Microsoft Patch Tuesday, month by month — Jan 2018 to Jul 2026
The complete dataset — every second-Tuesday release across 103 months. New Microsoft CVEs only (third-party and Chromium republished advisories excluded). Sourced to the Zero Day Initiative's monthly reviews (Dustin Childs), cross-checked against Krebs, Tenable, and BleepingComputer. The long view shows what two years alone can't: a typical month ran 50–70 CVEs in 2018, crossed 100 regularly by 2020, settled near 90–100 through 2025, then broke every record in 2026.
CVEs per month, 2018–2026, with exploited zero-days
Total new Microsoft CVEs (bars), one per Patch Tuesday. Red overlay = the actively-exploited zero-days that month. Labels mark January of each year.
What kind of bug — category mix over time
Each bar is one month's CVEs, split by vulnerability class. The mix is strikingly stable across eight years.
The full dataset
All 24 months. Zero-days column shows total publicly-known-or-exploited at release, with the actively-exploited subset called out. The last six months (from Feb 2026) are marked with dimmed rows — verified live but with the source discrepancies noted in the methodology.
| Month | CVEs | Critical | Zero-days | Top category | Most notable CVE |
|---|---|---|---|---|---|
| 2018-01 | 56 | 16 | 2 (1 exploited) | RCE (16) | CVE-2018-0802 Office Equation Editor RCE, actively exploited; plus Meltdown/Spectre (ADV180002) |
| 2018-02 | 50 | 14 | 1 | RCE (14) | CVE-2018-0852 Outlook memory-corruption RCE, Critical, code exec via Preview Pane |
| 2018-03 | 75 | 14 | 2 | Elevation of Privilege (23) | CVE-2018-0886 CredSSP RCE — MITM on RDP sessions |
| 2018-04 | 67 | 24 | 1 | Info Disclosure (18) | CVE-2018-1004 / Office & scripting-engine RCEs; 24 Critical |
| 2018-05 | 68 | 21 | 4 (2 exploited) | Elevation of Privilege (19) | CVE-2018-8174 'Double Kill' VBScript RCE, actively exploited |
| 2018-06 | 50 | 11 | 1 | RCE (16) | CVE-2018-8225 Windows DNSAPI RCE, wormable, SYSTEM-level |
| 2018-07 | 53 | 18 | 0 | RCE (14) | CVE-2018-8327 PowerShell Editor Services RCE, Critical (no in-the-wild zero-days) |
| 2018-08 | 60 | 20 | 2 (2 exploited) | RCE (26) | CVE-2018-8373 IE VBScript RCE, actively exploited (+ CVE-2018-8414 Shell RCE) |
| 2018-09 | 61 | 17 | 4 (1 exploited) | RCE (16) | CVE-2018-8440 ALPC Task Scheduler EoP, publicly disclosed & exploited (PowerPool) |
| 2018-10 | 49 | 12 | 4 (1 exploited) | RCE (18) | CVE-2018-8453 Win32k EoP, actively exploited (Kaspersky) |
| 2018-11 | 63 | 12 | 3 (1 exploited) | RCE (24) | CVE-2018-8589 Win32k EoP, actively exploited |
| 2018-12 | 39 | 9 | 2 (1 exploited) | RCE (10) | CVE-2018-8611 Windows Kernel EoP, actively exploited (third straight month) |
| 2019-01 | 49 | 7 | 1 | RCE (16) | CVE-2019-0547 DHCP Client RCE, wormable, CVSS 9.8 |
