How to use it Start with "Patch these first" for the fixes attackers are already using. Then filter the list by product or keyword, or tick "Critical only" to narrow it down.
Next Patch Tuesday: Tue 13 Oct 2026 (in 3 days)
October 2025 Patch Tuesday: Microsoft fixed 167 vulnerabilities, 7 of them Critical. 2 were already being exploited. Released Tue 14 Oct 2025.
- 167vulnerabilities fixed
- 7Critical
- 2exploited before the fix
- 1publicly disclosed
- 3now on CISA KEV
By type: 80 elevation of privilege, 29 remote code execution, 26 information disclosure, 11 denial of service, 10 security feature bypass, 10 spoofing, 1 tampering.
Update problems? Ask in Patch Tuesday & Updates. From October 2026 a “what broke for you?” thread opens there at 1 pm Eastern every Patch Tuesday.
Patch these first
Being exploited, already public, or on CISA’s list of vulnerabilities attackers are using. Whatever else waits for testing, these should not.
| CVE | What | Severity | CVSS | Why first |
|---|---|---|---|---|
CVE-2025-59287 | Windows Server Update Service (WSUS) Remote Code Execution | Critical | 9.8 | On CISA KEV federal deadline 14 Nov |
CVE-2025-24052 | Windows Agere Modem Driver Elevation of Privilege | Important | 7.8 | Publicly disclosed |
CVE-2025-24990 | Windows Agere Modem Driver Elevation of Privilege | Important | 7.8 | Exploited On CISA KEV federal deadline 4 Nov |
CVE-2025-59230 | Windows Remote Access Connection Manager Elevation of Privilege | Important | 7.8 | Exploited On CISA KEV federal deadline 4 Nov |
Critical (7)
Microsoft’s top rating: usually code execution with little or no user action.
| CVE | What | Impact | CVSS |
|---|---|---|---|
CVE-2025-49708 | Microsoft Graphics Component Elevation of Privilege | Elevation of Privilege | 9.9 |
CVE-2025-59287 | Windows Server Update Service (WSUS) Remote Code Execution | Remote Code Execution | 9.8 |
CVE-2025-59236 | Microsoft Excel Remote Code Execution | Remote Code Execution | 8.4 |
CVE-2025-59291 | Confidential Azure Container Instances Elevation of Privilege | Elevation of Privilege | 8.2 |
CVE-2025-59292 | Azure Compute Gallery Elevation of Privilege | Elevation of Privilege | 8.2 |
CVE-2025-59227 | Microsoft Office Remote Code Execution | Remote Code Execution | 7.8 |
CVE-2025-59234 | Microsoft Office Remote Code Execution | Remote Code Execution | 7.8 |
Added to CISA KEV in October 2025 (31)
Every vendor, not only Microsoft. CISA adds a vulnerability when it has evidence attackers are using it. US federal agencies must fix it by the deadline shown; for everyone else, it is the best free “patch this now” list there is.
