Claude is having a major outage. Status board · Discuss Claude

Patch Tuesday: October 2025

Each month's Microsoft security updates: what to patch first, the Critical fixes, and what CISA says attackers are exploiting.

How to use it Start with "Patch these first" for the fixes attackers are already using. Then filter the list by product or keyword, or tick "Critical only" to narrow it down.

Next Patch Tuesday: Tue 13 Oct 2026 (in 3 days)

October 2025 Patch Tuesday: Microsoft fixed 167 vulnerabilities, 7 of them Critical. 2 were already being exploited. Released Tue 14 Oct 2025.

  • 167vulnerabilities fixed
  • 7Critical
  • 2exploited before the fix
  • 1publicly disclosed
  • 3now on CISA KEV

By type: 80 elevation of privilege, 29 remote code execution, 26 information disclosure, 11 denial of service, 10 security feature bypass, 10 spoofing, 1 tampering.

Update problems? Ask in Patch Tuesday & Updates. From October 2026 a “what broke for you?” thread opens there at 1 pm Eastern every Patch Tuesday.

Patch these first

Being exploited, already public, or on CISA’s list of vulnerabilities attackers are using. Whatever else waits for testing, these should not.

CVEWhatSeverityCVSSWhy first
CVE-2025-59287Windows Server Update Service (WSUS) Remote Code ExecutionCritical9.8On CISA KEV federal deadline 14 Nov
CVE-2025-24052Windows Agere Modem Driver Elevation of PrivilegeImportant7.8Publicly disclosed
CVE-2025-24990Windows Agere Modem Driver Elevation of PrivilegeImportant7.8Exploited On CISA KEV federal deadline 4 Nov
CVE-2025-59230Windows Remote Access Connection Manager Elevation of PrivilegeImportant7.8Exploited On CISA KEV federal deadline 4 Nov

Critical (7)

Microsoft’s top rating: usually code execution with little or no user action.

CVEWhatImpactCVSS
CVE-2025-49708Microsoft Graphics Component Elevation of PrivilegeElevation of Privilege9.9
CVE-2025-59287Windows Server Update Service (WSUS) Remote Code ExecutionRemote Code Execution9.8
CVE-2025-59236Microsoft Excel Remote Code ExecutionRemote Code Execution8.4
CVE-2025-59291Confidential Azure Container Instances Elevation of PrivilegeElevation of Privilege8.2
CVE-2025-59292Azure Compute Gallery Elevation of PrivilegeElevation of Privilege8.2
CVE-2025-59227Microsoft Office Remote Code ExecutionRemote Code Execution7.8
CVE-2025-59234Microsoft Office Remote Code ExecutionRemote Code Execution7.8

Added to CISA KEV in October 2025 (31)

Every vendor, not only Microsoft. CISA adds a vulnerability when it has evidence attackers are using it. US federal agencies must fix it by the deadline shown; for everyone else, it is the best free “patch this now” list there is.