| 2019-02 | 77 | 20 | 5 (1 exploited) | RCE (29) | CVE-2019-0676 IE information disclosure, actively exploited |
| 2019-03 | 64 | 17 | 6 (2 exploited) | RCE (28) | CVE-2019-0808 Win32k EoP, exploited (chained with Chrome CVE-2019-5786) |
| 2019-04 | 74 | 13 | 2 (2 exploited) | RCE (26) | CVE-2019-0859 Win32k use-after-free EoP, actively exploited |
| 2019-05 | 79 | 22 | 2 (1 exploited) | RCE (41) | CVE-2019-0708 'BlueKeep' RDP pre-auth wormable RCE, CVSS 9.8 |
| 2019-06 | 88 | 21 | 4 | RCE (26) | CVE-2019-1069 Task Scheduler EoP, publicly disclosed (SandboxEscaper) |
| 2019-07 | 78 | 15 | 8 (2 exploited) | Elevation of Privilege (18) | CVE-2019-1132 Win32k EoP, exploited by Buhtrap APT |
| 2019-08 | 93 | 29 | 0 | RCE (29) | CVE-2019-1181 'DejaBlue' RDP pre-auth wormable RCE, CVSS 9.8 |
| 2019-09 | 80 | 17 | 4 (2 exploited) | Elevation of Privilege (19) | CVE-2019-1215 ws2ifsl EoP, actively exploited |
| 2019-10 | 59 | 8 | 0 | Elevation of Privilege (20) | CVE-2019-1060 MSXML RCE, Critical |
| 2019-11 | 74 | 13 | 1 (1 exploited) | Elevation of Privilege (23) | CVE-2019-1429 IE scripting-engine RCE, actively exploited |
| 2019-12 | 36 | 7 | 1 (1 exploited) | Info Disclosure (14) | CVE-2019-1458 Win32k EoP, exploited in Operation WizardOpium |
| 2020-01 | 49 | 8 | 0 | Elevation of Privilege (13) | CVE-2020-0601 'CurveBall' CryptoAPI cert-spoofing (NSA-reported), CVSS 8.1 |
| 2020-02 | 99 | 12 | 5 (1 exploited) | Elevation of Privilege (55) | CVE-2020-0674 IE scripting-engine RCE, actively exploited |
| 2020-03 | 115 | 26 | 0 | Elevation of Privilege (60) | CVE-2020-0796 'SMBGhost' wormable SMBv3 RCE (patched out-of-band days later) |
| 2020-04 | 113 | 17 | 4 (3 exploited) | Elevation of Privilege (39) | CVE-2020-1020 Adobe Type Manager RCE, actively exploited |
| 2020-05 | 111 | 16 | 0 | Elevation of Privilege (56) | CVE-2020-1118 Windows TLS DoS (unauth lsass crash) |
| 2020-06 | 129 | 11 | 3 | Elevation of Privilege (70) | CVE-2020-1281 Windows OLE RCE, Critical |
| 2020-07 | 123 | 18 | 1 | Elevation of Privilege (68) | CVE-2020-1350 'SIGRed' wormable DNS Server RCE, CVSS 10.0 |
| 2020-08 | 120 | 17 | 2 (2 exploited) | Elevation of Privilege (61) | CVE-2020-1472 'Zerologon' Netlogon EoP, CVSS 10.0 |
| 2020-09 | 129 | 23 | 0 | RCE (43) | CVE-2020-16875 Exchange memory-corruption RCE (SYSTEM via email) |
| 2020-10 | 87 | 11 | 6 | Elevation of Privilege (36) | CVE-2020-16898 'Bad Neighbor' TCP/IP RCE via ICMPv6, CVSS 9.8 |
| 2020-11 | 112 | 17 | 1 (1 exploited) | Elevation of Privilege (37) | CVE-2020-17087 Kernel EoP, exploited (chained with Chrome by Project Zero) |
| 2020-12 | 58 | 9 | 0 | RCE (16) | CVE-2020-17095 Hyper-V RCE, guest-to-host escape |
| 2021-01 | 83 | 10 | 2 (1 exploited) | Elevation of Privilege (34) | CVE-2021-1647 Microsoft Defender RCE, actively exploited |
