Skip to main content

What Is Microsoft Patch Tuesday? Why It Matters for Your Business

What Is Microsoft Patch Tuesday?

Microsoft Patch Tuesday is the monthly release of security updates for Windows, Microsoft 365, Office, Azure, SQL Server, Edge, and the rest of the Microsoft product line. It happens on the second Tuesday of every month, when Microsoft's Security Response Center (MSRC) publishes fixes for every vulnerability it has confirmed and coordinated a patch for that month — typically anywhere from 60 to well over 150 individual CVEs (Common Vulnerabilities and Exposures), depending on the month.

For IT teams and managed service providers, Patch Tuesday is the single most important recurring event on the security calendar. It is the moment you find out which of your systems just became a target, how urgently you need to act, and how much testing and deployment work is about to land on your plate.

Why Is It Called "Patch Tuesday"? A Brief History

Microsoft formalised the practice in October 2003. Before that, security updates shipped whenever they were ready — which meant IT departments could be blindsided by patches (and the reboots that came with them) on any day of the week. Consolidating releases into a single, predictable monthly window on the second Tuesday let administrators plan testing, change windows, and communication in advance instead of reacting to updates ad hoc.

The name stuck, and "Patch Tuesday" is now used generically across the industry for any vendor's scheduled monthly security release — though Microsoft's is by far the most closely watched, given how much of the world's business infrastructure runs on Windows Server, Windows 10/11, and Microsoft 365.

When Is Patch Tuesday? The Release Schedule

Patch Tuesday falls on the second Tuesday of every month, without exception. Updates are typically published in the early hours (Pacific Time), which usually means late morning in the Gulf and South Asia. Outside of this monthly cadence, Microsoft also ships:

  • Out-of-band updates — emergency, unscheduled patches for vulnerabilities being actively exploited in the wild, which can't wait for the next monthly cycle.
  • "C" and "D" week updates — optional, non-security preview updates released in the third and fourth weeks of the month, giving IT teams an early look at fixes before they become mandatory.

What Actually Gets Patched Each Month?

Every CVE Microsoft discloses on Patch Tuesday is rated by severity — Critical, Important, Moderate, or Low — and scored using the industry-standard CVSS (Common Vulnerability Scoring System, 0–10). Alongside the score, MSRC flags whether each vulnerability has already been publicly disclosed or is being actively exploited in the wild at the time of release — both are strong signals that a fix needs to be prioritised over anything rated purely by severity.

The vulnerabilities themselves span the full Microsoft ecosystem: Windows kernel and driver components, Windows Server roles (Active Directory, DNS, RDP, SMB), Microsoft Office and SharePoint, Exchange Server, Azure services, SQL Server, and Microsoft Edge. Edge's Chromium-based CVEs are usually reported separately from the rest, since the browser updates continuously rather than strictly on the monthly cycle — a nuance that trips up a lot of manual CVE counting.

Why Patch Tuesday Matters for Your Business

The moment Microsoft publishes a patch, attackers have the information they need to reverse-engineer it and build an exploit — a technique known in the industry as "Exploit Wednesday." Security researchers have repeatedly shown that working exploits for newly disclosed Windows vulnerabilities can appear within 24 to 72 hours of the patch going out. Every day a critical fix sits unapplied is a day your exposure window stays open to attackers who are actively looking for exactly that gap.

This is exactly how a large share of ransomware incidents start: not through some exotic zero-day, but through a known, already-patched vulnerability that simply hadn't been rolled out yet on the affected machine. Consistent, prioritised patching is one of the highest-leverage, lowest-cost things a business can do for its security posture — and one of the most commonly neglected.

Patch Tuesday Best Practices for IT Teams

  • Triage by risk, not just severity. A CVE that's already being exploited in the wild should jump the queue ahead of a theoretically "Critical" one that isn't — real-world exploitation is the strongest urgency signal MSRC gives you.
  • Patch the priority items fast. Actively exploited or publicly disclosed vulnerabilities affecting internet-facing or high-value systems should be deployed within 48–72 hours wherever possible.
  • Test before broad rollout. Stage updates through a pilot ring of representative devices before pushing to the whole fleet — Patch Tuesday updates occasionally introduce their own regressions.
  • Track KB articles per product line, not just CVE counts. A single cumulative update (KB) commonly bundles the fix for dozens of CVEs at once — know which builds/KBs apply to which of your Windows Server and Windows 10/11 versions.
  • Watch for out-of-band patches. Don't assume the second Tuesday is the only day updates can matter — emergency releases for actively exploited flaws can land any day of the month.
  • Keep an accurate asset inventory. You can't prioritise what you don't know you're running — especially with Windows Server versions that are easy to lose track of across a growing environment.

Track Every Patch Tuesday Release With Our Free Tool

To make this easier, we built the Patch Tuesday Tracker — a free tool that pulls live data straight from Microsoft's official Security Update Guide for any month you pick. In seconds you can see:

  • The total number of CVEs and KB patch articles released that month
  • A severity breakdown (Critical / Important / Moderate / Low) with CVSS scores
  • Which CVEs are being actively exploited or were publicly disclosed before the patch — surfaced first, so you know what to prioritise
  • Every KB article released, which products it applies to, and how many CVEs it fixes
  • A per-product breakdown across Windows Server, Windows 11, and Windows 10

No sign-up required — try the Patch Tuesday Tracker here and pick any recent month to see exactly what shipped.

Frequently Asked Questions

What is Patch Tuesday?

Patch Tuesday is Microsoft's monthly, scheduled release of security updates for Windows, Microsoft 365, Office, Azure, SQL Server, and other Microsoft products, published on the second Tuesday of every month.

When is the next Patch Tuesday?

Always the second Tuesday of the month. You can check exactly what was released for any recent month — including the current one — with our free Patch Tuesday Tracker.

How many vulnerabilities does Microsoft patch each Patch Tuesday?

It varies significantly by month, ranging from roughly 60 to well over 150 CVEs across the full Microsoft product line, before counting Microsoft Edge's continuously-updated Chromium CVEs separately.

What is a zero-day vulnerability?

A zero-day is a vulnerability that is publicly known or being actively exploited before a patch exists. Once Microsoft ships the fix, MSRC continues to flag it as "publicly disclosed" or "exploited in the wild" so IT teams know it needs urgent attention even after a patch is available.

Should I install Patch Tuesday updates immediately?

For anything rated Critical, actively exploited, or publicly disclosed, yes — as fast as your testing process allows, ideally within 48–72 hours. Lower-severity, non-exploited updates can usually follow your normal staged rollout schedule.

What is "Exploit Wednesday"?

Industry shorthand for how quickly attackers reverse-engineer a Patch Tuesday fix into a working exploit — often within a day or two of release, which is why prompt patching of high-severity issues matters so much.


Not sure your patch management process is keeping up? Decoding IT's managed cybersecurity services test, prioritise, and roll out Windows and Microsoft 365 updates across your environment — so critical fixes land fast without breaking production. Talk to us about managed patching.