UK’s trusted IT infrastructure partner since 2003
Servnet
FinanceToolsConfiguratorGet in Touch
Cyber Security

Microsoft Vulnerabilities Per Year: 2026 Stats and Historical Trends

Servnet Editorial · IT infrastructure analysis8 min read
Share

Enterprise infrastructure teams face a record‑breaking surge in update volumes in 2026, punctuated by Microsoft’s Security Update Guide listing 974 Microsoft CVEs across its September 2026 security release—shattering previous September totals such as 86 CVEs in September 2025 and 79 in September 2024. Across the preceding five years, Microsoft averaged between 968 and 1,250 total CVEs per calendar year; by contrast, 2026 is tracking toward more than 2,500 annual disclosures. With July 2026 already having logged 622 unique CVEs and September delivering nearly 1,000, the sheer scale of modern releases has strained standard operational windows. In the UK, where organisations accredited under the National Cyber Security Centre (NCSC) Cyber Essentials scheme must deploy critical patches within 14 days, traditional monthly deployment cadences are breaking down. Defending against modern threats requires shifting away from calendar-driven updates toward risk-based triage, focusing immediately on internet-facing assets, zero-day vulnerabilities, and widespread privilege-escalation vectors. Reviewing the latest Microsoft Patch Tuesday updates reveals an operational reality where volume demands structured, severity-based prioritisation.

September 2026 Microsoft CVE Count by Product
730 CVEs548 CVEs365 CVEs183 CVEs0 CVEs723 CVEsWindows OS111 CVEsOffice Apps62 CVEsSQL Server16 CVEsSharePointSeptember 2026 CVEs
View the data behind this chart
September 2026 Microsoft CVE Count by Product
Windows OSOffice AppsSQL ServerSharePoint
September 2026 CVEsCVEs723CVEs111CVEs62CVEs16

Multi-Year Annual Trends and the 2026 Vulnerability Surge

Understanding vulnerability volume in 2026 requires contextualising recent monthly spikes within historical annual baselines. Over the previous five calendar years, total annual Microsoft CVE disclosures remained relatively consistent: 1,250 CVEs in 2020, 1,212 in 2021, 968 in 2022, 970 in 2023, 1,142 in 2024, and 1,120 in 2025. Across that multi-year period, monthly Patch Tuesday disclosures routinely averaged 70 to 100 CVEs. By contrast, 2026 has witnessed unprecedented monthly concentration, putting full-year 2026 projections on track to more than double the annual average of the prior half-decade.

The September 2026 release cycle, published on 8 September 2026, registered a staggering 974 Microsoft CVEs. This represents a historic single-month record, vastly exceeding the 86 CVEs published in September 2025 and the 79 CVEs published in September 2024. In fact, the September 2026 release alone virtually matched the entire annual CVE output of 2022 (968 CVEs) in a single 30-day window. This surge follows elevated mid-year benchmarks, including July 2026 which tracked 622 unique CVEs according to MSRC data (with the Zero Day Initiative recording 621 CVEs), whereas intervening baseline months such as August 2026 logged 98 CVEs.

These figures illustrate that 2026 patch load is characterised by extreme volatility rather than steady baselines. For enterprise administrators, the swing from a typical monthly volume of roughly 100 CVEs to over 600 in July and nearly 1,000 in September shatters static resource allocation models. Rather than handling predictable monthly batches, infrastructure teams must routinely ingest hundreds of updates across modern client builds—such as Windows 11 Version 26H1 for ARM64-based systems referenced in advisory CVE-2026-69467—and core platform services simultaneously.

  • Annual historical baseline (2020–2025): 1,250 (2020), 1,212 (2021), 968 (2022), 970 (2023), 1,142 (2024), and 1,120 (2025).
  • Comparative September volumes: 974 CVEs in September 2026 vs 86 in September 2025 and 79 in September 2024.
  • July 2026 benchmark: 622 unique CVEs recorded by MSRC (621 recorded by ZDI).
  • Volatility: Monthly counts oscillate between standard baselines (~98 in August) and massive surges (974 in September).
Illustration: Microsoft Vulnerabilities Per Year: 2026 Statistics and Historical Trends

Severity and Impact Distribution: Privilege Escalation Dominance

A granular examination of the September 2026 release reveals critical shifts in impact types and exploitation ratings. AP7i’s breakdown of Microsoft’s September 2026 release shows Elevation of Privilege (EoP) accounted for 438 CVEs, representing the single largest category of vulnerabilities for the month. According to AP7i’s September 2026 analysis of MSRC data, Remote Code Execution (RCE) accounted for 258 CVEs, Information Disclosure totalled 173, and Denial of Service (DoS) comprised 56 advisories.