| 2021-02 | 56 | 11 | 7 (1 exploited) | RCE (16) | CVE-2021-1732 Win32k EoP exploited; CVE-2021-24078 DNS RCE 9.8 |
| 2021-03 | 89 | 14 | 7 (5 exploited) | RCE (45) | CVE-2021-26855 'ProxyLogon' Exchange SSRF→RCE, exploited by HAFNIUM |
| 2021-04 | 114 | 19 | 5 (1 exploited) | RCE (40) | CVE-2021-28310 Win32k EoP exploited; NSA-reported Exchange RCE CVE-2021-28480 (9.8) |
| 2021-05 | 55 | 4 | 3 | RCE (18) | CVE-2021-31166 HTTP.sys wormable RCE, CVSS 9.8 |
| 2021-06 | 50 | 5 | 9 (6 exploited) | RCE (11) | CVE-2021-33742 MSHTML RCE exploited (PuzzleMaker chain) |
| 2021-07 | 117 | 13 | 9 (4 exploited) | RCE (32) | CVE-2021-34527 'PrintNightmare' Print Spooler RCE, exploited |
| 2021-08 | 44 | 7 | 3 (1 exploited) | Elevation of Privilege (16) | CVE-2021-36948 Update Medic EoP exploited; CVE-2021-26424 TCP/IP RCE 9.9 |
| 2021-09 | 60 | 3 | 2 (1 exploited) | Elevation of Privilege (22) | CVE-2021-40444 MSHTML RCE, exploited via malicious Office docs |
| 2021-10 | 71 | 2 | 4 (1 exploited) | RCE (18) | CVE-2021-40449 Win32k EoP, actively exploited |
| 2021-11 | 55 | 6 | 4 (2 exploited) | Elevation of Privilege (20) | CVE-2021-42321 Exchange RCE, exploited (Tianfu Cup) |
| 2021-12 | 67 | 7 | 6 (1 exploited) | Elevation of Privilege (21) | CVE-2021-43890 AppX Installer spoofing, exploited by Emotet |
| 2022-01 | 96 | 9 | 6 | Elevation of Privilege (41) | CVE-2022-21907 HTTP.sys wormable RCE, CVSS 9.8 |
| 2022-02 | 48 | 0 | 1 | RCE (16) | CVE-2022-21989 Kernel EoP (no Critical-rated CVEs this month) |
| 2022-03 | 71 | 3 | 3 | RCE (28) | CVE-2022-23277 Exchange Server RCE, authenticated |
| 2022-04 | 128 | 10 | 2 (1 exploited) | RCE (47) | CVE-2022-24521 CLFS EoP, exploited (NSA-reported) |
| 2022-05 | 74 | 7 | 3 (1 exploited) | Elevation of Privilege (21) | CVE-2022-26925 LSA spoofing / NTLM relay (PetitPotam), exploited |
| 2022-06 | 55 | 3 | 1 (1 exploited) | RCE (26) | CVE-2022-30190 'Follina' MSDT RCE, exploited |
| 2022-07 | 84 | 4 | 1 (1 exploited) | Elevation of Privilege (52) | CVE-2022-22047 CSRSS EoP, actively exploited |
| 2022-08 | 121 | 17 | 2 (1 exploited) | Elevation of Privilege (64) | CVE-2022-34713 'DogWalk' MSDT RCE, actively exploited |
| 2022-09 | 64 | 5 | 2 (1 exploited) | RCE (23) | CVE-2022-37969 CLFS EoP, actively exploited |
| 2022-10 | 85 | 15 | 2 (1 exploited) | Elevation of Privilege (39) | CVE-2022-41033 COM+ Event System EoP, actively exploited |
| 2022-11 | 64 | 11 | 6 (6 exploited) | Elevation of Privilege (26) | CVE-2022-41082 'ProxyNotShell' Exchange RCE, exploited |
| 2022-12 | 52 | 6 | 2 (1 exploited) | Elevation of Privilege (18) | CVE-2022-44698 SmartScreen SFB (Mark-of-the-Web evasion), exploited |
| 2023-01 | 98 | 11 | 2 (1 exploited) | Elevation of Privilege (38) | CVE-2023-21674 ALPC EoP, exploited (sandbox escape to SYSTEM) |
