Skip to content

Patch Tuesday digest

Microsoft publishes its monthly security release on the second Tuesday. The day after, SentriKat sends you one email: what came out, and which parts of it touch the software you actually run.

It is an email, not a screen. There is no Patch Tuesday page in the product, nothing to open, nothing to configure month by month. If you are looking for where to click, there is nowhere: it arrives.

When it arrives

The day after Patch Tuesday: the Wednesday that follows the second Tuesday of the month, at 09:00 UTC.

That is usually the second Wednesday, and about one month in seven it is the third, because a month can start on a Wednesday. The rule that holds is the one written above: it follows the Tuesday, not the date.

The gap of a day is deliberate. Microsoft's advisories take some hours to be published and indexed everywhere, and a digest built the same evening would be built on half the picture.

What is in it

Five blocks, in this order:

  1. a heading, Patch Tuesday Digest with the month and year, and your organization's name under it;
  2. one line of summary: how many new CVEs were published in the last seven days that match your products, and across how many products;
  3. four boxes, Critical, High, Medium, Low;
  4. Top New CVEs, a table of at most ten;
  5. the View in SentriKat dashboard button, and the footer.

It goes to the active administrators of the organization who have an email address. Outside the SaaS you need SMTP configured for it to leave; on the SaaS it uses our mail and there is nothing to set up.

When it does not arrive

Three cases, and none of them is a fault:

  • no new CVEs matched in that window, so there is nothing to say;
  • the organization has alerts switched off and nothing critical or high came up;
  • the sending quota for the period is spent.

Trying it without waiting a month

POST /api/reports/patch-tuesday/trigger

Administrator only, five calls an hour. It takes days, to widen or narrow the window, and dry_run: with dry_run you get the summary back and nothing is sent, which is the way to see the shape of the mail before it reaches anyone.

What to do with it

Read it as a list of work, not as news. The part that matters is the one that names your own products: the rest of a Microsoft release is, for you, weather.

The findings themselves are already in the dashboard by the time the email arrives, and they behave like any other finding: same bands, same row menu, same assignment. The digest is a summary of something you can also see at Dashboard, not a separate list that needs its own workflow.

See also

  • Dashboard, where the same findings live
  • Remediation, for assigning them and for the deadlines
  • Alerts, for the other notifications and who receives them