How to use it Start with "Patch these first" for the fixes attackers are already using. Then filter the list by product or keyword, or tick "Critical only" to narrow it down.
Next Patch Tuesday: Tue 13 Oct 2026 (in 3 days)
November 2025 Patch Tuesday: Microsoft fixed 63 vulnerabilities, 5 of them Critical. 1 was already being exploited. Released Tue 11 Nov 2025.
- 63vulnerabilities fixed
- 5Critical
- 1exploited before the fix
- 0publicly disclosed
- 2now on CISA KEV
By type: 29 elevation of privilege, 16 remote code execution, 11 information disclosure, 3 denial of service, 2 spoofing, 2 security feature bypass.
Update problems? Ask in Patch Tuesday & Updates. From October 2026 a “what broke for you?” thread opens there at 1 pm Eastern every Patch Tuesday.
Patch these first
Being exploited, already public, or on CISA’s list of vulnerabilities attackers are using. Whatever else waits for testing, these should not.
| CVE | What | Severity | CVSS | Why first |
|---|---|---|---|---|
CVE-2025-60710 | Host Process for Windows Tasks Elevation of Privilege | Important | 7.8 | On CISA KEV federal deadline 27 Apr Ransomware |
CVE-2025-62215 | Windows Kernel Elevation of Privilege | Important | 7.0 | Exploited On CISA KEV federal deadline 3 Dec |
Critical (5)
Microsoft’s top rating: usually code execution with little or no user action.
| CVE | What | Impact | CVSS |
|---|---|---|---|
CVE-2025-60724 | GDI+ Remote Code Execution | Remote Code Execution | 9.8 |
CVE-2025-30398 | Nuance PowerScribe 360 Information Disclosure | Information Disclosure | 8.1 |
CVE-2025-62199 | Microsoft Office Remote Code Execution | Remote Code Execution | 7.8 |
CVE-2025-60716 | DirectX Graphics Kernel Elevation of Privilege | Elevation of Privilege | 7.0 |
CVE-2025-62214 | Visual Studio Remote Code Execution | Remote Code Execution | 6.7 |
Added to CISA KEV in November 2025 (11)
Every vendor, not only Microsoft. CISA adds a vulnerability when it has evidence attackers are using it. US federal agencies must fix it by the deadline shown; for everyone else, it is the best free “patch this now” list there is.
| CVE | Vendor and product | What | Added | Federal deadline | Ransomware |
|---|---|---|---|---|---|
CVE-2021-26829 | OpenPLC ScadaBR | Cross-site Scripting | 28 Nov | 19 Dec 2025 | |
CVE-2025-61757 | Oracle Fusion Middleware | Missing Authentication for Critical Function | 21 Nov | 12 Dec 2025 | |
CVE-2025-13223 | Google Chromium V8 | Type Confusion | 19 Nov | 10 Dec 2025 | |
CVE-2025-58034 | Fortinet FortiWeb | OS Command Injection | 18 Nov | 25 Nov 2025 | |
CVE-2025-64446 | Fortinet FortiWeb | Path Traversal | 14 Nov | 21 Nov 2025 | |
CVE-2025-12480 | Gladinet Triofox | Improper Access Control | 12 Nov | 3 Dec 2025 | |
CVE-2025-62215 | Microsoft Windows | Race Condition | 12 Nov | 3 Dec 2025 | |
CVE-2025-9242 | WatchGuard Firebox | Out-of-Bounds Write | 12 Nov | 3 Dec 2025 | |
CVE-2025-21042 | Samsung Mobile Devices | Out-of-Bounds Write | 10 Nov | 1 Dec 2025 | |
CVE-2025-11371 | Gladinet CentreStack and Triofox | Files or Directories Accessible to External Parties | 4 Nov | 25 Nov 2025 | |
CVE-2025-48703 | CWP Control Web Panel | OS Command Injection | 4 Nov | 25 Nov 2025 |
All 63 fixes
Show the full list, with a filter
| CVE | Product | What | Severity | CVSS |
|---|---|---|---|---|
CVE-2025-60724 | Microsoft Graphics Component | GDI+ Remote Code Execution | Critical | 9.8 |
CVE-2025-30398 | Nuance PowerScribe | Nuance PowerScribe 360 Information Disclosure | Critical | 8.1 |
CVE-2025-62199 | Microsoft Office | Microsoft Office Remote Code Execution | Critical | 7.8 |
CVE-2025-60716 | Windows DirectX | DirectX Graphics Kernel Elevation of Privilege | Critical | 7.0 |
CVE-2025-62214 | Visual Studio | Visual Studio Remote Code Execution | Critical | 6.7 |
CVE-2025-59499 | SQL Server | Microsoft SQL Server Elevation of Privilege | Important | 8.8 |
CVE-2025-62220 | Windows Subsystem for Linux GUI | Windows Subsystem for Linux GUI Remote Code Execution | Important | 8.8 |
