Deep dive · Patch Tuesday

Microsoft Patch Tuesday, month by month — Jan 2018 to Jul 2026

The complete dataset — every second-Tuesday release across 103 months. New Microsoft CVEs only (third-party and Chromium republished advisories excluded). Sourced to the Zero Day Initiative's monthly reviews (Dustin Childs), cross-checked against Krebs, Tenable, and BleepingComputer. The long view shows what two years alone can't: a typical month ran 50–70 CVEs in 2018, crossed 100 regularly by 2020, settled near 90–100 through 2025, then broke every record in 2026.

8,993
CVEs patched, 103 months
new Microsoft CVEs
1150
rated Critical
13% of the total
299
zero-days
139 actively exploited at release
569
the July 2026 record
vs a double-digit norm in 2018

CVEs per month, 2018–2026, with exploited zero-days

Total new Microsoft CVEs (bars), one per Patch Tuesday. Red overlay = the actively-exploited zero-days that month. Labels mark January of each year.

0 250 500 750 1000 '18 '19 '20 '21 '22 '23 '24 '25 '26
Eight years in one view. The floor rose from the ~40–60 range in 2018 to ~90–100 by 2025, then 2026 shattered the ceiling — April 147, June 200, July 569. Zero Day Initiative / Tenable / Krebs

What kind of bug — category mix over time

Each bar is one month's CVEs, split by vulnerability class. The mix is strikingly stable across eight years.

0 125 250 375 500'18'19'20'21'22'23'24'25'26Elevation of PrivRemote Code ExecInfo DisclosureSpoofingSecurity BypassDenial of Service
The most important thing here is what does NOT change: across 103 months, elevation-of-privilege and remote-code-execution stay the two biggest slices. The volume grew; the kind of Windows bug did not. (Pre-2024 category splits are approximate — see note below.) ZDI monthly category tables

The full dataset

All 24 months. Zero-days column shows total publicly-known-or-exploited at release, with the actively-exploited subset called out. The last six months (from Feb 2026) are marked with dimmed rows — verified live but with the source discrepancies noted in the methodology.

