Claude is having a major outage. Status board · Discuss Claude

Patch Tuesday: December 2025

Each month's Microsoft security updates: what to patch first, the Critical fixes, and what CISA says attackers are exploiting.

How to use it Start with "Patch these first" for the fixes attackers are already using. Then filter the list by product or keyword, or tick "Critical only" to narrow it down.

Next Patch Tuesday: Tue 13 Oct 2026 (in 3 days)

December 2025 Patch Tuesday: Microsoft fixed 57 vulnerabilities, 2 of them Critical. 1 was already being exploited. Released Tue 9 Dec 2025.

  • 57vulnerabilities fixed
  • 2Critical
  • 1exploited before the fix
  • 2publicly disclosed
  • 1now on CISA KEV

By type: 29 elevation of privilege, 19 remote code execution, 4 information disclosure, 3 denial of service, 2 spoofing.

Update problems? Ask in Patch Tuesday & Updates. From October 2026 a “what broke for you?” thread opens there at 1 pm Eastern every Patch Tuesday.

Patch these first

Being exploited, already public, or on CISA’s list of vulnerabilities attackers are using. Whatever else waits for testing, these should not.

CVEWhatSeverityCVSSWhy first
CVE-2025-64671GitHub Copilot for Jetbrains Remote Code ExecutionImportant8.4Publicly disclosed
CVE-2025-54100PowerShell Remote Code ExecutionImportant7.8Publicly disclosed
CVE-2025-62221Windows Cloud Files Mini Filter Driver Elevation of PrivilegeImportant7.8Exploited On CISA KEV federal deadline 30 Dec

Critical (2)

Microsoft’s top rating: usually code execution with little or no user action.

CVEWhatImpactCVSS
CVE-2025-62554Microsoft Office Remote Code ExecutionRemote Code Execution8.4
CVE-2025-62557Microsoft Office Remote Code ExecutionRemote Code Execution8.4

Added to CISA KEV in December 2025 (20)

Every vendor, not only Microsoft. CISA adds a vulnerability when it has evidence attackers are using it. US federal agencies must fix it by the deadline shown; for everyone else, it is the best free “patch this now” list there is.

CVEVendor and productWhatAddedFederal deadlineRansomware
CVE-2025-14847MongoDB MongoDB and MongoDB ServerMongoDB and MongoDB Server Improper Handling of Length Parameter Inconsistency29 Dec19 Jan 2026
CVE-2023-52163Digiever DS-2105 ProMissing Authorization22 Dec12 Jan 2026
CVE-2025-14733WatchGuard FireboxOut of Bounds Write19 Dec26 Dec 2025Known
CVE-2025-20393Cisco Multiple ProductsImproper Input Validation17 Dec24 Dec 2025
CVE-2025-40602SonicWall SMA1000 applianceSonicWall SMA1000 Missing Authorization17 Dec24 Dec 2025
CVE-2025-59374ASUS Live UpdateEmbedded Malicious Code17 Dec7 Jan 2026
CVE-2025-59718Fortinet Multiple ProductsImproper Verification of Cryptographic Signature16 Dec23 Dec 2025
CVE-2025-14611Gladinet CentreStack and TriofoxHard Coded Cryptographic15 Dec5 Jan 2026
CVE-2025-43529Apple Multiple ProductsUse-After-Free WebKit15 Dec5 Jan 2026
CVE-2018-4063Sierra Wireless AirLink ALEOSUnrestricted Upload of File with Dangerous Type12 Dec2 Jan 2026
CVE-2025-14174Google ChromiumOut of Bounds Memory Access12 Dec2 Jan 2026
CVE-2025-58360OSGeo GeoServerImproper Restriction of XML External Entity Reference11 Dec1 Jan 2026
CVE-2025-6218RARLAB WinRARPath Traversal9 Dec30 Dec 2025
CVE-2025-62221Microsoft WindowsUse After Free9 Dec30 Dec 2025
CVE-2022-37055D-Link RoutersBuffer Overflow8 Dec29 Dec 2025
CVE-2025-66644Array Networks ArrayOS AGArray Networks ArrayOS AG OS Command Injection8 Dec29 Dec 2025
CVE-2025-55182Meta React Server ComponentsRemote Code Execution5 Dec12 Dec 2025Known
CVE-2021-26828OpenPLC ScadaBRUnrestricted Upload of File with Dangerous Type3 Dec24 Dec 2025
CVE-2025-48572Android FrameworkPrivilege Escalation2 Dec23 Dec 2025
CVE-2025-48633Android FrameworkInformation Disclosure2 Dec23 Dec 2025