| CVE | Vendor and product | What | Added | Federal deadline | Ransomware |
|---|---|---|---|---|---|
CVE-2025-24893 | XWiki Platform | Eval Injection | 30 Oct | 20 Nov 2025 | |
CVE-2025-41244 | Broadcom VMware Aria Operations and VMware Tools | Privilege Defined with Unsafe Actions | 30 Oct | 20 Nov 2025 | |
CVE-2025-6204 | Dassault Systèmes DELMIA Apriso | Code Injection | 28 Oct | 18 Nov 2025 | |
CVE-2025-6205 | Dassault Systèmes DELMIA Apriso | Missing Authorization | 28 Oct | 18 Nov 2025 | |
CVE-2025-54236 | Adobe Commerce and Magento | Improper Input Validation | 24 Oct | 14 Nov 2025 | |
CVE-2025-59287 | Microsoft Windows | Server Update Service (WSUS) Deserialization of Untrusted Data | 24 Oct | 14 Nov 2025 | |
CVE-2025-61932 | Motex LANSCOPE Endpoint Manager | Improper Verification of Source of a Communication Channel | 22 Oct | 12 Nov 2025 | |
CVE-2022-48503 | Apple Multiple Products | Unspecified | 20 Oct | 10 Nov 2025 | |
CVE-2025-2746 | Kentico Xperience CMS | Authentication Bypass Using an Alternate Path or Channel | 20 Oct | 10 Nov 2025 | |
CVE-2025-2747 | Kentico Xperience CMS | Authentication Bypass Using an Alternate Path or Channel | 20 Oct | 10 Nov 2025 | |
CVE-2025-33073 | Microsoft Windows | SMB Client Improper Access Control | 20 Oct | 10 Nov 2025 | |
CVE-2025-61884 | Oracle E-Business Suite | Server-Side Request Forgery (SSRF) | 20 Oct | 10 Nov 2025 | Known |
CVE-2025-54253 | Adobe Experience Manager (AEM) Forms | Adobe Experience Manager Forms Code Execution | 15 Oct | 5 Nov 2025 | |
CVE-2016-7836 | SKYSEA Client View | Improper Authentication | 14 Oct | 4 Nov 2025 | |
CVE-2025-24990 | Microsoft Windows | Untrusted Pointer Dereference | 14 Oct | 4 Nov 2025 | |
CVE-2025-47827 | IGEL IGEL OS | IGEL OS Use of a Key Past its Expiration Date | 14 Oct | 4 Nov 2025 | |
CVE-2025-59230 | Microsoft Windows | Improper Access Control | 14 Oct | 4 Nov 2025 | |
CVE-2021-43798 | Grafana Labs Grafana | Grafana Path Traversal | 9 Oct | 30 Oct 2025 | |
CVE-2025-27915 | Synacor Zimbra Collaboration Suite (ZCS) | Cross-site Scripting | 7 Oct | 28 Oct 2025 | |
CVE-2010-3765 | Mozilla Multiple Products | Remote Code Execution | 6 Oct | 27 Oct 2025 | |
CVE-2010-3962 | Microsoft Internet Explorer | Uninitialized Memory Corruption | 6 Oct | 27 Oct 2025 | |
CVE-2011-3402 | Microsoft Windows | Remote Code Execution | 6 Oct | 27 Oct 2025 | |
CVE-2013-3918 | Microsoft Windows | Out-of-Bounds Write | 6 Oct | 27 Oct 2025 | |
CVE-2021-22555 | Linux Kernel | Heap Out-of-Bounds Write | 6 Oct | 27 Oct 2025 | |
CVE-2021-43226 | Microsoft Windows | Privilege Escalation | 6 Oct | 27 Oct 2025 | Known |
CVE-2025-61882 | Oracle E-Business Suite | Unspecified | 6 Oct | 27 Oct 2025 | Known |
CVE-2014-6278 | GNU GNU Bash | GNU Bash OS Command Injection | 2 Oct | 23 Oct 2025 | |
CVE-2015-7755 | Juniper ScreenOS | Improper Authentication | 2 Oct | 23 Oct 2025 | |
CVE-2017-1000353 | Jenkins Jenkins | Jenkins Remote Code Execution | 2 Oct | 23 Oct 2025 | |
CVE-2025-21043 | Samsung Mobile Devices | Out-of-Bounds Write | 2 Oct | 23 Oct 2025 | |
CVE-2025-4008 | Smartbedded Meteobridge | Command Injection | 2 Oct | 23 Oct 2025 |
All 167 fixes
Show the full list, with a filter
| CVE | Product | What | Severity | CVSS |
|---|---|---|---|---|
CVE-2025-49708 | Microsoft Graphics Component | Microsoft Graphics Component Elevation of Privilege | Critical | 9.9 |
CVE-2025-59287 | Windows Server Update Service | Windows Server Update Service (WSUS) Remote Code Execution | Critical | 9.8 |