| 2023-02 | 75 | 9 | 3 (3 exploited) | RCE (24) | CVE-2023-23376 CLFS EoP, exploited (also CVE-2023-21715, CVE-2023-21823) |
| 2023-03 | 74 | 6 | 2 (2 exploited) | RCE (18) | CVE-2023-23397 Outlook EoP + CVE-2023-24880 SmartScreen, both exploited; CVE-2023-23392 HTTP RCE 9.8 |
| 2023-04 | 97 | 7 | 1 (1 exploited) | RCE (48) | CVE-2023-21554 'QueueJumper' MSMQ RCE 9.8; CVE-2023-28252 CLFS EoP exploited |
| 2023-05 | 38 | 6 | 3 (2 exploited) | RCE (12) | CVE-2023-24932 Secure Boot bypass, exploited by BlackLotus UEFI bootkit |
| 2023-06 | 69 | 6 | 0 | RCE (25) | CVE-2023-29357 SharePoint privilege escalation, CVSS 9.8 |
| 2023-07 | 130 | 9 | 6 (6 exploited) | RCE (37) | CVE-2023-36884 Office/HTML RCE, exploited by Storm-0978 (RomCom) |
| 2023-08 | 74 | 6 | 0 | RCE (18) | CVE-2023-21709 Exchange Server EoP 9.8 (treat as Critical) |
| 2023-09 | 59 | 5 | 2 (2 exploited) | RCE (15) | CVE-2023-36761 Word info disclosure (NTLM hash), exploited via preview pane |
| 2023-10 | 102 | 13 | 3 (2 exploited) | Elevation of Privilege (30) | CVE-2023-35349 MSMQ RCE 9.8 (~20% of the month was Message Queuing bugs) |
| 2023-11 | 63 | 3 | 6 (3 exploited) | RCE (15) | CVE-2023-36397 PGM RCE 9.8 |
| 2023-12 | 33 | 4 | 0 | Elevation of Privilege (10) | CVE-2023-35628 MSHTML RCE 8.1 (code exec before Preview Pane) |
| 2024-01 | 49 | 2 | 0 | Info Disclosure (11) | CVE-2024-20674 Kerberos SFB 9.0 (MITM spoofing a Kerberos server) |
| 2024-02 | 72 | 5 | 2 (2 exploited) | RCE (18) | CVE-2024-21410 Exchange EoP 9.8 (NTLM relay), exploited; + SmartScreen/Shortcut SFBs |
| 2024-03 | 59 | 2 | 0 | Elevation of Privilege (20) | CVE-2024-21334 Open Management Infrastructure RCE 9.8 |
| 2024-04 | 147 | 3 | 2 (2 exploited) | RCE (45) | CVE-2024-26234 proxy driver spoofing, exploited; the largest Patch Tuesday of 2024 |
| 2024-05 | 59 | 1 | 2 (2 exploited) | RCE (16) | CVE-2024-30051 DWM Core EoP, exploited (paired with QakBot); CVE-2024-30040 MSHTML SFB |
| 2024-06 | 49 | 1 | 0 | Elevation of Privilege (19) | CVE-2024-30080 MSMQ RCE 9.8 (potentially wormable) |
| 2024-07 | 139 | 5 | 2 (2 exploited) | RCE (59) | CVE-2024-38077 Remote Desktop Licensing RCE 9.8 |
| 2024-08 | 90 | 7 | 10 (6 exploited) | Elevation of Privilege (36) | CVE-2024-38063 TCP/IP IPv6 RCE, CVSS 9.8, wormable |
| 2024-09 | 79 | 7 | 4 (4 exploited) | Elevation of Privilege (30) | CVE-2024-43491 Windows Update RCE, CVSS 9.8 |
| 2024-10 | 118 | 3 | 5 (2 exploited) | RCE (39) | CVE-2024-43468 Config Manager RCE, CVSS 9.8 |
| 2024-11 | 89 | 4 | 4 (2 exploited) | Elevation of Privilege (26) | CVE-2024-43639 Kerberos RCE, CVSS 9.8, potentially wormable |
| 2024-12 | 71 | 16 | 1 (1 exploited) | RCE (27) | CVE-2024-49112 LDAP RCE, CVSS 9.8, unauthenticated DC RCE |
| 2025-01 | 159 | 11 | 8 (3 exploited) | RCE (60) | CVE-2025-21298 OLE RCE, CVSS 9.8; largest month since 2017 |
