PatchTriageWhat to patch first
Monthly patch-priority intelligence

PatchTriage

Every Patch Tuesday, ranked by what actually matters — not by raw severity, but by what is being exploited, what is publicly disclosed, and who has to patch it first.

Built on Microsoft's MSRC data and the CISA KEV catalog, corroborated across independent reporting and analyst briefings. A composite priority score puts a low-CVSS vulnerability under active attack ahead of an unexploited 9.8 — because that is the order you should patch them in.

Between the briefs · updated weekdays Being exploited right now → The Track 1 short list: CVEs on the CISA KEV catalog or with confirmed in-the-wild exploitation. Carries an as-of stamp from the brief that produced it.

Monthly briefs

August 2026426 of 790 CVEs
1 exploited2 zero-day62 critical (Microsoft)46 critical (everything else)
July 2026653 of 1,415 CVEs
4 exploited1 zero-day75 critical (Microsoft)39 critical (everything else)