State now. Changed: 0 tier promotions, +4 known-exploited vulnerability additions, 27 leak-site claims, and 0 confirmed breaches since yesterday.
Patch Day archive
Start with the month, not a maze of menus. Each card shows the patch activity returned for this build, which vendors contributed, and the strongest exploitation signals. Open one to browse those records in stable, server-rendered pages.
Why now: September 2026 is the newest patch month in this site build.
What changed
This page does not publish a page-specific change count. Open the daily comparison for material tracker changes, then start with the newest vendor patch month below.
Details
The summary names this build's complete set, and each month shows its vendor mix and strongest exploitation signals.
September 2026
Period: Month to date through 2026-09-12 21:29 UTCAugust 2026
July 2026
June 2026
May 2026
April 2026
March 2026
February 2026
January 2026
December 2025
November 2025
October 2025
September 2025
August 2025
Vendor coverage
What the archive covers, and why some vendors are absent.
- MicrosoftCoveredPatch Tuesday: the Microsoft Security Response Center monthly release, tracked in depth on this page.
- AndroidCoveredGoogle Android Security Bulletins via the OSV feed. The fix commit is the CVE-to-patch link; severity is Android's qualitative rating (no CVSS).
- CiscoCoveredCisco public CSAF 2.0 advisories: per-CVE CVSS, a Security Impact Rating, and vendor-fix remediation links.
- Red HatCoveredRed Hat CSAF 2.0 security advisories (RHSA/RHBA/RHEA): a per-CVE CVSS base score where the advisory publishes one (v3 or v4), else Red Hat's own document severity, plus vendor-fix remediation links. CC BY 4.0, attributed to Red Hat, Inc. 29030 of 29030 row(s) carry a link to the original advisory (a document that publishes no self reference carries none).
- SAPNo machine-readable feedSAP Security Patch Day notes list the CVEs, but the patch detail (the Note that maps a CVE to its fix) requires an S-user support login. No anonymous machine-readable CVE-to-patch mapping exists.
- AdobeNo machine-readable feedAdobe publishes security bulletins (APSB) as HTML pages only, with no structured feed and no machine-readable CVE-to-patch mapping.
- FortinetNo machine-readable feedFortiGuard PSIRT advisories are HTML and RSS only, with no CSAF or JSON feed carrying a machine-readable CVE-to-fixed-version mapping.
- IvantiNo machine-readable feedIvanti security advisories are HTML only, with no structured feed and no machine-readable CVE-to-patch mapping.
Cross-vendor sources and licences
- Android Google Android Security Bulletins (via OSV) via feedAdvisory data under the Android Open Source Project (Apache 2.0); OSV feed CC-BY 4.0.
- Cisco Cisco Security Advisories (CSAF 2.0)Cisco Security Vulnerability Policy; CSAF documents published credential-free.
- Red Hat Red Hat Security Data (CSAF 2.0 advisories)CC BY 4.0, per Red Hat's own CSAF document legal_disclaimer; requires attribution to Red Hat, Inc. and a link to the original advisory.
Full obligations and source details are on the attributions page.
How this is computed
The archive groups source-returned vendor patch records by month. Counts describe this site build, tracked totals identify records also present in the vulnerability table, and source obligations remain listed above.
Method reviewed on .