Patch Tuesday Dashboard: Monthly CVE Counts • SQ Magazine
How this tracker is maintained
Every cycle passes the same checks before it appears, on the vendor’s own schedule.
-
Sourced
Counts come from each vendor’s own security channel, linked on every row: Microsoft’s MSRC guide, Adobe’s APSB bulletins, SAP’s Security Patch Day notes, and the Siemens and Schneider Electric CSAF advisories. Chromium CVEs mirrored into Edge and server-side cloud fixes are excluded, because an administrator never installs them.
-
Dated
Each row is one vendor cycle, dated by its Patch Tuesday. The header names the next one.
-
Re-checked
Each cycle is re-checked after release; exploited-at-release flags and revised counts follow the vendor’s bulletin updates.
- Why do these counts differ from news reports?
- Most outlets count every CVE identifier in the bulletin. This tracker counts vulnerabilities that ship an installable update, which is the number an administrator actually patches.
- Which vendors are covered?
- Microsoft, Adobe, SAP, Siemens, and Schneider Electric, all of which release on the second Tuesday, plus security-software vendors in months where they publish CVE advisories for their own products. Vendor counts are not comparable to each other: Siemens advisories bundle upstream component CVEs, and SAP’s critical tier is its former HotNews band. Compare a vendor with itself over time, not with its neighbors.
- Can I cite this?
- Yes. Use “Cite this tracker” and cite the cycle month alongside any count.
This is informational content, not patching guidance for your environment. Counts reflect the vendor’s bulletin at release and can be revised. Prioritize using the linked advisory and your own asset inventory.