CVEVendor and productWhatAddedFederal deadlineRansomware
CVE-2025-24893XWiki PlatformEval Injection30 Oct20 Nov 2025
CVE-2025-41244Broadcom VMware Aria Operations and VMware ToolsPrivilege Defined with Unsafe Actions30 Oct20 Nov 2025
CVE-2025-6204Dassault Systèmes DELMIA AprisoCode Injection28 Oct18 Nov 2025
CVE-2025-6205Dassault Systèmes DELMIA AprisoMissing Authorization28 Oct18 Nov 2025
CVE-2025-54236Adobe Commerce and MagentoImproper Input Validation24 Oct14 Nov 2025
CVE-2025-59287Microsoft WindowsServer Update Service (WSUS) Deserialization of Untrusted Data24 Oct14 Nov 2025
CVE-2025-61932Motex LANSCOPE Endpoint ManagerImproper Verification of Source of a Communication Channel22 Oct12 Nov 2025
CVE-2022-48503Apple Multiple ProductsUnspecified20 Oct10 Nov 2025
CVE-2025-2746Kentico Xperience CMSAuthentication Bypass Using an Alternate Path or Channel20 Oct10 Nov 2025
CVE-2025-2747Kentico Xperience CMSAuthentication Bypass Using an Alternate Path or Channel20 Oct10 Nov 2025
CVE-2025-33073Microsoft WindowsSMB Client Improper Access Control20 Oct10 Nov 2025
CVE-2025-61884Oracle E-Business SuiteServer-Side Request Forgery (SSRF)20 Oct10 Nov 2025Known
CVE-2025-54253Adobe Experience Manager (AEM) FormsAdobe Experience Manager Forms Code Execution15 Oct5 Nov 2025
CVE-2016-7836SKYSEA Client ViewImproper Authentication14 Oct4 Nov 2025
CVE-2025-24990Microsoft WindowsUntrusted Pointer Dereference14 Oct4 Nov 2025
CVE-2025-47827IGEL IGEL OSIGEL OS Use of a Key Past its Expiration Date14 Oct4 Nov 2025
CVE-2025-59230Microsoft WindowsImproper Access Control14 Oct4 Nov 2025
CVE-2021-43798Grafana Labs GrafanaGrafana Path Traversal9 Oct30 Oct 2025
CVE-2025-27915Synacor Zimbra Collaboration Suite (ZCS)Cross-site Scripting7 Oct28 Oct 2025
CVE-2010-3765Mozilla Multiple ProductsRemote Code Execution6 Oct27 Oct 2025
CVE-2010-3962Microsoft Internet ExplorerUninitialized Memory Corruption6 Oct27 Oct 2025
CVE-2011-3402Microsoft WindowsRemote Code Execution6 Oct27 Oct 2025
CVE-2013-3918Microsoft WindowsOut-of-Bounds Write6 Oct27 Oct 2025
CVE-2021-22555Linux KernelHeap Out-of-Bounds Write6 Oct27 Oct 2025
CVE-2021-43226Microsoft WindowsPrivilege Escalation6 Oct27 Oct 2025Known
CVE-2025-61882Oracle E-Business SuiteUnspecified6 Oct27 Oct 2025Known
CVE-2014-6278GNU GNU BashGNU Bash OS Command Injection2 Oct23 Oct 2025
CVE-2015-7755Juniper ScreenOSImproper Authentication2 Oct23 Oct 2025
CVE-2017-1000353Jenkins JenkinsJenkins Remote Code Execution2 Oct23 Oct 2025
CVE-2025-21043Samsung Mobile DevicesOut-of-Bounds Write2 Oct23 Oct 2025
CVE-2025-4008Smartbedded MeteobridgeCommand Injection2 Oct23 Oct 2025