While high-profile discussions frequently focus on RCEs, the heavy concentration of 438 EoP vulnerabilities is particularly dangerous for enterprise identity perimeters. Attackers often chain an initial low-privilege entry point with local privilege escalation to compromise system kernels, access local Security Account Manager (SAM) databases, or move laterally across corporate subnets.

Severity ratings further underscore the risk. Out of the September advisories, Microsoft designated 113 CVEs as Critical and flagged 58 as 'Exploitation More Likely'. The release also included two actively exploited zero‑day vulnerabilities. When over 100 vulnerabilities in a single release warrant a Critical classification and dozens carry verified weaponisation profiles, blanket patching without automated prioritisation risks catastrophic operational delays.

  • Elevation of Privilege (EoP): 438 CVEs in September 2026.
  • Remote Code Execution (RCE): 258 CVEs in September 2026.
  • Information Disclosure: 173 CVEs in September 2026.
  • Denial of Service (DoS): 56 CVEs in September 2026.
  • High-risk classifications: 113 Critical CVEs, 58 flagged 'Exploitation More Likely', and 2 zero-days.

Product-Family Vulnerability Exposure: Windows, Data, and Collaboration

The patch burden is not distributed uniformly across the Microsoft technology stack. Analysis of September 2026 data shows that Windows client and server operating system components accounted for 723 CVEs out of Microsoft’s 974‑CVE release, forming the majority of the month’s Microsoft vulnerabilities. The remaining September 2026 enterprise footprint included 111 Office CVEs, 62 SQL Server CVEs, and 16 SharePoint Server CVEs.

This broad distribution highlights the architectural complexity of contemporary Microsoft environments. Securing an enterprise estate requires coordinating updates across user productivity applications, database engines, and shared intranet workloads alongside underlying OS components. Furthermore, core security infrastructure components require dedicated attention; for instance, advisory CVE‑2026‑50656 addressed the Microsoft Malware Protection Engine, with versions 1.1.26050.11 listed as affected and 1.1.26060.3008 documented as the fixed build.

Because SQL Server and SharePoint Server host core operational databases and document repositories, applying 62 database patches and 16 SharePoint updates involves strict staging to avoid application downtime or breaking database schema connections. Enterprise IT departments using vulnerability management solutions must decouple high-impact server tiers from standard desktop rollout schedules to maintain continuity.

  • Windows core operating system: 723 CVEs in September 2026.
  • Microsoft Office productivity stack: 111 CVEs in September 2026.
  • Microsoft SQL Server database tier: 62 CVEs in September 2026.
  • Microsoft SharePoint Server collaboration layer: 16 CVEs in September 2026.
  • Malware Protection Engine engine fix: version 1.1.26050.11 updated to 1.1.26060.3008 (CVE-2026-50656).

The UK Operational Reality: Reconciling High Volumes with NCSC SLAs

For UK-based organisations, high monthly vulnerability counts create compliance friction with established security standards. The UK National Cyber Security Centre (NCSC) Cyber Essentials requirements state that software must be updated, including vulnerability fixes, within 14 days of release where the update fixes vulnerabilities described by the vendor as ‘critical’ or ‘high risk’, or addresses vulnerabilities with a CVSS v3 base score of 7.0 or above. When a single monthly cycle contains 974 CVEs—with 113 rated Critical—completing testing, pilot ring sign-off, and broad deployment across an entire infrastructure estate within a two-week window demands rigorous process automation.

This 14‑day requirement is typically more aggressive than the 30‑day or longer enterprise change windows often used across mid‑market IT departments. The requirement commonly applies across public-sector organisations and private commercial entities participating in UK government supply chains where Cyber Essentials certification is specified as a condition. Delaying in‑scope updates beyond 14 days causes organisations to fail Cyber Essentials assessment and leaves systems exposed during peak weaponisation periods.

To support rapid response, the NCSC operates an Early Warning service that publishes daily intelligence summaries covering 24-hour periods ending at 17:00 on the previous working day. This alert mechanism provides UK defenders with continuous threat telemetry rather than leaving them dependent on monthly vendor disclosures. UK infrastructure leaders must integrate this daily feed into internal ticketing queues to identify active exploits long before monthly deployment pipelines complete.

  • NCSC Cyber Essentials mandate: Critical vulnerabilities must be patched within 14 days of release.
  • NCSC Early Warning service: Daily feeds covering 24-hour periods ending at 17:00 the previous day.
  • Commercial impact: Supply chain compliance depends on maintaining the 14-day SLA, even during 900+ CVE cycles.

