Microsoft Patch Tuesday: dates, versions & actively exploited flaws

Microsoft Patch Tuesday is the second Tuesday of the month, when Microsoft ships bundled security updates for Windows, Windows Server, Office, Exchange and more. patchletter shows the current versions of the Microsoft products it tracks and which flaws are already being actively exploited according to CISA.

Next Patch Tuesday:

Actively exploited at Microsoft (CISA KEV)

These tracked Microsoft products currently appear in the CISA KEV catalog with an actively exploited vulnerability β€” patch these first.

ProductCVE
Microsoft SharePoint ServerCVE-2026-45659Ransomware→
Microsoft Defender (Platform)CVE-2026-33825Ransomware→
Microsoft Exchange ServerCVE-2023-21529Ransomware→
Exchange ServerCVE-2023-21529Ransomware→
Microsoft SQL ServerCVE-2020-0618Ransomware→
Microsoft SharePoint ServerCVE-2023-24955Ransomware→
Microsoft SharePoint ServerCVE-2023-29357Ransomware→
Microsoft Exchange ServerCVE-2022-41080Ransomware→
Exchange ServerCVE-2022-41080Ransomware→
Microsoft Defender (Platform)CVE-2022-44698Ransomware→
Exchange ServerCVE-2022-41040Ransomware→
Microsoft Exchange ServerCVE-2022-41040Ransomware→
Microsoft Exchange ServerCVE-2022-41082Ransomware→
Exchange ServerCVE-2022-41082Ransomware→
Exchange ServerCVE-2018-8581Ransomware→
Microsoft Exchange ServerCVE-2018-8581Ransomware→
Exchange ServerCVE-2021-34523Ransomware→
Exchange ServerCVE-2021-26855Ransomware→
Exchange ServerCVE-2021-34473Ransomware→
Exchange ServerCVE-2021-31207Ransomware→
Exchange ServerCVE-2021-27065Ransomware→
Exchange ServerCVE-2021-26857Ransomware→
Exchange ServerCVE-2020-0688Ransomware→
Exchange ServerCVE-2021-26858Ransomware→
Microsoft Exchange ServerCVE-2021-34523Ransomware→
Microsoft Exchange ServerCVE-2021-34473Ransomware→
Microsoft Exchange ServerCVE-2021-31207Ransomware→
Microsoft Exchange ServerCVE-2021-26855Ransomware→
Microsoft Exchange ServerCVE-2021-26858Ransomware→
Microsoft Exchange ServerCVE-2020-0688Ransomware→
Microsoft Exchange ServerCVE-2021-27065Ransomware→
Microsoft Exchange ServerCVE-2021-26857Ransomware→
Microsoft SQL ServerCVE-2019-1068β†’
Microsoft SharePoint ServerCVE-2026-56164β†’
Microsoft Defender (Platform)CVE-2026-41091β†’
Microsoft Defender (Platform)CVE-2026-45498β†’
Microsoft SharePoint ServerCVE-2026-32201β†’
Microsoft Exchange ServerCVE-2021-31196β†’
Exchange ServerCVE-2021-31196β†’
Exchange ServerCVE-2024-21410β†’
Microsoft Exchange ServerCVE-2024-21410β†’
OutlookCVE-2023-35311β†’
Microsoft EdgeCVE-2016-7201β†’
Microsoft EdgeCVE-2016-7200β†’
Microsoft Exchange ServerCVE-2021-33766β†’
Exchange ServerCVE-2021-33766β†’
Microsoft Exchange ServerCVE-2020-17144β†’
Exchange ServerCVE-2020-17144β†’
Microsoft Defender (Platform)CVE-2021-1647β†’

Source: CISA KEV Β· updated daily

Current Microsoft versions

31 Microsoft products tracked by patchletter and their currently detected version.

All Patch Tuesday details

patchletter does not track individual Patch Tuesday CVEs β€” the full, rated list lives in the official Microsoft Security Update Guide. We show you what got updated and what is already being actively exploited.

Microsoft Security Update Guide (MSRC) β†’

Frequently asked questions

What is Microsoft Patch Tuesday?

Patch Tuesday is the second Tuesday of each month, when Microsoft releases its bundled security updates for Windows, Office, Exchange and other products. Admins plan their patching around this date.

When is the next Patch Tuesday?

The next Microsoft Patch Tuesday is 08/09/2026. It always falls on the second Tuesday of the month.

Does patchletter show every Patch Tuesday CVE?

No. patchletter shows the current versions of the Microsoft products it tracks and which of their vulnerabilities are actively exploited (CISA KEV). The complete list of every CVE is in Microsoft's Security Update Guide.

What does patchletter cost?

Nothing. Subscribe to your Microsoft tools with just an email address and get notified about new versions and actively exploited vulnerabilities.

Never miss a Microsoft update

Subscribe to your Microsoft tools and get an email the moment a new version ships or an actively exploited vulnerability appears.

Browse the catalog