All 167 fixes

Show the full list, with a filter
CVEProductWhatSeverityCVSS
CVE-2025-49708Microsoft Graphics ComponentMicrosoft Graphics Component Elevation of PrivilegeCritical9.9
CVE-2025-59287Windows Server Update ServiceWindows Server Update Service (WSUS) Remote Code ExecutionCritical9.8
CVE-2025-59236Microsoft Office ExcelMicrosoft Excel Remote Code ExecutionCritical8.4
CVE-2025-59291Confidential Azure Container InstancesConfidential Azure Container Instances Elevation of PrivilegeCritical8.2
CVE-2025-59292Confidential Azure Container InstancesAzure Compute Gallery Elevation of PrivilegeCritical8.2
CVE-2025-59227Microsoft OfficeMicrosoft Office Remote Code ExecutionCritical7.8
CVE-2025-59234Microsoft OfficeMicrosoft Office Remote Code ExecutionCritical7.8
CVE-2025-55315ASP.NET CoreASP.NET Security Feature BypassImportant9.9
CVE-2025-58715Microsoft Windows SpeechWindows Speech Runtime Elevation of PrivilegeImportant8.8
CVE-2025-58716Microsoft Windows SpeechWindows Speech Runtime Elevation of PrivilegeImportant8.8
CVE-2025-58718Remote Desktop ClientRemote Desktop Client Remote Code ExecutionImportant8.8
CVE-2025-59213Microsoft Configuration ManagerConfiguration Manager Elevation of PrivilegeImportant8.8
CVE-2025-59228Microsoft Office SharePointMicrosoft SharePoint Remote Code ExecutionImportant8.8
CVE-2025-59237Microsoft Office SharePointMicrosoft SharePoint Remote Code ExecutionImportant8.8
CVE-2025-59249Microsoft Exchange ServerMicrosoft Exchange Server Elevation of PrivilegeImportant8.8
CVE-2025-59295Internet ExplorerWindows URL Parsing Remote Code ExecutionImportant8.8
CVE-2025-53782Microsoft Exchange ServerMicrosoft Exchange Server Elevation of PrivilegeImportant8.4
CVE-2025-59250JDBC Driver for SQL ServerJDBC Driver for SQL Server SpoofingImportant8.1
CVE-2025-24052Agere Windows Modem DriverWindows Agere Modem Driver Elevation of PrivilegeImportant7.8
CVE-2025-24990Agere Windows Modem DriverWindows Agere Modem Driver Elevation of PrivilegeImportant7.8
CVE-2025-50152Windows KernelWindows Kernel Elevation of PrivilegeImportant7.8
CVE-2025-50175Windows Digital MediaWindows Digital Media Elevation of PrivilegeImportant7.8
CVE-2025-53150Windows Digital MediaWindows Digital Media Elevation of PrivilegeImportant7.8
CVE-2025-53768XboxXbox IStorageService Elevation of PrivilegeImportant7.8
CVE-2025-55328Windows Hyper-VWindows Hyper-V Elevation of PrivilegeImportant7.8
CVE-2025-55339Windows NDISWindows Network Driver Interface Specification (NDIS) Driver Elevation of PrivilegeImportant7.8
CVE-2025-55677Windows Device Association Broker serviceWindows Device Association Broker Service Elevation of PrivilegeImportant7.8
CVE-2025-55680Windows Cloud Files Mini Filter DriverWindows Cloud Files Mini Filter Driver Elevation of PrivilegeImportant7.8
CVE-2025-55692Windows Error ReportingWindows Error Reporting Service Elevation of PrivilegeImportant7.8
CVE-2025-55694Windows Error ReportingWindows Error Reporting Service Elevation of PrivilegeImportant7.8
CVE-2025-55696NtQueryInformation Token function (ntifs.h)NtQueryInformation Token function (ntifs.h) Elevation of PrivilegeImportant7.8
CVE-2025-55697Azure LocalAzure Local Elevation of PrivilegeImportant7.8
CVE-2025-55701Microsoft WindowsWindows Authentication Elevation of PrivilegeImportant7.8
CVE-2025-58714Windows Ancillary Function Driver for WinSockWindows Ancillary Function Driver for WinSock Elevation of PrivilegeImportant7.8
CVE-2025-58720Windows Cryptographic ServicesWindows Cryptographic Services Information DisclosureImportant7.8
CVE-2025-58722Windows DWMMicrosoft DWM Core Library Elevation of PrivilegeImportant7.8
CVE-2025-58724Azure Connected Machine AgentArc Enabled Servers – Azure Connected Machine Agent Elevation of PrivilegeImportant7.8
CVE-2025-58728Windows Bluetooth ServiceWindows Bluetooth Service Elevation of PrivilegeImportant7.8
CVE-2025-59187Windows KernelWindows Kernel Elevation of PrivilegeImportant7.8
CVE-2025-59191Connected Devices Platform Service (Cdpsvc)Windows Connected Devices Platform Service Elevation of PrivilegeImportant7.8
CVE-2025-59192Storport.sys DriverStorport.sys Driver Elevation of PrivilegeImportant7.8