All 57 fixes

Show the full list, with a filter
CVEProductWhatSeverityCVSS
CVE-2025-62554Microsoft OfficeMicrosoft Office Remote Code ExecutionCritical8.4
CVE-2025-62557Microsoft OfficeMicrosoft Office Remote Code ExecutionCritical8.4
CVE-2025-62456Windows Resilient File System (ReFS)Windows Resilient File System (ReFS) Remote Code ExecutionImportant8.8
CVE-2025-62549Windows Routing and Remote Access Service (RRAS)Windows Routing and Remote Access Service (RRAS) Remote Code ExecutionImportant8.8
CVE-2025-62550Azure Monitor AgentAzure Monitor Agent Remote Code ExecutionImportant8.8
CVE-2025-64672Microsoft Office SharePointMicrosoft SharePoint Server SpoofingImportant8.8
CVE-2025-64678Windows Routing and Remote Access Service (RRAS)Windows Routing and Remote Access Service (RRAS) Remote Code ExecutionImportant8.8
CVE-2025-64671CopilotGitHub Copilot for Jetbrains Remote Code ExecutionImportant8.4
CVE-2025-54100Windows PowerShellPowerShell Remote Code ExecutionImportant7.8
CVE-2025-55233Windows Projected File SystemWindows Projected File System Elevation of PrivilegeImportant7.8
CVE-2025-59516Windows Storage VSP DriverWindows Storage VSP Driver Elevation of PrivilegeImportant7.8
CVE-2025-59517Windows Storage VSP DriverWindows Storage VSP Driver Elevation of PrivilegeImportant7.8
CVE-2025-62221Windows Cloud Files Mini Filter DriverWindows Cloud Files Mini Filter Driver Elevation of PrivilegeImportant7.8
CVE-2025-62454Windows Cloud Files Mini Filter DriverWindows Cloud Files Mini Filter Driver Elevation of PrivilegeImportant7.8
CVE-2025-62455Windows Message QueuingMicrosoft Message Queuing (MSMQ) Elevation of PrivilegeImportant7.8
CVE-2025-62457Windows Cloud Files Mini Filter DriverWindows Cloud Files Mini Filter Driver Elevation of PrivilegeImportant7.8
CVE-2025-62458Windows Win32K – GRFXWin32k Elevation of PrivilegeImportant7.8
CVE-2025-62461Windows Projected File System Filter DriverWindows Projected File System Elevation of PrivilegeImportant7.8
CVE-2025-62462Windows Projected File SystemWindows Projected File System Elevation of PrivilegeImportant7.8
CVE-2025-62464Windows Projected File SystemWindows Projected File System Elevation of PrivilegeImportant7.8
CVE-2025-62466Windows Client-Side Caching (CSC) ServiceWindows Client-Side Caching Elevation of PrivilegeImportant7.8
CVE-2025-62467Windows Projected File SystemWindows Projected File System Elevation of PrivilegeImportant7.8
CVE-2025-62470Windows Common Log File System DriverWindows Common Log File System Driver Elevation of PrivilegeImportant7.8
CVE-2025-62472Windows Remote Access Connection ManagerWindows Remote Access Connection Manager Elevation of PrivilegeImportant7.8
CVE-2025-62474Windows Remote Access Connection ManagerWindows Remote Access Connection Manager Elevation of PrivilegeImportant7.8
CVE-2025-62552Microsoft Office AccessMicrosoft Access Remote Code ExecutionImportant7.8
CVE-2025-62553Microsoft Office ExcelMicrosoft Excel Remote Code ExecutionImportant7.8
CVE-2025-62556Microsoft Office ExcelMicrosoft Excel Remote Code ExecutionImportant7.8
CVE-2025-62558Microsoft Office WordMicrosoft Word Remote Code ExecutionImportant7.8
CVE-2025-62559Microsoft Office WordMicrosoft Word Remote Code ExecutionImportant7.8
CVE-2025-62560Microsoft Office ExcelMicrosoft Excel Remote Code ExecutionImportant7.8
CVE-2025-62561Microsoft Office ExcelMicrosoft Excel Remote Code ExecutionImportant7.8
CVE-2025-62562Microsoft Office OutlookMicrosoft Outlook Remote Code ExecutionImportant7.8
CVE-2025-62563Microsoft Office ExcelMicrosoft Excel Remote Code ExecutionImportant7.8
CVE-2025-62564Microsoft Office ExcelMicrosoft Excel Remote Code ExecutionImportant7.8
CVE-2025-62571Windows InstallerWindows Installer Elevation of PrivilegeImportant7.8
CVE-2025-62572Application Information ServicesApplication Information Service Elevation of PrivilegeImportant7.8
CVE-2025-64661Windows ShellWindows Shell Elevation of PrivilegeImportant7.8
CVE-2025-64669Windows Admin CenterWindows Admin Center Elevation of PrivilegeImportant7.8
CVE-2025-64673Storvsp.sys DriverWindows Storage VSP Driver Elevation of PrivilegeImportant7.8
CVE-2025-64679Windows DWM Core LibraryWindows DWM Core Library Elevation of PrivilegeImportant7.8
CVE-2025-64680Windows DWM Core LibraryWindows DWM Core Library Elevation of PrivilegeImportant7.8
CVE-2025-64658Windows ShellWindows File Explorer Elevation of PrivilegeImportant7.5
CVE-2025-64666Microsoft Exchange ServerMicrosoft Exchange Server Elevation of PrivilegeImportant7.5
CVE-2025-62565Windows ShellWindows File Explorer Elevation of PrivilegeImportant7.3
CVE-2025-62570Windows Camera Frame Server MonitorWindows Camera Frame Server Monitor Information DisclosureImportant7.1
CVE-2025-62469Microsoft Brokering File SystemMicrosoft Brokering File System Elevation of PrivilegeImportant7.0
CVE-2025-62555Microsoft Office WordMicrosoft Word Remote Code ExecutionImportant7.0
CVE-2025-62569Microsoft Brokering File SystemMicrosoft Brokering File System Elevation of PrivilegeImportant7.0
CVE-2025-62573Windows DirectXDirectX Graphics Kernel Elevation of PrivilegeImportant7.0
CVE-2025-62463Windows DirectXDirectX Graphics Kernel Denial of ServiceImportant6.5
CVE-2025-62465Windows DirectXDirectX Graphics Kernel Denial of ServiceImportant6.5
CVE-2025-62473Windows Routing and Remote Access Service (RRAS)Windows Routing and Remote Access Service (RRAS) Information DisclosureImportant6.5
CVE-2025-64670Microsoft Graphics ComponentWindows DirectX Information DisclosureImportant6.5
CVE-2025-62468Windows Defender Firewall ServiceWindows Defender Firewall Service Information DisclosureImportant5.5
CVE-2025-62567Windows Hyper-VWindows Hyper-V Denial of ServiceImportant5.3
CVE-2025-64667Microsoft Exchange ServerMicrosoft Exchange Server SpoofingImportant5.3