CVE-2025-59236 | Microsoft Office Excel | Microsoft Excel Remote Code Execution | Critical | 8.4 |
CVE-2025-59291 | Confidential Azure Container Instances | Confidential Azure Container Instances Elevation of Privilege | Critical | 8.2 |
CVE-2025-59292 | Confidential Azure Container Instances | Azure Compute Gallery Elevation of Privilege | Critical | 8.2 |
CVE-2025-59227 | Microsoft Office | Microsoft Office Remote Code Execution | Critical | 7.8 |
CVE-2025-59234 | Microsoft Office | Microsoft Office Remote Code Execution | Critical | 7.8 |
CVE-2025-55315 | ASP.NET Core | ASP.NET Security Feature Bypass | Important | 9.9 |
CVE-2025-58715 | Microsoft Windows Speech | Windows Speech Runtime Elevation of Privilege | Important | 8.8 |
CVE-2025-58716 | Microsoft Windows Speech | Windows Speech Runtime Elevation of Privilege | Important | 8.8 |
CVE-2025-58718 | Remote Desktop Client | Remote Desktop Client Remote Code Execution | Important | 8.8 |
CVE-2025-59213 | Microsoft Configuration Manager | Configuration Manager Elevation of Privilege | Important | 8.8 |
CVE-2025-59228 | Microsoft Office SharePoint | Microsoft SharePoint Remote Code Execution | Important | 8.8 |
CVE-2025-59237 | Microsoft Office SharePoint | Microsoft SharePoint Remote Code Execution | Important | 8.8 |
CVE-2025-59249 | Microsoft Exchange Server | Microsoft Exchange Server Elevation of Privilege | Important | 8.8 |
CVE-2025-59295 | Internet Explorer | Windows URL Parsing Remote Code Execution | Important | 8.8 |
CVE-2025-53782 | Microsoft Exchange Server | Microsoft Exchange Server Elevation of Privilege | Important | 8.4 |
CVE-2025-59250 | JDBC Driver for SQL Server | JDBC Driver for SQL Server Spoofing | Important | 8.1 |
CVE-2025-24052 | Agere Windows Modem Driver | Windows Agere Modem Driver Elevation of Privilege | Important | 7.8 |
CVE-2025-24990 | Agere Windows Modem Driver | Windows Agere Modem Driver Elevation of Privilege | Important | 7.8 |
CVE-2025-50152 | Windows Kernel | Windows Kernel Elevation of Privilege | Important | 7.8 |
CVE-2025-50175 | Windows Digital Media | Windows Digital Media Elevation of Privilege | Important | 7.8 |
CVE-2025-53150 | Windows Digital Media | Windows Digital Media Elevation of Privilege | Important | 7.8 |
CVE-2025-53768 | Xbox | Xbox IStorageService Elevation of Privilege | Important | 7.8 |
CVE-2025-55328 | Windows Hyper-V | Windows Hyper-V Elevation of Privilege | Important | 7.8 |
CVE-2025-55339 | Windows NDIS | Windows Network Driver Interface Specification (NDIS) Driver Elevation of Privilege | Important | 7.8 |
CVE-2025-55677 | Windows Device Association Broker service | Windows Device Association Broker Service Elevation of Privilege | Important | 7.8 |
CVE-2025-55680 | Windows Cloud Files Mini Filter Driver | Windows Cloud Files Mini Filter Driver Elevation of Privilege | Important | 7.8 |
CVE-2025-55692 | Windows Error Reporting | Windows Error Reporting Service Elevation of Privilege | Important | 7.8 |
CVE-2025-55694 | Windows Error Reporting | Windows Error Reporting Service Elevation of Privilege | Important | 7.8 |
CVE-2025-55696 | NtQueryInformation Token function (ntifs.h) | NtQueryInformation Token function (ntifs.h) Elevation of Privilege | Important | 7.8 |
CVE-2025-55697 | Azure Local | Azure Local Elevation of Privilege | Important | 7.8 |
CVE-2025-55701 | Microsoft Windows | Windows Authentication Elevation of Privilege | Important | 7.8 |