CVE-2025-59199Software Protection Platform (SPP)Software Protection Platform (SPP) Elevation of PrivilegeImportant7.8
CVE-2025-59201Network Connection Status Indicator (NCSI)Network Connection Status Indicator (NCSI) Elevation of PrivilegeImportant7.8
CVE-2025-59207Windows KernelWindows Kernel Elevation of PrivilegeImportant7.8
CVE-2025-59222Microsoft Office WordMicrosoft Word Remote Code ExecutionImportant7.8
CVE-2025-59223Microsoft Office ExcelMicrosoft Excel Remote Code ExecutionImportant7.8
CVE-2025-59224Microsoft Office ExcelMicrosoft Excel Remote Code ExecutionImportant7.8
CVE-2025-59225Microsoft Office ExcelMicrosoft Excel Remote Code ExecutionImportant7.8
CVE-2025-59226Microsoft Office VisioMicrosoft Office Visio Remote Code ExecutionImportant7.8
CVE-2025-59230Windows Remote Access Connection ManagerWindows Remote Access Connection Manager Elevation of PrivilegeImportant7.8
CVE-2025-59231Microsoft Office ExcelMicrosoft Excel Remote Code ExecutionImportant7.8
CVE-2025-59233Microsoft Office ExcelMicrosoft Excel Remote Code ExecutionImportant7.8
CVE-2025-59238Microsoft Office PowerPointMicrosoft PowerPoint Remote Code ExecutionImportant7.8
CVE-2025-59241Windows Health and Optimized Experiences ServiceWindows Health and Optimized Experiences Elevation of PrivilegeImportant7.8
CVE-2025-59242Windows Ancillary Function Driver for WinSockWindows Ancillary Function Driver for WinSock Elevation of PrivilegeImportant7.8
CVE-2025-59243Microsoft Office ExcelMicrosoft Excel Remote Code ExecutionImportant7.8
CVE-2025-59254Windows DWM Core LibraryMicrosoft DWM Core Library Elevation of PrivilegeImportant7.8
CVE-2025-59255Windows DWM Core LibraryWindows DWM Core Library Elevation of PrivilegeImportant7.8
CVE-2025-59275Windows Authentication MethodsWindows Authentication Elevation of PrivilegeImportant7.8
CVE-2025-59277Windows Authentication MethodsWindows Authentication Elevation of PrivilegeImportant7.8
CVE-2025-59278Windows Authentication MethodsWindows Authentication Elevation of PrivilegeImportant7.8
CVE-2025-59281XBox Gaming ServicesXbox Gaming Services Elevation of PrivilegeImportant7.8
CVE-2025-59290Windows Bluetooth ServiceWindows Bluetooth Service Elevation of PrivilegeImportant7.8
CVE-2025-59494Azure Monitor AgentAzure Monitor Agent Elevation of PrivilegeImportant7.8
CVE-2025-53139Windows HelloWindows Hello Security Feature BypassImportant7.7
CVE-2025-55698Windows DirectXDirectX Graphics Kernel Denial of ServiceImportant7.7
CVE-2025-59200Data Sharing Service ClientData Sharing Service SpoofingImportant7.7
CVE-2025-55326Connected Devices Platform Service (Cdpsvc)Windows Connected Devices Platform Service (Cdpsvc) Remote Code ExecutionImportant7.5
CVE-2025-58726Windows SMB ServerWindows SMB Server Elevation of PrivilegeImportant7.5
CVE-2025-59248Microsoft Exchange ServerMicrosoft Exchange Server SpoofingImportant7.5
CVE-2025-48004Windows Brokering File SystemMicrosoft Brokering File System Elevation of PrivilegeImportant7.4
CVE-2025-55335Windows NTFSWindows NTFS Elevation of PrivilegeImportant7.4
CVE-2025-55687Windows Resilient File System (ReFS)Windows Resilient File System (ReFS) Elevation of PrivilegeImportant7.4
CVE-2025-55693Windows KernelWindows Kernel Elevation of PrivilegeImportant7.4
CVE-2025-59189Windows Brokering File SystemMicrosoft Brokering File System Elevation of PrivilegeImportant7.4
CVE-2025-59206Windows Resilient File System (ReFS) Deduplication ServiceWindows Resilient File System (ReFS) Deduplication Service Elevation of PrivilegeImportant7.4
CVE-2025-59210Windows Resilient File System (ReFS) Deduplication ServiceWindows Resilient File System (ReFS) Deduplication Service Elevation of PrivilegeImportant7.4
CVE-2025-25004Microsoft PowerShellPowerShell Elevation of PrivilegeImportant7.3
CVE-2025-55240Visual StudioVisual Studio Elevation of PrivilegeImportant7.3
CVE-2025-55247.NET.NET Elevation of PrivilegeImportant7.3
CVE-2025-59208Windows MapUrlToZoneWindows MapUrlToZone Information DisclosureImportant7.1
CVE-2025-59232Microsoft Office ExcelMicrosoft Excel Information DisclosureImportant7.1
CVE-2025-59235Microsoft Office ExcelMicrosoft Excel Information DisclosureImportant7.1
CVE-2025-47989Azure Connected Machine AgentArc Enabled Servers – Azure Connected Machine Agent Elevation of PrivilegeImportant7.0
