Microsoft's May 2018 Patch Tuesday fixes 68 security issues, 21 of them critical, including one being actively exploited to hack users
Latest Patch Tuesday included 68 fixes, 21 of them rated “critical.” — Microsoft on Tuesday patched two Windows vulnerabilities that attackers …
Context & Ripple Effects
Microsoft's monthly Patch Tuesday ritual was already well established by May 2018, but this batch of 68 fixes — 21 critical, one under active attack — sits at the low end of an arc the later coverage makes explicit: the same cadence delivered 108 fixes in April 2021, 77 with three exploited zero-days in February 2023, and a record near-200 by mid-2026 as AI-assisted bug discovery scaled up.
What stays constant across every batch in the coverage is the actively-exploited-in-the-wild flaw: it appears in this 2018 release and again in the November 2022 batch with six exploited Windows zero-days, making each Patch Tuesday less a maintenance event than an emergency response for anyone running Windows.
First-order effects
- Windows and Office administrators must treat this cycle as urgent rather than routine — at least one of the 68 patched vulnerabilities is already being used to hack users, so unpatched machines are live targets until the update lands.
- Microsoft's own advisory burden grows immediately: 21 critical ratings mean enterprise patch teams must triage within days, not the month-long cycles some organizations historically allowed.
Second-order effects
- Attackers who lose the actively exploited flaw will reverse-engineer the patch to find unpatched variant bugs, pushing the next wave of exploitation toward customers who lag on deployment.
- Security vendors and managed service providers gain a recurring selling point — patch-management-as-a-service — because each month's batch, from this 68-fix release onward, is too large and too urgent for understaffed IT teams to handle alone.
Third-order effects
- If the trajectory in the coverage holds — 68 fixes here climbing to a record near-200 by June 2026 — the monthly patch becomes a permanent structural cost of running Windows, and AI-assisted vulnerability discovery turns the fix backlog into a growth curve rather than a one-off spike.
- The recurring pattern of actively exploited zero-days in nearly every batch points toward regulators and cyber-insurance markets treating timely Patch Tuesday deployment as a baseline duty of care for any organization running Microsoft software.
The trend: Microsoft's Patch Tuesday batches are swelling from dozens of fixes toward hundreds as AI-assisted bug discovery accelerates, while actively exploited zero-days make each monthly cycle a de facto emergency deadline for Windows users.