CVE-2025-58714 | Windows Ancillary Function Driver for WinSock | Windows Ancillary Function Driver for WinSock Elevation of Privilege | Important | 7.8 |
CVE-2025-58720 | Windows Cryptographic Services | Windows Cryptographic Services Information Disclosure | Important | 7.8 |
CVE-2025-58722 | Windows DWM | Microsoft DWM Core Library Elevation of Privilege | Important | 7.8 |
CVE-2025-58724 | Azure Connected Machine Agent | Arc Enabled Servers – Azure Connected Machine Agent Elevation of Privilege | Important | 7.8 |
CVE-2025-58728 | Windows Bluetooth Service | Windows Bluetooth Service Elevation of Privilege | Important | 7.8 |
CVE-2025-59187 | Windows Kernel | Windows Kernel Elevation of Privilege | Important | 7.8 |
CVE-2025-59191 | Connected Devices Platform Service (Cdpsvc) | Windows Connected Devices Platform Service Elevation of Privilege | Important | 7.8 |
CVE-2025-59192 | Storport.sys Driver | Storport.sys Driver Elevation of Privilege | Important | 7.8 |
CVE-2025-59199 | Software Protection Platform (SPP) | Software Protection Platform (SPP) Elevation of Privilege | Important | 7.8 |
CVE-2025-59201 | Network Connection Status Indicator (NCSI) | Network Connection Status Indicator (NCSI) Elevation of Privilege | Important | 7.8 |
CVE-2025-59207 | Windows Kernel | Windows Kernel Elevation of Privilege | Important | 7.8 |
CVE-2025-59222 | Microsoft Office Word | Microsoft Word Remote Code Execution | Important | 7.8 |
CVE-2025-59223 | Microsoft Office Excel | Microsoft Excel Remote Code Execution | Important | 7.8 |
CVE-2025-59224 | Microsoft Office Excel | Microsoft Excel Remote Code Execution | Important | 7.8 |
CVE-2025-59225 | Microsoft Office Excel | Microsoft Excel Remote Code Execution | Important | 7.8 |
CVE-2025-59226 | Microsoft Office Visio | Microsoft Office Visio Remote Code Execution | Important | 7.8 |
CVE-2025-59230 | Windows Remote Access Connection Manager | Windows Remote Access Connection Manager Elevation of Privilege | Important | 7.8 |
CVE-2025-59231 | Microsoft Office Excel | Microsoft Excel Remote Code Execution | Important | 7.8 |
CVE-2025-59233 | Microsoft Office Excel | Microsoft Excel Remote Code Execution | Important | 7.8 |
CVE-2025-59238 | Microsoft Office PowerPoint | Microsoft PowerPoint Remote Code Execution | Important | 7.8 |
CVE-2025-59241 | Windows Health and Optimized Experiences Service | Windows Health and Optimized Experiences Elevation of Privilege | Important | 7.8 |
CVE-2025-59242 | Windows Ancillary Function Driver for WinSock | Windows Ancillary Function Driver for WinSock Elevation of Privilege | Important | 7.8 |
CVE-2025-59243 | Microsoft Office Excel | Microsoft Excel Remote Code Execution | Important | 7.8 |
CVE-2025-59254 | Windows DWM Core Library | Microsoft DWM Core Library Elevation of Privilege | Important | 7.8 |
CVE-2025-59255 | Windows DWM Core Library | Windows DWM Core Library Elevation of Privilege | Important | 7.8 |
CVE-2025-59275 | Windows Authentication Methods | Windows Authentication Elevation of Privilege | Important | 7.8 |
CVE-2025-59277 | Windows Authentication Methods | Windows Authentication Elevation of Privilege | Important | 7.8 |
CVE-2025-59278 | Windows Authentication Methods | Windows Authentication Elevation of Privilege | Important | 7.8 |
CVE-2025-59281 | XBox Gaming Services | Xbox Gaming Services Elevation of Privilege | Important | 7.8 |