CVE-2025-50174Windows Device Association Broker serviceWindows Device Association Broker Service Elevation of PrivilegeImportant7.0
CVE-2025-53717Windows Virtualization-Based Security (VBS) EnclaveWindows Virtualization-Based Security (VBS) Enclave Elevation of PrivilegeImportant7.0
CVE-2025-55331Windows PrintWorkflowUserSvcWindows PrintWorkflowUserSvc Elevation of PrivilegeImportant7.0
CVE-2025-55340Windows Remote Desktop ProtocolWindows Remote Desktop Protocol Security Feature BypassImportant7.0
CVE-2025-55678Windows DirectXDirectX Graphics Kernel Elevation of PrivilegeImportant7.0
CVE-2025-55681Windows DWMDesktop Window Manager Elevation of PrivilegeImportant7.0
CVE-2025-55684Windows PrintWorkflowUserSvcWindows PrintWorkflowUserSvc Elevation of PrivilegeImportant7.0
CVE-2025-55685Windows PrintWorkflowUserSvcWindows PrintWorkflowUserSvc Elevation of PrivilegeImportant7.0
CVE-2025-55686Windows PrintWorkflowUserSvcWindows PrintWorkflowUserSvc Elevation of PrivilegeImportant7.0
CVE-2025-55688Windows PrintWorkflowUserSvcWindows PrintWorkflowUserSvc Elevation of PrivilegeImportant7.0
CVE-2025-55689Windows PrintWorkflowUserSvcWindows PrintWorkflowUserSvc Elevation of PrivilegeImportant7.0
CVE-2025-55690Windows PrintWorkflowUserSvcWindows PrintWorkflowUserSvc Elevation of PrivilegeImportant7.0
CVE-2025-55691Windows PrintWorkflowUserSvcWindows PrintWorkflowUserSvc Elevation of PrivilegeImportant7.0
CVE-2025-58725Windows COMWindows COM+ Event System Service Elevation of PrivilegeImportant7.0
CVE-2025-58727Windows Connected Devices Platform ServiceWindows Connected Devices Platform Service Elevation of PrivilegeImportant7.0
CVE-2025-58730Inbox COM ObjectsInbox COM Objects (Global Memory) Remote Code ExecutionImportant7.0
CVE-2025-58731Inbox COM ObjectsInbox COM Objects (Global Memory) Remote Code ExecutionImportant7.0
CVE-2025-58732Inbox COM ObjectsInbox COM Objects (Global Memory) Remote Code ExecutionImportant7.0
CVE-2025-58733Inbox COM ObjectsInbox COM Objects (Global Memory) Remote Code ExecutionImportant7.0
CVE-2025-58734Inbox COM ObjectsInbox COM Objects (Global Memory) Remote Code ExecutionImportant7.0
CVE-2025-58735Inbox COM ObjectsInbox COM Objects (Global Memory) Remote Code ExecutionImportant7.0
CVE-2025-58736Inbox COM ObjectsInbox COM Objects (Global Memory) Remote Code ExecutionImportant7.0
CVE-2025-58737Windows Remote DesktopRemote Desktop Protocol Remote Code ExecutionImportant7.0
CVE-2025-58738Inbox COM ObjectsInbox COM Objects (Global Memory) Remote Code ExecutionImportant7.0
CVE-2025-59193Windows Management ServicesWindows Management Services Elevation of PrivilegeImportant7.0
CVE-2025-59194Windows KernelWindows Kernel Elevation of PrivilegeImportant7.0
CVE-2025-59195Microsoft Graphics ComponentWindows Graphics Component Denial of ServiceImportant7.0
CVE-2025-59196Windows SSDP ServiceWindows Simple Search and Discovery Protocol (SSDP) Service Elevation of PrivilegeImportant7.0
CVE-2025-59202Windows Remote Desktop ServicesWindows Remote Desktop Services Elevation of PrivilegeImportant7.0
CVE-2025-59205Microsoft Graphics ComponentWindows Graphics Component Elevation of PrivilegeImportant7.0
CVE-2025-59221Microsoft Office WordMicrosoft Word Remote Code ExecutionImportant7.0
CVE-2025-59261Microsoft Graphics ComponentWindows Graphics Component Elevation of PrivilegeImportant7.0
CVE-2025-59282Inbox COM ObjectsInternet Information Services (IIS) Inbox COM Objects (Global Memory) Remote Code ExecutionImportant7.0
CVE-2025-59285Azure Monitor AgentAzure Monitor Agent Elevation of PrivilegeImportant7.0
CVE-2025-59289Windows Bluetooth ServiceWindows Bluetooth Service Elevation of PrivilegeImportant7.0
CVE-2025-59497Microsoft Defender for LinuxMicrosoft Defender for Linux Denial of ServiceImportant7.0
CVE-2025-55320Microsoft Configuration ManagerConfiguration Manager Elevation of PrivilegeImportant6.8
CVE-2025-55700Windows Routing and Remote Access Service (RRAS)Windows Routing and Remote Access Service (RRAS) Information DisclosureImportant6.5
CVE-2025-58717Windows Routing and Remote Access Service (RRAS)Windows Routing and Remote Access Service (RRAS) Information DisclosureImportant6.5