CVE-2025-62222 | Visual Studio Code CoPilot Chat Extension | Agentic AI and Visual Studio Code Remote Code Execution | Important | 8.8 |
CVE-2025-62210 | Dynamics 365 Field Service (online) | Dynamics 365 Field Service (online) Spoofing | Important | 8.7 |
CVE-2025-62211 | Dynamics 365 Field Service (online) | Dynamics 365 Field Service (online) Spoofing | Important | 8.7 |
CVE-2025-60715 | Windows Routing and Remote Access Service (RRAS) | Windows Routing and Remote Access Service (RRAS) Remote Code Execution | Important | 8.0 |
CVE-2025-62204 | Microsoft Office SharePoint | Microsoft SharePoint Remote Code Execution | Important | 8.0 |
CVE-2025-62452 | Windows Routing and Remote Access Service (RRAS) | Windows Routing and Remote Access Service (RRAS) Remote Code Execution | Important | 8.0 |
CVE-2025-59505 | Windows Smart Card | Windows Smart Card Reader Elevation of Privilege | Important | 7.8 |
CVE-2025-59511 | Windows WLAN Service | Windows WLAN Service Elevation of Privilege | Important | 7.8 |
CVE-2025-59512 | Customer Experience Improvement Program (CEIP) | Customer Experience Improvement Program (CEIP) Elevation of Privilege | Important | 7.8 |
CVE-2025-59514 | Microsoft Streaming Service | Microsoft Streaming Service Proxy Elevation of Privilege | Important | 7.8 |
CVE-2025-60703 | Windows Remote Desktop | Windows Remote Desktop Services Elevation of Privilege | Important | 7.8 |
CVE-2025-60705 | Windows Client-Side Caching (CSC) Service | Windows Client-Side Caching Elevation of Privilege | Important | 7.8 |
CVE-2025-60707 | Multimedia Class Scheduler Service (MMCSS) | Multimedia Class Scheduler Service (MMCSS) Driver Elevation of Privilege | Important | 7.8 |
CVE-2025-60709 | Windows Common Log File System Driver | Windows Common Log File System Driver Elevation of Privilege | Important | 7.8 |
CVE-2025-60710 | Host Process for Windows Tasks | Host Process for Windows Tasks Elevation of Privilege | Important | 7.8 |
CVE-2025-60713 | Windows Routing and Remote Access Service (RRAS) | Windows Routing and Remote Access Service (RRAS) Elevation of Privilege | Important | 7.8 |
CVE-2025-60714 | Windows OLE | Windows OLE Remote Code Execution | Important | 7.8 |
CVE-2025-60718 | Windows Administrator Protection | Windows Administrator Protection Elevation of Privilege | Important | 7.8 |
CVE-2025-60720 | Windows TDX.sys | Windows Transport Driver Interface (TDI) Translation Driver Elevation of Privilege | Important | 7.8 |
CVE-2025-60721 | Windows Administrator Protection | Windows Administrator Protection Elevation of Privilege | Important | 7.8 |
CVE-2025-60727 | Microsoft Office Excel | Microsoft Excel Remote Code Execution | Important | 7.8 |
CVE-2025-62200 | Microsoft Office Excel | Microsoft Excel Remote Code Execution | Important | 7.8 |
CVE-2025-62201 | Microsoft Office Excel | Microsoft Excel Remote Code Execution | Important | 7.8 |
CVE-2025-62203 | Microsoft Office Excel | Microsoft Excel Remote Code Execution | Important | 7.8 |
CVE-2025-62205 | Microsoft Office Word | Microsoft Office Remote Code Execution | Important | 7.8 |
CVE-2025-62216 | Microsoft Office | Microsoft Office Remote Code Execution | Important | 7.8 |
CVE-2025-60704 | Windows Kerberos | Windows Kerberos Elevation of Privilege | Important | 7.5 |
CVE-2025-59504 | Azure Monitor Agent | Azure Monitor Agent Remote Code Execution | Important | 7.3 |
CVE-2025-60726 | Microsoft Office Excel | Microsoft Excel Information Disclosure | Important | 7.1 |
CVE-2025-62202 | Microsoft Office Excel | Microsoft Excel Information Disclosure | Important | 7.1 |
CVE-2025-59506 | Windows DirectX | DirectX Graphics Kernel Elevation of Privilege | Important | 7.0 |
CVE-2025-59507 | Windows Speech | Windows Speech Runtime Elevation of Privilege | Important | 7.0 |
CVE-2025-59508 | Windows Speech | Windows Speech Recognition Elevation of Privilege | Important | 7.0 |
CVE-2025-59515 | Windows Broadcast DVR User Service | Windows Broadcast DVR User Service Elevation of Privilege | Important | 7.0 |
CVE-2025-60717 | Windows Broadcast DVR User Service | Windows Broadcast DVR User Service Elevation of Privilege | Important | 7.0 |