MonthCVEsCriticalZero-daysTop categoryMost notable CVE
2018-01 56 16 2 (1 exploited) RCE (16) CVE-2018-0802 Office Equation Editor RCE, actively exploited; plus Meltdown/Spectre (ADV180002)
2018-02 50 14 1 RCE (14) CVE-2018-0852 Outlook memory-corruption RCE, Critical, code exec via Preview Pane
2018-03 75 14 2 Elevation of Privilege (23) CVE-2018-0886 CredSSP RCE — MITM on RDP sessions
2018-04 67 24 1 Info Disclosure (18) CVE-2018-1004 / Office & scripting-engine RCEs; 24 Critical
2018-05 68 21 4 (2 exploited) Elevation of Privilege (19) CVE-2018-8174 'Double Kill' VBScript RCE, actively exploited
2018-06 50 11 1 RCE (16) CVE-2018-8225 Windows DNSAPI RCE, wormable, SYSTEM-level
2018-07 53 18 0 RCE (14) CVE-2018-8327 PowerShell Editor Services RCE, Critical (no in-the-wild zero-days)
2018-08 60 20 2 (2 exploited) RCE (26) CVE-2018-8373 IE VBScript RCE, actively exploited (+ CVE-2018-8414 Shell RCE)
2018-09 61 17 4 (1 exploited) RCE (16) CVE-2018-8440 ALPC Task Scheduler EoP, publicly disclosed & exploited (PowerPool)
2018-10 49 12 4 (1 exploited) RCE (18) CVE-2018-8453 Win32k EoP, actively exploited (Kaspersky)
2018-11 63 12 3 (1 exploited) RCE (24) CVE-2018-8589 Win32k EoP, actively exploited
2018-12 39 9 2 (1 exploited) RCE (10) CVE-2018-8611 Windows Kernel EoP, actively exploited (third straight month)
2019-01 49 7 1 RCE (16) CVE-2019-0547 DHCP Client RCE, wormable, CVSS 9.8
2019-02 77 20 5 (1 exploited) RCE (29) CVE-2019-0676 IE information disclosure, actively exploited
2019-03 64 17 6 (2 exploited) RCE (28) CVE-2019-0808 Win32k EoP, exploited (chained with Chrome CVE-2019-5786)
2019-04 74 13 2 (2 exploited) RCE (26) CVE-2019-0859 Win32k use-after-free EoP, actively exploited
2019-05 79 22 2 (1 exploited) RCE (41) CVE-2019-0708 'BlueKeep' RDP pre-auth wormable RCE, CVSS 9.8
2019-06 88 21 4 RCE (26) CVE-2019-1069 Task Scheduler EoP, publicly disclosed (SandboxEscaper)
2019-07 78 15 8 (2 exploited) Elevation of Privilege (18) CVE-2019-1132 Win32k EoP, exploited by Buhtrap APT
2019-08 93 29 0 RCE (29) CVE-2019-1181 'DejaBlue' RDP pre-auth wormable RCE, CVSS 9.8
2019-09 80 17 4 (2 exploited) Elevation of Privilege (19) CVE-2019-1215 ws2ifsl EoP, actively exploited
2019-10 59 8 0 Elevation of Privilege (20) CVE-2019-1060 MSXML RCE, Critical
2019-11 74 13 1 (1 exploited) Elevation of Privilege (23) CVE-2019-1429 IE scripting-engine RCE, actively exploited
2019-12 36 7 1 (1 exploited) Info Disclosure (14) CVE-2019-1458 Win32k EoP, exploited in Operation WizardOpium
2020-01 49 8 0 Elevation of Privilege (13) CVE-2020-0601 'CurveBall' CryptoAPI cert-spoofing (NSA-reported), CVSS 8.1
2020-02 99 12 5 (1 exploited) Elevation of Privilege (55) CVE-2020-0674 IE scripting-engine RCE, actively exploited
2020-03 115 26 0 Elevation of Privilege (60) CVE-2020-0796 'SMBGhost' wormable SMBv3 RCE (patched out-of-band days later)
2020-04 113 17 4 (3 exploited) Elevation of Privilege (39) CVE-2020-1020 Adobe Type Manager RCE, actively exploited
2020-05 111 16 0 Elevation of Privilege (56) CVE-2020-1118 Windows TLS DoS (unauth lsass crash)
2020-06 129 11 3 Elevation of Privilege (70) CVE-2020-1281 Windows OLE RCE, Critical
2020-07 123 18 1 Elevation of Privilege (68) CVE-2020-1350 'SIGRed' wormable DNS Server RCE, CVSS 10.0
2020-08 120 17 2 (2 exploited) Elevation of Privilege (61) CVE-2020-1472 'Zerologon' Netlogon EoP, CVSS 10.0
2020-09 129 23 0 RCE (43) CVE-2020-16875 Exchange memory-corruption RCE (SYSTEM via email)
2020-10 87 11 6 Elevation of Privilege (36) CVE-2020-16898 'Bad Neighbor' TCP/IP RCE via ICMPv6, CVSS 9.8
2020-11 112 17 1 (1 exploited) Elevation of Privilege (37) CVE-2020-17087 Kernel EoP, exploited (chained with Chrome by Project Zero)
2020-12 58 9 0 RCE (16) CVE-2020-17095 Hyper-V RCE, guest-to-host escape
2021-01 83 10 2 (1 exploited) Elevation of Privilege (34) CVE-2021-1647 Microsoft Defender RCE, actively exploited
2021-02 56 11 7 (1 exploited) RCE (16) CVE-2021-1732 Win32k EoP exploited; CVE-2021-24078 DNS RCE 9.8