| 2025-02 | 57 | 4 | 4 (2 exploited) | RCE (18) | CVE-2025-21198 HPC Pack RCE, CVSS 9.0 |
| 2025-03 | 56 | 6 | 7 (6 exploited) | RCE (17) | CVE-2025-24993 NTFS RCE (exploited) |
| 2025-04 | 124 | 11 | 1 (1 exploited) | Elevation of Privilege (50) | CVE-2025-29824 CLFS EoP, exploited in ransomware |
| 2025-05 | 75 | 12 | 7 (5 exploited) | RCE (18) | CVE-2025-29813 Azure DevOps EoP, CVSS 10.0 |
| 2025-06 | 66 | 10 | 2 (1 exploited) | RCE (20) | CVE-2025-33053 WebDAV RCE, exploited |
| 2025-07 | 130 | 10 | 1 | Elevation of Privilege (53) | CVE-2025-47981 SPNEGO NEGOEX RCE, CVSS 9.8, wormable |
| 2025-08 | 107 | 13 | 1 | Elevation of Privilege (42) | CVE-2025-53766 GDI+ heap-overflow RCE, CVSS 9.8 |
| 2025-09 | 81 | 8 | 2 | Elevation of Privilege (39) | CVE-2025-55232 HPC Pack RCE, CVSS 9.8, potentially wormable |
| 2025-10 | 172 | 16 | 6 (3 exploited) | Elevation of Privilege (80) | CVE-2025-59287 WSUS RCE, CVSS 9.8, wormable (later exploited) |
| 2025-11 | 63 | 4 | 1 (1 exploited) | Elevation of Privilege (28) | CVE-2025-60724 GDI+ RCE, CVSS 9.8 |
| 2025-12 | 56 | 3 | 3 (1 exploited) | Elevation of Privilege (26) | CVE-2025-62221 Cloud Files EoP, exploited |
| 2026-01 | 112 | 8 | 3 (1 exploited) | Elevation of Privilege (50) | CVE-2026-20805 DWM info disclosure, exploited |
| 2026-02 | 58 | 5 | 6 | Elevation of Privilege (29) | CVE-2026-21531 Azure SDK for Python RCE, CVSS 9.8, unauthenticated |
| 2026-03 | 84 | 8 | 2 | Elevation of Privilege (45) | CVE-2026-26144 Excel zero-click Copilot Agent data exfil, CVSS 7.5 |
| 2026-04 | 163 | 8 | 2 (1 exploited) | Elevation of Privilege (81) | CVE-2026-32201 SharePoint spoofing, exploited zero-day; CVE-2026-33824 IKE RCE, CVSS 9.8 |
| 2026-05 | 138 | 30 | 0 | Elevation of Privilege (53) | CVE-2026-42898 Dynamics 365 on-prem RCE, CVSS 9.9; first zero-day-free month since Jun 2024 |
| 2026-06 | 200 | 33 | 6 (1 exploited) | Elevation of Privilege (65) | CVE-2026-42897 Exchange spoofing, actively exploited zero-day |
| 2026-07 | 569 | 56 | 3 (2 exploited) | RCE (140) | CVE-2026-56155 ADFS EoP, actively exploited; largest Patch Tuesday on record |
Three things the month-by-month view makes obvious
- Elevation of privilege is the workhorse. It's the largest or second-largest class in almost every month — the bug attackers chain after an initial foothold, not the flashy pre-auth RCE that gets headlines.
- Zero-days are lumpy, not trending. Months swing from 0 (May 2026 — the first zero-day-free Patch Tuesday since June 2024) to 10 (August 2024). No smooth climb; exploitation is opportunistic.
- 2026 is where the volume broke pattern. Four of the six largest months in the whole window are in 2026. Whether that's AI-assisted research, more internal Microsoft tooling, or a reporting change, the monthly data alone can't say — but the break is real.