CVE-2025-58729Windows Local Session Manager (LSM)Windows Local Session Manager (LSM) Denial of ServiceImportant6.5
CVE-2025-58739Windows File ExplorerMicrosoft Windows File Explorer SpoofingImportant6.5
CVE-2025-59185Windows Core ShellNTLM Hash Disclosure SpoofingImportant6.5
CVE-2025-59214Windows File ExplorerMicrosoft Windows File Explorer SpoofingImportant6.5
CVE-2025-59244Windows Core ShellNTLM Hash Disclosure SpoofingImportant6.5
CVE-2025-59257Windows Local Session Manager (LSM)Windows Local Session Manager (LSM) Denial of ServiceImportant6.5
CVE-2025-59259Windows Local Session Manager (LSM)Windows Local Session Manager (LSM) Denial of ServiceImportant6.5
CVE-2025-48813Virtual Secure ModeVirtual Secure Mode SpoofingImportant6.3
CVE-2025-55334Windows KernelWindows Kernel Security Feature BypassImportant6.2
CVE-2025-59258Active Directory Federation Services (AD FS)Windows Active Directory Federation Services (ADFS) Information DisclosureImportant6.2
CVE-2025-55330Windows BitLockerWindows BitLocker Security Feature BypassImportant6.1
CVE-2025-55332Windows BitLockerWindows BitLocker Security Feature BypassImportant6.1
CVE-2025-55333Windows BitLockerWindows BitLocker Security Feature BypassImportant6.1
CVE-2025-55337Windows BitLockerWindows BitLocker Security Feature BypassImportant6.1
CVE-2025-55338Windows BitLockerWindows BitLocker Security Feature BypassImportant6.1
CVE-2025-55682Windows BitLockerWindows BitLocker Security Feature BypassImportant6.1
CVE-2025-47979Windows Failover ClusterMicrosoft Failover Cluster Information DisclosureImportant5.5
CVE-2025-55325Windows Storage Management ProviderWindows Storage Management Provider Information DisclosureImportant5.5
CVE-2025-55336Windows Cloud Files Mini Filter DriverWindows Cloud Files Mini Filter Driver Information DisclosureImportant5.5
CVE-2025-55676Windows USB Video DriverWindows USB Video Class System Driver Information DisclosureImportant5.5
CVE-2025-55683Windows KernelWindows Kernel Information DisclosureImportant5.5
CVE-2025-55695Windows WLAN Auto Config ServiceWindows WLAN AutoConfig Service Information DisclosureImportant5.5
CVE-2025-55699Windows KernelWindows Kernel Information DisclosureImportant5.5
CVE-2025-59184Windows High Availability ServicesStorage Spaces Direct Information DisclosureImportant5.5
CVE-2025-59186Windows KernelWindows Kernel Information DisclosureImportant5.5
CVE-2025-59188Windows Failover ClusterMicrosoft Failover Cluster Information DisclosureImportant5.5
CVE-2025-59190Microsoft Windows Search ComponentWindows Search Service Denial of ServiceImportant5.5
CVE-2025-59197Windows ETL ChannelWindows ETL Channel Information DisclosureImportant5.5
CVE-2025-59203Windows StateRepository APIWindows State Repository API Server File Information DisclosureImportant5.5
CVE-2025-59204Windows Management ServicesWindows Management Services Information DisclosureImportant5.5
CVE-2025-59209Windows Push Notification CoreWindows Push Notification Information DisclosureImportant5.5
CVE-2025-59211Windows Push Notification CoreWindows Push Notification Information DisclosureImportant5.5
CVE-2025-59229Microsoft OfficeMicrosoft Office Denial of ServiceImportant5.5
CVE-2025-59253Microsoft Windows Search ComponentWindows Search Service Denial of ServiceImportant5.5
CVE-2025-59260Microsoft Failover Cluster Virtual DriverMicrosoft Failover Cluster Virtual Driver Information DisclosureImportant5.5
CVE-2025-55679Windows KernelWindows Kernel Information DisclosureImportant5.1
CVE-2025-59198Microsoft Windows Search ComponentWindows Search Service Denial of ServiceImportant5.0
CVE-2025-55248.NET, .NET Framework, Visual Studio.NET, .NET Framework, and Visual Studio Information DisclosureImportant4.8
CVE-2025-58719Connected Devices Platform Service (Cdpsvc)Windows Connected Devices Platform Service Elevation of PrivilegeImportant4.7
CVE-2025-59284Windows NTLMWindows NTLM SpoofingImportant3.3
CVE-2025-59280Windows SMB ClientWindows SMB Client TamperingImportant3.1
CVE-2025-59294Windows Taskbar LiveWindows Taskbar Live Preview Information DisclosureImportant2.1
CVE-2025-59502Windows Remote Procedure CallRemote Procedure Call Denial of ServiceModerate7.5
CVE-2025-59288Github: PlaywrightPlaywright SpoofingModerate5.3