CVE-2025-59290 | Windows Bluetooth Service | Windows Bluetooth Service Elevation of Privilege | Important | 7.8 |
CVE-2025-59494 | Azure Monitor Agent | Azure Monitor Agent Elevation of Privilege | Important | 7.8 |
CVE-2025-53139 | Windows Hello | Windows Hello Security Feature Bypass | Important | 7.7 |
CVE-2025-55698 | Windows DirectX | DirectX Graphics Kernel Denial of Service | Important | 7.7 |
CVE-2025-59200 | Data Sharing Service Client | Data Sharing Service Spoofing | Important | 7.7 |
CVE-2025-55326 | Connected Devices Platform Service (Cdpsvc) | Windows Connected Devices Platform Service (Cdpsvc) Remote Code Execution | Important | 7.5 |
CVE-2025-58726 | Windows SMB Server | Windows SMB Server Elevation of Privilege | Important | 7.5 |
CVE-2025-59248 | Microsoft Exchange Server | Microsoft Exchange Server Spoofing | Important | 7.5 |
CVE-2025-48004 | Windows Brokering File System | Microsoft Brokering File System Elevation of Privilege | Important | 7.4 |
CVE-2025-55335 | Windows NTFS | Windows NTFS Elevation of Privilege | Important | 7.4 |
CVE-2025-55687 | Windows Resilient File System (ReFS) | Windows Resilient File System (ReFS) Elevation of Privilege | Important | 7.4 |
CVE-2025-55693 | Windows Kernel | Windows Kernel Elevation of Privilege | Important | 7.4 |
CVE-2025-59189 | Windows Brokering File System | Microsoft Brokering File System Elevation of Privilege | Important | 7.4 |
CVE-2025-59206 | Windows Resilient File System (ReFS) Deduplication Service | Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege | Important | 7.4 |
CVE-2025-59210 | Windows Resilient File System (ReFS) Deduplication Service | Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege | Important | 7.4 |
CVE-2025-25004 | Microsoft PowerShell | PowerShell Elevation of Privilege | Important | 7.3 |
CVE-2025-55240 | Visual Studio | Visual Studio Elevation of Privilege | Important | 7.3 |
CVE-2025-55247 | .NET | .NET Elevation of Privilege | Important | 7.3 |
CVE-2025-59208 | Windows MapUrlToZone | Windows MapUrlToZone Information Disclosure | Important | 7.1 |
CVE-2025-59232 | Microsoft Office Excel | Microsoft Excel Information Disclosure | Important | 7.1 |
CVE-2025-59235 | Microsoft Office Excel | Microsoft Excel Information Disclosure | Important | 7.1 |
CVE-2025-47989 | Azure Connected Machine Agent | Arc Enabled Servers – Azure Connected Machine Agent Elevation of Privilege | Important | 7.0 |
CVE-2025-50174 | Windows Device Association Broker service | Windows Device Association Broker Service Elevation of Privilege | Important | 7.0 |
CVE-2025-53717 | Windows Virtualization-Based Security (VBS) Enclave | Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege | Important | 7.0 |
CVE-2025-55331 | Windows PrintWorkflowUserSvc | Windows PrintWorkflowUserSvc Elevation of Privilege | Important | 7.0 |
CVE-2025-55340 | Windows Remote Desktop Protocol | Windows Remote Desktop Protocol Security Feature Bypass | Important | 7.0 |
CVE-2025-55678 | Windows DirectX | DirectX Graphics Kernel Elevation of Privilege | Important | 7.0 |
CVE-2025-55681 | Windows DWM | Desktop Window Manager Elevation of Privilege | Important | 7.0 |
CVE-2025-55684 | Windows PrintWorkflowUserSvc | Windows PrintWorkflowUserSvc Elevation of Privilege | Important | 7.0 |
CVE-2025-55685 | Windows PrintWorkflowUserSvc | Windows PrintWorkflowUserSvc Elevation of Privilege | Important | 7.0 |
CVE-2025-55686 | Windows PrintWorkflowUserSvc | Windows PrintWorkflowUserSvc Elevation of Privilege | Important | 7.0 |
