Combined view

All three datasets on one timeline

The global CVE firehose, Microsoft's Patch Tuesday, and US breach counts, together. They measure different things at different scales — all published CVEs (tens of thousands a year), one vendor's monthly releases (hundreds), and reported US data compromises (thousands) — so this uses two axes: CVEs on the left, the two smaller series sharing the right. All three are climbing; all three broke pattern between 2023 and 2026.

Global CVEs vs Patch Tuesday vs US breaches, per year

Left axis (amber): all CVEs published worldwide. Right axis: Microsoft Patch Tuesday CVEs per calendar year (teal, dashed) and ITRC US data compromises (red, solid) on a shared scale. 2026 is partial for CVE/Patch Tuesday and omitted for breaches (Q1 only published).

0 0 12.5k 1.25k 25k 2.5k 37.5k 3.75k 50k 5kAll CVEs (per yr) MS Patch Tuesday (per yr)US breaches (ITRC)20162017201820192020202120222023202420252026
The red line is the newest addition: US data compromises stepped up 78% in 2023 — a year before the CVE surge — and held at record levels through 2025. Microsoft's annual Patch Tuesday volume drifted up modestly (≈700 in 2018 to ≈1,150 in 2025) while the global count multiplied several times over. The teal line's 2026 jump is July's 569-CVE record landing in a partial year. CVE.org / NVD + Zero Day Initiative + ITRC

How the three relate

2.4%

Microsoft's slice of the whole

Microsoft's 1,146 Patch Tuesday CVEs in 2025 were about 2.4% of the 48,185 published worldwide. One major vendor is a small fraction of the global firehose — most CVE volume comes from the sprawling third-party ecosystem (WordPress plugins, the Linux kernel, thousands of smaller projects).

All 3

rose, then broke pattern

Global CVEs jumped 38% in 2024 and 21% in 2025. Microsoft's monthly range held flat for eighteen months, then spiked in 2026 (April 163, June 200, July 569). And US breach counts moved first — the 78% step-up landed in 2023 and held. Three different measures, all off their baselines within the same three-year window.

but they aren't the same signal

The global rise is dominated by more issuers (CNAs) and disclosure completeness. Microsoft's rise is a single vendor's own release cadence. Reading them as one "AI is causing more bugs" trend conflates two very different mechanisms — which is exactly the mistake this site exists to avoid.

The honest combined read

Put together, the three datasets say the same careful thing: disclosure volume, Microsoft's own releases, and reported US breaches all broke their baselines in the 2023–2026 window. That correlation is real and worth watching — and the breach data adds the one consequence-side signal: vuln exploitation became the #1 breach entry vector in 2026. What none of these show — separately or combined — is that AI is the cause. The confounders (CNA expansion, the NVD enrichment collapse, breach-notification law growth, Microsoft's internal tooling) are large, documented, and unquantified. The combined view sharpens the question; it doesn't answer it. The full reasoning is on the AI Question page →