Published later in the month (13)

Microsoft Edge updates, out-of-band fixes and cloud services. “Fixed by Microsoft” means a cloud service Microsoft has already patched: there is nothing to install.

DateCVEWhatSeverityAction
23 OctCVE-2025-59503Azure Compute Resource Provider Elevation of PrivilegeCriticalFixed by Microsoft
9 OctCVE-2025-59246Azure Entra ID Elevation of PrivilegeCriticalFixed by Microsoft
9 OctCVE-2025-59218Azure Entra ID Elevation of PrivilegeCriticalFixed by Microsoft
9 OctCVE-2025-55321Azure Monitor Log Analytics SpoofingCriticalFixed by Microsoft
9 OctCVE-2025-59252M365 Copilot Information DisclosureCriticalFixed by Microsoft
9 OctCVE-2025-59272Microsoft Copilot Information DisclosureCriticalFixed by Microsoft
9 OctCVE-2025-59286Microsoft Copilot Information DisclosureCriticalFixed by Microsoft
9 OctCVE-2025-59247Azure PlayFab Elevation of PrivilegeCriticalFixed by Microsoft
9 OctCVE-2025-59271Redis Enterprise Elevation of PrivilegeCriticalFixed by Microsoft
23 OctCVE-2025-59500Azure Notification Service Elevation of PrivilegeCriticalFixed by Microsoft
23 OctCVE-2025-59273Azure Event Grid System Elevation of PrivilegeCriticalFixed by Microsoft
31 OctCVE-2025-60711Microsoft Edge (Chromium-based) Remote Code ExecutionImportantUpdate
24 OctCVE-2025-59501Microsoft Configuration Manager SpoofingImportantUpdate

From Microsoft’s Security Update Guide and CISA’s Known Exploited Vulnerabilities catalog, checked 2 days ago. Only vulnerabilities Microsoft itself issued are counted; Chromium fixes that Edge inherits are left out. For known problems with the updates themselves, see Windows release health.

← All tools