SQ Magazine The Threat Index Patch Tuesday Dashboard
Patch Tuesday Dashboard
This dashboard records monthly security-update cycles from nine vendors: Microsoft, Adobe, SAP, Siemens, and Schneider Electric on the second Tuesday, plus four security-software vendors in the months they publish CVE advisories for their own products. Each row gives the cycle month, how many vulnerabilities shipped an installable update, how many the vendor rated critical, and how many were reported as exploited at release. Counts are comparable for one vendor over time, never between vendors.
61 records next Patch Tuesday 8 Sep 2026 cycles through August 2026 last verified 14 Aug 2026 next review by 13 Sep 2026
- Cycles tracked
- 61
- Latest Microsoft cycle
- 345
- Zero-days in 2026
- 39
- Tracking since
- Jan 2025
Microsoft CVEs per cycle, Jan 2025 to Aug 2026
Latest change August 2026 cycle recorded from vendor advisories: Microsoft 345 CVEs (36 critical, 1 exploited), Adobe 51 (33 critical), SAP 28 notes (4 critical), Siemens 20 (2 critical). Schneider deferred pending verifiable advisory text. (14 Aug 2026) All changes
All records
61 cycles, newest cycle first. Filter or search below.
What is in scope Every bulletin a tracked vendor publishes in its monthly security cycle.
61 vendor cycles from 9 vendors, 4,047 CVEs in total, 2025-01 to 2026-08. Counts are comparable for one vendor over time, never between vendors. 78 of those were disclosed as exploited before a fix existed.
| Vendor | Cycle | CVEs | Critical | Zero-days (exploited at release) | Bulletin | Detail |
|---|---|---|---|---|---|---|
| Microsoft | Aug 2026 | 345 | 36 | 1 Exploited | Advisory ↗ | |
|
||||||
| Adobe | Aug 2026 | 51 | 33 | 0 Exploited | Advisory ↗ | |
|
||||||
| SAP | Aug 2026 | 28 | 4 | 0 | Advisory ↗ | |
|
||||||
| Siemens | Aug 2026 | 20 | 2 | 0 | Advisory ↗ | |
|
||||||
| Microsoft | Jul 2026 | 530 | 52 | 5 Exploited | Advisory ↗ | |
|
||||||
| SAP | Jul 2026 | 20 | 3 | 0 | Advisory ↗ | |
|
||||||
| Adobe | Jul 2026 | 98 | 72 | 1 Exploited | Advisory ↗ | |
|
||||||
| Siemens | Jul 2026 | 383 | 19 | 0 | Advisory ↗ | |
|
||||||
| Schneider Electric | Jul 2026 | 2 | 0 | 0 | Advisory ↗ | |
|
||||||
| ESET | Jul 2026 | 4 | 0 | 0 | Advisory ↗ | |
|
||||||
| Bitdefender | Jul 2026 | 1 | Undisclosed | 0 | Advisory ↗ | |
|
||||||
| Microsoft | Jun 2026 | 171 | 28 | 0 | Advisory ↗ | |
|
||||||
| SAP | Jun 2026 | 17 | 4 | 0 | Advisory ↗ | |
|
||||||
| Adobe | Jun 2026 | 145 | 64 | 1 Exploited | Advisory ↗ | |
|
||||||
| Siemens | Jun 2026 | 7 | 1 | 0 | Advisory ↗ | |
|
||||||
| Schneider Electric | Jun 2026 | 6 | 0 | 0 | Advisory ↗ | |
|
||||||
| Bitdefender | Jun 2026 | 2 | Undisclosed | 0 | Advisory ↗ | |
|
||||||
| Microsoft | May 2026 | 95 | 15 | 7 Exploited | Advisory ↗ | |
|
||||||
| SAP | May 2026 | 16 | 2 | 0 | Advisory ↗ | |
|
||||||
| Adobe | May 2026 | 51 | 26 | 1 Exploited | Advisory ↗ | |
|
||||||
| Siemens | May 2026 | 236 | 27 | 0 | Advisory ↗ | |
|
||||||
| Schneider Electric | May 2026 | 4 | 0 | 0 | Advisory ↗ | |
|
||||||
| Trend Micro | May 2026 | 8 | 0 | 1 Exploited | Advisory ↗ | |
|
||||||
| Kaspersky | May 2026 | 4 | Undisclosed | 0 | Advisory ↗ | |
|
||||||
| Microsoft | Apr 2026 | 152 | 6 | 8 Exploited | Advisory ↗ | |
|
||||||
| SAP | Apr 2026 | 19 | 1 | 0 | Advisory ↗ | |
|
||||||
| Adobe | Apr 2026 | 55 | 37 | 2 Exploited | Advisory ↗ | |
|
||||||
| Siemens | Apr 2026 | 22 | 2 | 0 | Advisory ↗ | |
|
||||||
| Schneider Electric | Apr 2026 | 9 | 1 | 0 | Advisory ↗ | |
|
||||||
| Microsoft | Mar 2026 | 61 | 2 | 1 Exploited | Advisory ↗ | |
|
||||||
| SAP | Mar 2026 | 16 | 2 | 0 | Advisory ↗ | |
|
||||||
| Adobe | Mar 2026 | 81 | 22 | 0 | Advisory ↗ | |
|
||||||
| Siemens | Mar 2026 | 37 | 2 | 0 | Advisory ↗ | |
|
||||||
| Schneider Electric | Mar 2026 | 6 | 0 | 0 | Advisory ↗ | |
|
||||||
| Kaspersky | Mar 2026 | 2 | Undisclosed | 0 | Advisory ↗ | |
|
||||||
| Microsoft | Feb 2026 | 38 | 0 | 8 Exploited | Advisory ↗ | |
|
||||||
| SAP | Feb 2026 | 28 | 2 | 0 | Advisory ↗ | |
|
||||||
| Adobe | Feb 2026 | 44 | 27 | 0 | Advisory ↗ | |
|
||||||
| Siemens | Feb 2026 | 13 | 0 | 0 | Advisory ↗ | |
|
||||||
| Schneider Electric | Feb 2026 | 3 | 1 | 0 | Advisory ↗ | |
|
||||||
| Trend Micro | Feb 2026 | 8 | 2 | 0 | Advisory ↗ | |
|
||||||
| ESET | Feb 2026 | 1 | 0 | 0 | Advisory ↗ | |
