Vendor of the WeekWeekly
Vendor of the week: Microsoft is having the busiest month
Updated 12 August 2026 · Timeframe: Last 30 days
Microsoft logged 1,121 new CVEs in the last 30 days, 36 on CISA KEV over the year, avg CVSS 7.3.
Why it matters
Vendor risk is concentrated and cyclical. Knowing which vendor in your stack is having a busy month tells you where to point limited patching attention.
Large CVE volume can be a positive signal that a vendor is working through its code base and eliminating vulnerabilities.
What to do
- Security leaders. If Microsoft is a core vendor, ask for their remediation posture and your exposure to this month's CVEs.
- Lean IT orgs. Prioritize Microsoft products in this cycle if you run them; deprioritize quiet vendors.
- MSPs. Track per-vendor velocity across clients to forecast patching load.
Our take
Naming the vendors driving this month's risk — with the data behind it — is the kind of specific, useful signal generic threat commentary never provides.
Earlier issues
Past states of this signal, most recent first.
11 August 2026 Vendor of the week: Oracle is having the busiest month
Timeframe: Last 30 days
Oracle logged 1,108 new CVEs in the last 30 days, 5 on CISA KEV over the year, avg CVSS 7.4.