2021-03 89 14 7 (5 exploited) RCE (45) CVE-2021-26855 'ProxyLogon' Exchange SSRF→RCE, exploited by HAFNIUM
2021-04 114 19 5 (1 exploited) RCE (40) CVE-2021-28310 Win32k EoP exploited; NSA-reported Exchange RCE CVE-2021-28480 (9.8)
2021-05 55 4 3 RCE (18) CVE-2021-31166 HTTP.sys wormable RCE, CVSS 9.8
2021-06 50 5 9 (6 exploited) RCE (11) CVE-2021-33742 MSHTML RCE exploited (PuzzleMaker chain)
2021-07 117 13 9 (4 exploited) RCE (32) CVE-2021-34527 'PrintNightmare' Print Spooler RCE, exploited
2021-08 44 7 3 (1 exploited) Elevation of Privilege (16) CVE-2021-36948 Update Medic EoP exploited; CVE-2021-26424 TCP/IP RCE 9.9
2021-09 60 3 2 (1 exploited) Elevation of Privilege (22) CVE-2021-40444 MSHTML RCE, exploited via malicious Office docs
2021-10 71 2 4 (1 exploited) RCE (18) CVE-2021-40449 Win32k EoP, actively exploited
2021-11 55 6 4 (2 exploited) Elevation of Privilege (20) CVE-2021-42321 Exchange RCE, exploited (Tianfu Cup)
2021-12 67 7 6 (1 exploited) Elevation of Privilege (21) CVE-2021-43890 AppX Installer spoofing, exploited by Emotet
2022-01 96 9 6 Elevation of Privilege (41) CVE-2022-21907 HTTP.sys wormable RCE, CVSS 9.8
2022-02 48 0 1 RCE (16) CVE-2022-21989 Kernel EoP (no Critical-rated CVEs this month)
2022-03 71 3 3 RCE (28) CVE-2022-23277 Exchange Server RCE, authenticated
2022-04 128 10 2 (1 exploited) RCE (47) CVE-2022-24521 CLFS EoP, exploited (NSA-reported)
2022-05 74 7 3 (1 exploited) Elevation of Privilege (21) CVE-2022-26925 LSA spoofing / NTLM relay (PetitPotam), exploited
2022-06 55 3 1 (1 exploited) RCE (26) CVE-2022-30190 'Follina' MSDT RCE, exploited
2022-07 84 4 1 (1 exploited) Elevation of Privilege (52) CVE-2022-22047 CSRSS EoP, actively exploited
2022-08 121 17 2 (1 exploited) Elevation of Privilege (64) CVE-2022-34713 'DogWalk' MSDT RCE, actively exploited
2022-09 64 5 2 (1 exploited) RCE (23) CVE-2022-37969 CLFS EoP, actively exploited
2022-10 85 15 2 (1 exploited) Elevation of Privilege (39) CVE-2022-41033 COM+ Event System EoP, actively exploited
2022-11 64 11 6 (6 exploited) Elevation of Privilege (26) CVE-2022-41082 'ProxyNotShell' Exchange RCE, exploited
2022-12 52 6 2 (1 exploited) Elevation of Privilege (18) CVE-2022-44698 SmartScreen SFB (Mark-of-the-Web evasion), exploited
2023-01 98 11 2 (1 exploited) Elevation of Privilege (38) CVE-2023-21674 ALPC EoP, exploited (sandbox escape to SYSTEM)
2023-02 75 9 3 (3 exploited) RCE (24) CVE-2023-23376 CLFS EoP, exploited (also CVE-2023-21715, CVE-2023-21823)
2023-03 74 6 2 (2 exploited) RCE (18) CVE-2023-23397 Outlook EoP + CVE-2023-24880 SmartScreen, both exploited; CVE-2023-23392 HTTP RCE 9.8
2023-04 97 7 1 (1 exploited) RCE (48) CVE-2023-21554 'QueueJumper' MSMQ RCE 9.8; CVE-2023-28252 CLFS EoP exploited
2023-05 38 6 3 (2 exploited) RCE (12) CVE-2023-24932 Secure Boot bypass, exploited by BlackLotus UEFI bootkit
2023-06 69 6 0 RCE (25) CVE-2023-29357 SharePoint privilege escalation, CVSS 9.8
2023-07 130 9 6 (6 exploited) RCE (37) CVE-2023-36884 Office/HTML RCE, exploited by Storm-0978 (RomCom)
2023-08 74 6 0 RCE (18) CVE-2023-21709 Exchange Server EoP 9.8 (treat as Critical)
2023-09 59 5 2 (2 exploited) RCE (15) CVE-2023-36761 Word info disclosure (NTLM hash), exploited via preview pane
2023-10 102 13 3 (2 exploited) Elevation of Privilege (30) CVE-2023-35349 MSMQ RCE 9.8 (~20% of the month was Message Queuing bugs)
2023-11 63 3 6 (3 exploited) RCE (15) CVE-2023-36397 PGM RCE 9.8
2023-12 33 4 0 Elevation of Privilege (10) CVE-2023-35628 MSHTML RCE 8.1 (code exec before Preview Pane)
2024-01 49 2 0 Info Disclosure (11) CVE-2024-20674 Kerberos SFB 9.0 (MITM spoofing a Kerberos server)
2024-02 72 5 2 (2 exploited) RCE (18) CVE-2024-21410 Exchange EoP 9.8 (NTLM relay), exploited; + SmartScreen/Shortcut SFBs
2024-03 59 2 0 Elevation of Privilege (20) CVE-2024-21334 Open Management Infrastructure RCE 9.8
2024-04 147 3 2 (2 exploited) RCE (45) CVE-2024-26234 proxy driver spoofing, exploited; the largest Patch Tuesday of 2024