CVE-2025-55688 | Windows PrintWorkflowUserSvc | Windows PrintWorkflowUserSvc Elevation of Privilege | Important | 7.0 |
CVE-2025-55689 | Windows PrintWorkflowUserSvc | Windows PrintWorkflowUserSvc Elevation of Privilege | Important | 7.0 |
CVE-2025-55690 | Windows PrintWorkflowUserSvc | Windows PrintWorkflowUserSvc Elevation of Privilege | Important | 7.0 |
CVE-2025-55691 | Windows PrintWorkflowUserSvc | Windows PrintWorkflowUserSvc Elevation of Privilege | Important | 7.0 |
CVE-2025-58725 | Windows COM | Windows COM+ Event System Service Elevation of Privilege | Important | 7.0 |
CVE-2025-58727 | Windows Connected Devices Platform Service | Windows Connected Devices Platform Service Elevation of Privilege | Important | 7.0 |
CVE-2025-58730 | Inbox COM Objects | Inbox COM Objects (Global Memory) Remote Code Execution | Important | 7.0 |
CVE-2025-58731 | Inbox COM Objects | Inbox COM Objects (Global Memory) Remote Code Execution | Important | 7.0 |
CVE-2025-58732 | Inbox COM Objects | Inbox COM Objects (Global Memory) Remote Code Execution | Important | 7.0 |
CVE-2025-58733 | Inbox COM Objects | Inbox COM Objects (Global Memory) Remote Code Execution | Important | 7.0 |
CVE-2025-58734 | Inbox COM Objects | Inbox COM Objects (Global Memory) Remote Code Execution | Important | 7.0 |
CVE-2025-58735 | Inbox COM Objects | Inbox COM Objects (Global Memory) Remote Code Execution | Important | 7.0 |
CVE-2025-58736 | Inbox COM Objects | Inbox COM Objects (Global Memory) Remote Code Execution | Important | 7.0 |
CVE-2025-58737 | Windows Remote Desktop | Remote Desktop Protocol Remote Code Execution | Important | 7.0 |
CVE-2025-58738 | Inbox COM Objects | Inbox COM Objects (Global Memory) Remote Code Execution | Important | 7.0 |
CVE-2025-59193 | Windows Management Services | Windows Management Services Elevation of Privilege | Important | 7.0 |
CVE-2025-59194 | Windows Kernel | Windows Kernel Elevation of Privilege | Important | 7.0 |
CVE-2025-59195 | Microsoft Graphics Component | Windows Graphics Component Denial of Service | Important | 7.0 |
CVE-2025-59196 | Windows SSDP Service | Windows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege | Important | 7.0 |
CVE-2025-59202 | Windows Remote Desktop Services | Windows Remote Desktop Services Elevation of Privilege | Important | 7.0 |
CVE-2025-59205 | Microsoft Graphics Component | Windows Graphics Component Elevation of Privilege | Important | 7.0 |
CVE-2025-59221 | Microsoft Office Word | Microsoft Word Remote Code Execution | Important | 7.0 |
CVE-2025-59261 | Microsoft Graphics Component | Windows Graphics Component Elevation of Privilege | Important | 7.0 |
CVE-2025-59282 | Inbox COM Objects | Internet Information Services (IIS) Inbox COM Objects (Global Memory) Remote Code Execution | Important | 7.0 |
CVE-2025-59285 | Azure Monitor Agent | Azure Monitor Agent Elevation of Privilege | Important | 7.0 |
CVE-2025-59289 | Windows Bluetooth Service | Windows Bluetooth Service Elevation of Privilege | Important | 7.0 |
CVE-2025-59497 | Microsoft Defender for Linux | Microsoft Defender for Linux Denial of Service | Important | 7.0 |
CVE-2025-55320 | Microsoft Configuration Manager | Configuration Manager Elevation of Privilege | Important | 6.8 |
CVE-2025-55700 | Windows Routing and Remote Access Service (RRAS) | Windows Routing and Remote Access Service (RRAS) Information Disclosure | Important | 6.5 |