Published later in the month (8)

Microsoft Edge updates, out-of-band fixes and cloud services. “Fixed by Microsoft” means a cloud service Microsoft has already patched: there is nothing to install.

DateCVEWhatSeverityAction
18 DecCVE-2025-65037Azure Container Apps Remote Code ExecutionCriticalFixed by Microsoft
18 DecCVE-2025-65041Microsoft Partner Center Elevation of PrivilegeCriticalFixed by Microsoft
18 DecCVE-2025-64663Custom Question Answering Elevation of PrivilegeCriticalFixed by Microsoft
18 DecCVE-2025-64675Azure Cosmos DB SpoofingCriticalFixed by Microsoft
18 DecCVE-2025-64677Office Out-of-Box Experience SpoofingCriticalFixed by Microsoft
18 DecCVE-2025-64676Microsoft Purview eDiscovery Remote Code ExecutionCriticalFixed by Microsoft
4 DecCVE-2025-62223Microsoft Edge (Chromium-based) for Mac SpoofingLowUpdate
18 DecCVE-2025-65046Microsoft Edge (Chromium-based) SpoofingLowUpdate

From Microsoft’s Security Update Guide and CISA’s Known Exploited Vulnerabilities catalog, checked 6 days ago. Only vulnerabilities Microsoft itself issued are counted; Chromium fixes that Edge inherits are left out. For known problems with the updates themselves, see Windows release health.

← All tools