2024-05 59 1 2 (2 exploited) RCE (16) CVE-2024-30051 DWM Core EoP, exploited (paired with QakBot); CVE-2024-30040 MSHTML SFB
2024-06 49 1 0 Elevation of Privilege (19) CVE-2024-30080 MSMQ RCE 9.8 (potentially wormable)
2024-07 139 5 2 (2 exploited) RCE (59) CVE-2024-38077 Remote Desktop Licensing RCE 9.8
2024-08 90 7 10 (6 exploited) Elevation of Privilege (36) CVE-2024-38063 TCP/IP IPv6 RCE, CVSS 9.8, wormable
2024-09 79 7 4 (4 exploited) Elevation of Privilege (30) CVE-2024-43491 Windows Update RCE, CVSS 9.8
2024-10 118 3 5 (2 exploited) RCE (39) CVE-2024-43468 Config Manager RCE, CVSS 9.8
2024-11 89 4 4 (2 exploited) Elevation of Privilege (26) CVE-2024-43639 Kerberos RCE, CVSS 9.8, potentially wormable
2024-12 71 16 1 (1 exploited) RCE (27) CVE-2024-49112 LDAP RCE, CVSS 9.8, unauthenticated DC RCE
2025-01 159 11 8 (3 exploited) RCE (60) CVE-2025-21298 OLE RCE, CVSS 9.8; largest month since 2017
2025-02 57 4 4 (2 exploited) RCE (18) CVE-2025-21198 HPC Pack RCE, CVSS 9.0
2025-03 56 6 7 (6 exploited) RCE (17) CVE-2025-24993 NTFS RCE (exploited)
2025-04 124 11 1 (1 exploited) Elevation of Privilege (50) CVE-2025-29824 CLFS EoP, exploited in ransomware
2025-05 75 12 7 (5 exploited) RCE (18) CVE-2025-29813 Azure DevOps EoP, CVSS 10.0
2025-06 66 10 2 (1 exploited) RCE (20) CVE-2025-33053 WebDAV RCE, exploited
2025-07 130 10 1 Elevation of Privilege (53) CVE-2025-47981 SPNEGO NEGOEX RCE, CVSS 9.8, wormable
2025-08 107 13 1 Elevation of Privilege (42) CVE-2025-53766 GDI+ heap-overflow RCE, CVSS 9.8
2025-09 81 8 2 Elevation of Privilege (39) CVE-2025-55232 HPC Pack RCE, CVSS 9.8, potentially wormable
2025-10 172 16 6 (3 exploited) Elevation of Privilege (80) CVE-2025-59287 WSUS RCE, CVSS 9.8, wormable (later exploited)
2025-11 63 4 1 (1 exploited) Elevation of Privilege (28) CVE-2025-60724 GDI+ RCE, CVSS 9.8
2025-12 56 3 3 (1 exploited) Elevation of Privilege (26) CVE-2025-62221 Cloud Files EoP, exploited
2026-01 112 8 3 (1 exploited) Elevation of Privilege (50) CVE-2026-20805 DWM info disclosure, exploited
2026-02 58 5 6 Elevation of Privilege (29) CVE-2026-21531 Azure SDK for Python RCE, CVSS 9.8, unauthenticated
2026-03 84 8 2 Elevation of Privilege (45) CVE-2026-26144 Excel zero-click Copilot Agent data exfil, CVSS 7.5
2026-04 163 8 2 (1 exploited) Elevation of Privilege (81) CVE-2026-32201 SharePoint spoofing, exploited zero-day; CVE-2026-33824 IKE RCE, CVSS 9.8
2026-05 138 30 0 Elevation of Privilege (53) CVE-2026-42898 Dynamics 365 on-prem RCE, CVSS 9.9; first zero-day-free month since Jun 2024
2026-06 200 33 6 (1 exploited) Elevation of Privilege (65) CVE-2026-42897 Exchange spoofing, actively exploited zero-day
2026-07 569 56 3 (2 exploited) RCE (140) CVE-2026-56155 ADFS EoP, actively exploited; largest Patch Tuesday on record
Totals, criticals, and zero-day counts are ZDI-sourced (100 of 103 months fetched directly this build). Three months are marked low-confidence: Feb 2023 and Jul 2023 (the ZDI page fetch failed — totals are from the historical record) and Apr 2024 (147 total cross-referenced from the ZDI July 2024 review). Per-category splits are approximate, especially before 2024. full data: patch-tuesday.json

Three things the month-by-month view makes obvious

  • Elevation of privilege is the workhorse. It's the largest or second-largest class in almost every month — the bug attackers chain after an initial foothold, not the flashy pre-auth RCE that gets headlines.
  • Zero-days are lumpy, not trending. Months swing from 0 (May 2026 — the first zero-day-free Patch Tuesday since June 2024) to 10 (August 2024). No smooth climb; exploitation is opportunistic.
  • 2026 is where the volume broke pattern. Four of the six largest months in the whole window are in 2026. Whether that's AI-assisted research, more internal Microsoft tooling, or a reporting change, the monthly data alone can't say — but the break is real.