Strategic Patch Triage: Moving Beyond Blanket Monthly Deployment

Managing sustained volumes of 600 to nearly 1,000 monthly CVEs requires abandoning manual patch review in favour of structured triage. The NCSC guidance for Microsoft environments consistently emphasises internet-facing systems and domain controllers as estate components that require rapid patching because they are likely to be targeted early following a major release. Vulnerabilities affecting exposed edge services or identity infrastructure require targeted remediation out-of-band, bypassing prolonged testing queues.

To maintain both operational stability and rapid defense, UK organisations should implement a multi-tier patch strategy. Tier 1 encompasses internet-exposed web endpoints, reverse proxies, and Active Directory domain controllers, which must receive fixes for zero-days, Critical RCEs, and vulnerabilities flagged 'Exploitation More Likely' (such as the 58 identified in September 2026) within 48 to 72 hours.

Tier 2 focuses on internal application servers, including SQL Server clusters (navigating the 62 CVEs reported) and SharePoint farms (16 CVEs), deploying within a validated 7- to 10-day window following automated regression checks. Tier 3 covers standard Windows 11 enterprise endpoints, completing full deployment within the mandatory 14-day Cyber Essentials limit. Enforcing rigid zero trust network access controls limits lateral movement should low-level workstation patching lag slightly behind exposed server remediations.

  • Tier 1 (48-72 hours): Edge services, domain controllers, zero-days, and 'Exploitation More Likely' CVEs.
  • Tier 2 (7-10 days): Internal database (SQL) and collaboration (SharePoint) workloads with staged regression.
  • Tier 3 (Under 14 days): Standard client endpoints (Windows 11) to comply with Cyber Essentials certification.
  • Architectural isolation: Zero trust access restrictions to minimise lateral traversal from delayed workstation patches.
UK Cyber Essentials 14-Day Patch SLA Window
W0W1W2W3W4Triage & Alert Ingestion1wDC & Perimeter Patching1wDatabase & Staged Rollout1wBroad Endpoint Deployment1wTotal: 4 weeks end-to-end
View the data behind this chart
UK Cyber Essentials 14-Day Patch SLA Window
PhaseStarts (week)Duration (weeks)
Triage & Alert Ingestion11
DC & Perimeter Patching11
Database & Staged Rollout21
Broad Endpoint Deployment21

Hypothetical Incident Scenario: Multi-Tier Triage Under Cyber Essentials

[Hypothetical Implementation Scenario — For Illustrative Purposes Only] The following worked walkthrough models how an operational team might execute risk-based triage against high-volume releases. Consider a mid-sized UK engineering consultancy operating an estate comprising 450 Windows 11 endpoints, four Active Directory domain controllers, two SQL Server database instances, and an internet-facing SharePoint portal. On 8 September 2026, Microsoft releases its 974-CVE update bundle, which includes two zero-days, 113 Critical vulnerabilities, 723 Windows CVEs, 62 SQL Server CVEs, and 16 SharePoint CVEs.

Under a traditional unsegmented patch policy, the consultancy's four-person IT team would face a highly demanding task—regression testing nearly 1,000 fixes across databases, internal systems, and laptops within the 14-day Cyber Essentials audit window—which in many organisations can lead to delayed rollouts.

By leveraging the NCSC Early Warning daily feed and applying vulnerability triage, the team identifies the two active zero-days and internet-facing SharePoint vulnerabilities on Day 1. The edge SharePoint servers and domain controllers are isolated and patched by Day 3. SQL Server updates are deployed to a test staging instance on Day 5 and pushed to production by Day 9. Windows 11 endpoints receive cumulative updates in staggered waves between Days 7 and 12. In this illustrative scenario, by Day 13 all 974 CVEs are addressed, the 14-day compliance threshold is achieved, and operational services avoid unscheduled downtime.

  • Day 1: Ingestion of MSRC release notes and NCSC Early Warning intelligence; zero-days isolated.
  • Days 2-3: Immediate patching of Active Directory domain controllers and internet-facing SharePoint servers.
  • Days 4-9: Staged deployment and validation across the 62 SQL Server database CVEs.
  • Days 7-12: Ring deployment to client workstations across the 723 Windows OS components.
  • Day 13: Full estate compliance verified within the 14-day Cyber Essentials window.

Methodology

This data study compiles and analyses vulnerability disclosures published by the Microsoft Security Response Center (MSRC) alongside multi-year historical tracking from 2020 through 2025 and monthly 2026 telemetry from independent cybersecurity organisations. For 2026, monthly disclosures across January through June and August averaged between 85 and 115 CVEs (with August logging 98 CVEs). July (622 CVEs) and September (974 CVEs) were specifically selected as focal points because they represent historic volume bookends where standard patching cadences faced acute failure modes under record-breaking patch loads.