CVE-2025-58717 | Windows Routing and Remote Access Service (RRAS) | Windows Routing and Remote Access Service (RRAS) Information Disclosure | Important | 6.5 |
CVE-2025-58729 | Windows Local Session Manager (LSM) | Windows Local Session Manager (LSM) Denial of Service | Important | 6.5 |
CVE-2025-58739 | Windows File Explorer | Microsoft Windows File Explorer Spoofing | Important | 6.5 |
CVE-2025-59185 | Windows Core Shell | NTLM Hash Disclosure Spoofing | Important | 6.5 |
CVE-2025-59214 | Windows File Explorer | Microsoft Windows File Explorer Spoofing | Important | 6.5 |
CVE-2025-59244 | Windows Core Shell | NTLM Hash Disclosure Spoofing | Important | 6.5 |
CVE-2025-59257 | Windows Local Session Manager (LSM) | Windows Local Session Manager (LSM) Denial of Service | Important | 6.5 |
CVE-2025-59259 | Windows Local Session Manager (LSM) | Windows Local Session Manager (LSM) Denial of Service | Important | 6.5 |
CVE-2025-48813 | Virtual Secure Mode | Virtual Secure Mode Spoofing | Important | 6.3 |
CVE-2025-55334 | Windows Kernel | Windows Kernel Security Feature Bypass | Important | 6.2 |
CVE-2025-59258 | Active Directory Federation Services (AD FS) | Windows Active Directory Federation Services (ADFS) Information Disclosure | Important | 6.2 |
CVE-2025-55330 | Windows BitLocker | Windows BitLocker Security Feature Bypass | Important | 6.1 |
CVE-2025-55332 | Windows BitLocker | Windows BitLocker Security Feature Bypass | Important | 6.1 |
CVE-2025-55333 | Windows BitLocker | Windows BitLocker Security Feature Bypass | Important | 6.1 |
CVE-2025-55337 | Windows BitLocker | Windows BitLocker Security Feature Bypass | Important | 6.1 |
CVE-2025-55338 | Windows BitLocker | Windows BitLocker Security Feature Bypass | Important | 6.1 |
CVE-2025-55682 | Windows BitLocker | Windows BitLocker Security Feature Bypass | Important | 6.1 |
CVE-2025-47979 | Windows Failover Cluster | Microsoft Failover Cluster Information Disclosure | Important | 5.5 |
CVE-2025-55325 | Windows Storage Management Provider | Windows Storage Management Provider Information Disclosure | Important | 5.5 |
CVE-2025-55336 | Windows Cloud Files Mini Filter Driver | Windows Cloud Files Mini Filter Driver Information Disclosure | Important | 5.5 |
CVE-2025-55676 | Windows USB Video Driver | Windows USB Video Class System Driver Information Disclosure | Important | 5.5 |
CVE-2025-55683 | Windows Kernel | Windows Kernel Information Disclosure | Important | 5.5 |
CVE-2025-55695 | Windows WLAN Auto Config Service | Windows WLAN AutoConfig Service Information Disclosure | Important | 5.5 |
CVE-2025-55699 | Windows Kernel | Windows Kernel Information Disclosure | Important | 5.5 |
CVE-2025-59184 | Windows High Availability Services | Storage Spaces Direct Information Disclosure | Important | 5.5 |
CVE-2025-59186 | Windows Kernel | Windows Kernel Information Disclosure | Important | 5.5 |
CVE-2025-59188 | Windows Failover Cluster | Microsoft Failover Cluster Information Disclosure | Important | 5.5 |
CVE-2025-59190 | Microsoft Windows Search Component | Windows Search Service Denial of Service | Important | 5.5 |
CVE-2025-59197 | Windows ETL Channel | Windows ETL Channel Information Disclosure | Important | 5.5 |
CVE-2025-59203 | Windows StateRepository API | Windows State Repository API Server File Information Disclosure | Important | 5.5 |
CVE-2025-59204 | Windows Management Services | Windows Management Services Information Disclosure | Important | 5.5 |