|
||||||
| Microsoft | Jan 2026 | 108 | 7 | 3 Exploited | Advisory ↗ | |
|
||||||
| SAP | Jan 2026 | 20 | 4 | 0 | Advisory ↗ | |
|
||||||
| Adobe | Jan 2026 | 25 | 18 | 0 | Advisory ↗ | |
|
||||||
| Siemens | Jan 2026 | 15 | 1 | 0 | Advisory ↗ | |
|
||||||
| Schneider Electric | Jan 2026 | 12 | 1 | 0 | Advisory ↗ | |
|
||||||
| Trend Micro | Jan 2026 | 8 | 1 | 0 | Advisory ↗ | |
|
||||||
| ESET | Jan 2026 | 1 | 0 | 0 | Advisory ↗ | |
|
||||||
| Microsoft | Dec 2025 | 54 | 2 | 1 Exploited | Advisory ↗ | |
|
||||||
| Microsoft | Nov 2025 | 51 | 3 | 1 Exploited | Advisory ↗ | |
|
||||||
| Microsoft | Oct 2025 | 155 | 7 | 8 Exploited | Advisory ↗ | |
|
||||||
| Microsoft | Sep 2025 | 77 | 8 | 0 | Advisory ↗ | |
|
||||||
| Microsoft | Aug 2025 | 94 | 9 | 2 Exploited | Advisory ↗ | |
|
||||||
| Microsoft | Jul 2025 | 125 | 14 | 3 Exploited | Advisory ↗ | |
|
||||||
| Microsoft | Jun 2025 | 57 | 9 | 1 Exploited | Advisory ↗ | |
|
||||||
| Microsoft | May 2025 | 58 | 5 | 5 Exploited | Advisory ↗ | |
|
||||||
| Microsoft | Apr 2025 | 107 | 11 | 2 Exploited | Advisory ↗ | |
|
||||||
| Microsoft | Mar 2025 | 48 | 5 | 7 Exploited | Advisory ↗ | |
|
||||||
| Microsoft | Feb 2025 | 45 | 3 | 6 Exploited | Advisory ↗ | |
|
||||||
| Microsoft | Jan 2025 | 148 | 10 | 3 Exploited | Advisory ↗ | |
|
||||||
No records match the current filters.
What the data shows
Every figure below comes from the verified table above, redrawn as the trends and comparisons a table cannot show.
Verification ledger
5 most recent of 5 logged updates- August 2026 cycle recorded from vendor advisories: Microsoft 345 CVEs (36 critical, 1 exploited), Adobe 51 (33 critical), SAP 28 notes (4 critical), Siemens 20 (2 critical). Schneider deferred pending verifiable advisory text. 14 Aug 2026
- Adobe April 2026 corrected: the cycle carried zero zero-days, but Adobe's out-of-band bulletin APSB26-43 (11 April) states CVE-2026-34621 was exploited in the wild. Zero-day count, exploited flag and CVE ID now recorded. 26 Jul 2026
- Dashboard expanded beyond Microsoft: 38 cycles added across Adobe, SAP, Siemens, Schneider Electric, Trend Micro, ESET, Kaspersky and Bitdefender, each verified against the vendor bulletin. 25 Jul 2026
- Methodology, per-cycle anchors, and record callouts added; the intro now states the tracker covers Microsoft cycles since January 2025. 24 Jul 2026
- Tracker launched with 19 Microsoft cycles covering January 2025 through July 2026. 22 Jul 2026
How this tracker is maintained
Every cycle passes the same checks before it appears, on the vendor’s own schedule.
-
Sourced
Counts come from each vendor’s own security channel, linked on every row: Microsoft’s MSRC guide, Adobe’s APSB bulletins, SAP’s Security Patch Day notes, and the Siemens and Schneider Electric CSAF advisories. Chromium CVEs mirrored into Edge and server-side cloud fixes are excluded, because an administrator never installs them.
-
Dated
Each row is one vendor cycle, dated by its Patch Tuesday. The header names the next one.
-
Re-checked
Each cycle is re-checked after release; exploited-at-release flags and revised counts follow the vendor’s bulletin updates.
- Why do these counts differ from news reports?
- Most outlets count every CVE identifier in the bulletin. This tracker counts vulnerabilities that ship an installable update, which is the number an administrator actually patches.
- Which vendors are covered?
- Microsoft, Adobe, SAP, Siemens, and Schneider Electric, all of which release on the second Tuesday, plus security-software vendors in months where they publish CVE advisories for their own products. Vendor counts are not comparable to each other: Siemens advisories bundle upstream component CVEs, Kaspersky’s fixes address third-party components inside its own products, and SAP’s critical tier is its former HotNews band. Compare a vendor with itself over time, not with its neighbors.
This is informational content, not patching guidance for your environment. Counts reflect the vendor’s bulletin at release and can be revised. Prioritize using the linked advisory and your own asset inventory.
Quoting a figure with a link to this page needs no permission. Cite it as you would any source. Reuse of the compiled dataset itself is licensed under CC BY 4.0: credit SQ Magazine and link back.