CVE-2025-60719 | Windows Ancillary Function Driver for WinSock | Windows Ancillary Function Driver for WinSock Elevation of Privilege | Important | 7.0 |
CVE-2025-62213 | Windows Ancillary Function Driver for WinSock | Windows Ancillary Function Driver for WinSock Elevation of Privilege | Important | 7.0 |
CVE-2025-62215 | Windows Kernel | Windows Kernel Elevation of Privilege | Important | 7.0 |
CVE-2025-62217 | Windows Ancillary Function Driver for WinSock | Windows Ancillary Function Driver for WinSock Elevation of Privilege | Important | 7.0 |
CVE-2025-62218 | Microsoft Wireless Provisioning System | Microsoft Wireless Provisioning System Elevation of Privilege | Important | 7.0 |
CVE-2025-62219 | Microsoft Wireless Provisioning System | Microsoft Wireless Provisioning System Elevation of Privilege | Important | 7.0 |
CVE-2025-62449 | Visual Studio Code CoPilot Chat Extension | Microsoft Visual Studio Code CoPilot Chat Extension Security Feature Bypass | Important | 6.8 |
CVE-2025-47179 | Microsoft Configuration Manager | Configuration Manager Elevation of Privilege | Important | 6.7 |
CVE-2025-60708 | Storvsp.sys Driver | Storvsp.sys Driver Denial of Service | Important | 6.5 |
CVE-2025-60722 | OneDrive for Android | Microsoft OneDrive for Android Elevation of Privilege | Important | 6.5 |
CVE-2025-62206 | Microsoft Dynamics 365 (on-premises) | Microsoft Dynamics 365 (On-Premises) Information Disclosure | Important | 6.5 |
CVE-2025-60723 | Windows DirectX | DirectX Graphics Kernel Denial of Service | Important | 6.3 |
CVE-2025-59240 | Microsoft Office Excel | Microsoft Excel Information Disclosure | Important | 5.5 |
CVE-2025-59509 | Windows Speech | Windows Speech Recognition Information Disclosure | Important | 5.5 |
CVE-2025-59510 | Windows Routing and Remote Access Service (RRAS) | Windows Routing and Remote Access Service (RRAS) Denial of Service | Important | 5.5 |
CVE-2025-59513 | Windows Bluetooth RFCOM Protocol Driver | Windows Bluetooth RFCOM Protocol Driver Information Disclosure | Important | 5.5 |
CVE-2025-60706 | Role: Windows Hyper-V | Windows Hyper-V Information Disclosure | Important | 5.5 |
CVE-2025-62208 | Windows License Manager | Windows License Manager Information Disclosure | Important | 5.5 |
CVE-2025-62209 | Windows License Manager | Windows License Manager Information Disclosure | Important | 5.5 |
CVE-2025-62453 | GitHub Copilot and Visual Studio Code | GitHub Copilot and Visual Studio Code Security Feature Bypass | Important | 5.0 |
CVE-2025-60728 | Microsoft Office Excel | Microsoft Excel Information Disclosure | Important | 4.3 |
Published later in the month (8)
Microsoft Edge updates, out-of-band fixes and cloud services. “Fixed by Microsoft” means a cloud service Microsoft has already patched: there is nothing to install.
| Date | CVE | What | Severity | Action |
|---|---|---|---|---|
| 20 Nov | CVE-2025-49752 | Azure Bastion Elevation of Privilege | Critical | Fixed by Microsoft |
| 20 Nov | CVE-2025-59245 | Microsoft SharePoint Online Elevation of Privilege | Critical | Fixed by Microsoft |
| 20 Nov | CVE-2025-64657 | Azure Application Gateway Elevation of Privilege | Critical | Fixed by Microsoft |
| 20 Nov | CVE-2025-64656 | Azure Application Gateway Elevation of Privilege | Critical | Fixed by Microsoft |
| 20 Nov | CVE-2025-64655 | Dynamics OmniChannel SDK Storage Containers Elevation of Privilege | Critical | Fixed by Microsoft |
| 20 Nov | CVE-2025-62207 | Azure Monitor Elevation of Privilege | Critical | Fixed by Microsoft |
| 20 Nov | CVE-2025-62459 | Microsoft Defender Portal Spoofing | Critical | Fixed by Microsoft |
| 20 Nov | CVE-2025-64660 | GitHub Copilot and Visual Studio Code Remote Code Execution | Important | Update |
From Microsoft’s Security Update Guide and CISA’s Known Exploited Vulnerabilities catalog, checked 1 day ago. Only vulnerabilities Microsoft itself issued are counted; Chromium fixes that Edge inherits are left out. For known problems with the updates themselves, see Windows release health.