Vulnerability volumes, severity distributions, and impacted product families were cross-verified across primary MSRC release notes and technical advisories, with supplemental cross-referencing provided by published analyses from AdminSignal, AP7i, and Brinqa. Discrepancies between reporting frameworks—such as the single-CVE variance between MSRC (622 CVEs) and the Zero Day Initiative (621 CVEs) in July 2026—have been documented explicitly to ensure reporting fidelity.

Compliance and service-level frameworks were evaluated directly against technical specifications published by the UK National Cyber Security Centre (NCSC). This includes the 14-day remediation timeline mandated by the Cyber Essentials IT infrastructure requirements and daily alert structures operated through the NCSC Early Warning service.

Sources

Every figure in this article traces to the sources below.

  • Microsoft Security Response Center — September 2026 Update Guide
  • Microsoft Security Response Center — Advisory CVE-2026-69601
  • Microsoft Security Response Center — Advisory CVE-2026-69467
  • Microsoft Security Response Center — Advisory CVE-2026-50656
  • AdminSignal — September 2026 Patch Tuesday Priorities
  • AP7i — Microsoft September 2026 Analysis
  • Brinqa — Patch Tuesday CVE Tracker July 2026
  • NCSC — Cyber Essentials Infrastructure Requirements
  • NCSC — Early Warning Service
  • NCSC — Online Security Guidance for Microsoft Estates
Open data

The 9 data points behind this study are free to download, each with its source. The figures belong to those sources: cite the named source and check its terms before reusing a figure.

Cite as: Servnet Research, “Microsoft Vulnerabilities Per Year: 2026 Stats and Historical Trends”, servnetuk.com, 2026.

Servnet Research publishes dated observations from public sources for information only. It is not legal, security, financial or investment advice, and data are provided without warranty. Figures from named sources belong to those sources. Spotted an error, or want something corrected or removed? See our corrections and takedown policy.

Share
Key takeaways
  • Microsoft's Security Update Guide published 974 CVEs in September 2026, highlighting an intense operational burden for infrastructure teams.
  • Elevation of Privilege accounted for 438 of the September 2026 CVEs, making credential theft and lateral movement key enterprise threats.
  • Core Windows operating system components accounted for 723 CVEs in September 2026, alongside 111 Office, 62 SQL Server, and 16 SharePoint fixes.
  • The UK NCSC Cyber Essentials scheme enforces a strict 14-day patch SLA, making automated, tiered deployment essential.
  • Adopting a 3-tier triage strategy allows UK enterprises to secure domain controllers and edge assets within 72 hours while meeting compliance.
Frequently asked

FAQsMicrosoft Vulnerabilities Per Year

How many CVEs did Microsoft publish in September 2026?

Microsoft listed 974 Microsoft CVEs in its September 2026 Security Update Guide, released on 8 September 2026. This release included 113 vulnerabilities rated as Critical, 58 flagged as 'Exploitation More Likely', and two actively exploited zero-day flaws.

Which vulnerability types were most prevalent in the September 2026 Microsoft release?

Elevation of Privilege (EoP) was the most common vulnerability type with 438 CVEs. Remote Code Execution (RCE) accounted for 258 CVEs, Information Disclosure represented 173 CVEs, and Denial of Service (DoS) comprised 56 CVEs.

What are the specific product breakdowns for the September 2026 update?

The September 2026 release included 723 Windows CVEs, 111 Microsoft Office CVEs, 62 SQL Server CVEs, and 16 SharePoint Server CVEs. Additionally, security infrastructure fixes included an update to the Microsoft Malware Protection Engine (CVE-2026-50656).

What is the UK Cyber Essentials requirement for patching Microsoft vulnerabilities?

The UK NCSC Cyber Essentials scheme requires organisations to apply security updates for software vulnerabilities within 14 days of release. In practice, meeting this timeframe during months with over 900 CVEs is significantly easier with automated, tiered patch deployment.

How does the NCSC Early Warning service help UK IT teams?

The NCSC Early Warning service provides daily intelligence summaries covering a 24-hour period ending at 17:00 on the previous working day. This gives UK administrators continuous threat visibility rather than relying entirely on monthly patch summaries.

Related

Continue reading

More in Research

Got a question this study didn’t answer?

One conversation with an engineer who’s done this before. No sales script.

Talk to Servnet →

Talk to a UK specialist

Get expert advice or a no-obligation quote — servers, storage, networking, maintenance, finance and cloud. We reply the same working day.

or call 0800 987 4111