is the cause. The confounders (CNA expansion, the NVD enrichment collapse, breach-notification law growth, Microsoft's internal tooling) are large, documented, and unquantified. The combined view sharpens the question; it doesn't answer it. The full reasoning is on the AI Question page →