CVE-2025-59209 | Windows Push Notification Core | Windows Push Notification Information Disclosure | Important | 5.5 |
CVE-2025-59211 | Windows Push Notification Core | Windows Push Notification Information Disclosure | Important | 5.5 |
CVE-2025-59229 | Microsoft Office | Microsoft Office Denial of Service | Important | 5.5 |
CVE-2025-59253 | Microsoft Windows Search Component | Windows Search Service Denial of Service | Important | 5.5 |
CVE-2025-59260 | Microsoft Failover Cluster Virtual Driver | Microsoft Failover Cluster Virtual Driver Information Disclosure | Important | 5.5 |
CVE-2025-55679 | Windows Kernel | Windows Kernel Information Disclosure | Important | 5.1 |
CVE-2025-59198 | Microsoft Windows Search Component | Windows Search Service Denial of Service | Important | 5.0 |
CVE-2025-55248 | .NET, .NET Framework, Visual Studio | .NET, .NET Framework, and Visual Studio Information Disclosure | Important | 4.8 |
CVE-2025-58719 | Connected Devices Platform Service (Cdpsvc) | Windows Connected Devices Platform Service Elevation of Privilege | Important | 4.7 |
CVE-2025-59284 | Windows NTLM | Windows NTLM Spoofing | Important | 3.3 |
CVE-2025-59280 | Windows SMB Client | Windows SMB Client Tampering | Important | 3.1 |
CVE-2025-59294 | Windows Taskbar Live | Windows Taskbar Live Preview Information Disclosure | Important | 2.1 |
CVE-2025-59502 | Windows Remote Procedure Call | Remote Procedure Call Denial of Service | Moderate | 7.5 |
CVE-2025-59288 | Github: Playwright | Playwright Spoofing | Moderate | 5.3 |
Published later in the month (13)
Microsoft Edge updates, out-of-band fixes and cloud services. “Fixed by Microsoft” means a cloud service Microsoft has already patched: there is nothing to install.
| Date | CVE | What | Severity | Action |
|---|---|---|---|---|
| 23 Oct | CVE-2025-59503 | Azure Compute Resource Provider Elevation of Privilege | Critical | Fixed by Microsoft |
| 9 Oct | CVE-2025-59246 | Azure Entra ID Elevation of Privilege | Critical | Fixed by Microsoft |
| 9 Oct | CVE-2025-59218 | Azure Entra ID Elevation of Privilege | Critical | Fixed by Microsoft |
| 9 Oct | CVE-2025-55321 | Azure Monitor Log Analytics Spoofing | Critical | Fixed by Microsoft |
| 9 Oct | CVE-2025-59252 | M365 Copilot Information Disclosure | Critical | Fixed by Microsoft |
| 9 Oct | CVE-2025-59272 | Microsoft Copilot Information Disclosure | Critical | Fixed by Microsoft |
| 9 Oct | CVE-2025-59286 | Microsoft Copilot Information Disclosure | Critical | Fixed by Microsoft |
| 9 Oct | CVE-2025-59247 | Azure PlayFab Elevation of Privilege | Critical | Fixed by Microsoft |
| 9 Oct | CVE-2025-59271 | Redis Enterprise Elevation of Privilege | Critical | Fixed by Microsoft |
| 23 Oct | CVE-2025-59500 | Azure Notification Service Elevation of Privilege | Critical | Fixed by Microsoft |
| 23 Oct | CVE-2025-59273 | Azure Event Grid System Elevation of Privilege | Critical | Fixed by Microsoft |
| 31 Oct | CVE-2025-60711 | Microsoft Edge (Chromium-based) Remote Code Execution | Important | Update |
| 24 Oct | CVE-2025-59501 | Microsoft Configuration Manager Spoofing | Important | Update |
From Microsoft’s Security Update Guide and CISA’s Known Exploited Vulnerabilities catalog, checked 2 days ago. Only vulnerabilities Microsoft itself issued are counted; Chromium fixes that Edge inherits are left out. For known problems with the updates themselves, see Windows release health.