Agregátor RSS
Microsoft’s Patch Tuesday updates: Keeping up with the latest fixes
Long before Taco Tuesday became part of the pop-culture vernacular, Tuesdays were synonymous with security — and for anyone in the tech world, they still are. Patch Tuesday, as you most likely know, refers to the day each month when Microsoft releases security updates and patches for its software products — everything from Windows to Office to SQL Server, developer tools to browsers.
The practice, which happens on the second Tuesday of the month, was initiated to streamline the patch distribution process and make it easier for users and IT system administrators to manage updates. Like tacos, Patch Tuesday is here to stay.
Patch Tuesday coverage has long been a staple of Computerworld’s commitment to provide critical information to the IT industry. That’s why we’ve gathered together this collection of recent patches, a rolling list we’ll keep updated each month.
In case you missed a recent Patch Tuesday announcement, here are the latest six months of updates.
September Patch Tuesday: 963 CVEs, 2 exploited flaws, 1 messageSeptember’s Patch Tuesday is Microsoft’s biggest of 2026, with 963 CVEs, two exploited flaws and a clear message: prioritize Windows, Office and SQL Server.
Two vulnerabilities are already exploited: CVE-2026-81963 in the Windows Update Stack and CVE-2026-85880 in Advanced Local Procedure Call. Nothing in this release was publicly disclosed ahead of the patch. Readiness recommends a Patch Now scheduling for Windows, Office, SQL Server and the developer tooling, and standard patch release for Exchange.
Get more info on the September 2026 Microsoft security updates.
August’s Patch Tuesday is a monster: 751 fixes, with an exploited Windows flawMicrosoft’s August 2026 Patch Tuesday closes at 751 CVE entries (across all product families), with 108 rated as critical. One flaw is already exploited, CVE-2026-68820, an elevation of privilege in the Windows WinSock driver (afd.sys). Two more were disclosed but not exploited.
This security-only release earns Patch Now for Windows, Office and Exchange; no SQL Server updates this month. Unfortunately, several critical issues affect server roles: Windows DNS Server carries a cluster of critical RCEs; Windows DHCP Server is the most-populated Microsoft product family at 14 entries. Testing should lead with printing and fonts and the Remote Desktop client, then a WinSock smoke test given the exploited afd.sys flaw.
Get more info on the August 2026 Microsoft security updates.
July’s Patch Tuesday sees an end-of-support collision amidst a massive, record-setting patch waveMicrosoft addressed 722 CVEs this month once the 427 Chromium upstream relays are set aside — roughly three times a normal cycle and one of the largest single months in recent memory. Two vulnerabilities arrive under active exploitation: an elevation of privilege in Active Directory Federation Services (CVE-2026-56155), and an elevation of privilege in SharePoint Server (CVE-2026-56164). A third, a BitLocker security feature bypass (CVE-2026-50661) is publicly disclosed but not yet exploited.
The July 2026 Patch Tuesday earns Patch Now recommendations for Windows, Office, Exchange, and SQL Server. SharePoint has two critical RCEs on top of its exploited zero-day, and Exchange Server returns with a critical on-premises spoofing flaw. Adding to our (dear) administrator’s efforts, SharePoint Server 2016/2019 and SQL Server 2016 all reach end of support today.
More info is available here on Microsoft Security updates for July 2026.
For June, Patch Tuesday means an IT scrambleMicrosoft this month released 206 updates affecting Windows, Office, Exchange Server, and its developer tools — including three Windows vulnerabilities already publicly disclosed. That trio includes an elevation of privilege in the Collaborative Translation Framework (CVE-2026-45586), a denial of service in HTTP.sys (CVE-2026-49160), and a BitLocker security feature bypass (CVE-2026-50507). At the moment, none appear to be under active exploitation, but all three are rated “Exploitation More Likely.”
Even without an exploited zero-day, the June 2026 Patch Tuesday release requires Patch Now recommendations for Windows, Office, and Exchange. The latter is back in the patch picture with a consolidated security update that Microsoft recommends installing “as soon as possible.”
More info is available here on Microsoft Security updates for June 2026.
For May, Patch Tuesday means 139 updates — but no zero-daysMicrosoft this month released 139 updates affecting Windows, Office, .NET, and SQL Server (though there were no updates for Microsoft Exchange Server). Despite the absence of zero-days, the May Patch Tuesday update still requires Patch Now recommendations for Windows and Office.
The combination of three unauthenticated network RCEs (Netlogon, DNS Client, and SSO Plugin for Jira and Confluence), four Word Preview Pane RCEs, the large TCP/IP vulnerability cluster, and the carry-over BitLocker recovery condition (still active on Windows 10 and Windows Server) warrants an accelerated deployment release schedule.
More info is available here on Microsoft Security updates for May 2026.
Microsoft’s Patch Tuesday release for April is a whopperWindows admins are going to be busy this month, dealing with the largest Patch Tuesday cycle in memory. The April release involves 165 updates and roughly 340 unique CVEs from Microsoft — including two zero-days, one of which is already being actively exploited in the wild.
The Readiness team recommends “Patch Now” schedules for nearly every major product family: Windows, Office (with a zero-day), Microsoft Edge (Chromium), SQL Server, and Microsoft Developer Tools (.NET). April also brings Phase 2 of Microsoft’s Kerberos RC4 hardening with full enforcement set for July. There is a lot to cover, so here’s a useful infographic mapping the deployment risk for each platform.
More info is available here on Microsoft Security updates for April 2026.
Linux nativně na ESP32-S3 – bez emulace a rovnou s 9,7″ e-paperem
Microsoft: September updates cause RDS failures on Windows Server
UK.gov begins killing off passwords for 23 million users
Samsung si rýpl do Applu jako nikdy předtím. Hvězdou reklamy na Galaxy Z Fold8 je Tim Cook
Revolut discloses data breach exposing financial info, passports
LibreOffice 26.8 vylepšuje sazbu textu a rychleji načítá velké dokumenty
Microsoft: September updates break audio on some Windows PCs
S čínskými HBM to nepůjde rychle, brzdou je výtěžnost
Nejlevnější OLED TV už stojí méně než 16 tisíc. LG se hodí na filmy i hry a lze ji využít také jako PC monitor
Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users
Porovnali jsme iPhone Duo, Galaxy Z Fold8 a Xiaomi 18 Fold. Která skládačka je nejlepší?
CISA: Hackers now exploit max severity GitLab flaw in attacks
Postřehy z bezpečnosti: pomozte likvidovat phishing
Íránci zajali americkou ponorku. Naštěstí byla jen bezpilotní a prý už nějaký čas mimo provoz
Intel: Vyrobili jsme milion waferů s High-NA EUV. TSMC: Do roku 2030 nemá smysl
Homebrew 7.0.0
Nic neuděláte špatně a stejně přijdete o peníze aneb Jak útočníci vykradli peněženky, které měly být nedobytné
FreeBSD pracuje na novém správci služeb, pracovní stanice Thelio Mira AI
- « první
- ‹ předchozí
- …
- 25
- 26
- 27
- 28
- 29
- 30
- 31
- 32
- 33
- …
- následující ›
- poslední »



