How to use it Start with "Patch these first" for the fixes attackers are already using. Then filter the list by product or keyword, or tick "Critical only" to narrow it down.
Next Patch Tuesday: Tue 13 Oct 2026 (in 3 days)
December 2025 Patch Tuesday: Microsoft fixed 57 vulnerabilities, 2 of them Critical. 1 was already being exploited. Released Tue 9 Dec 2025.
- 57vulnerabilities fixed
- 2Critical
- 1exploited before the fix
- 2publicly disclosed
- 1now on CISA KEV
By type: 29 elevation of privilege, 19 remote code execution, 4 information disclosure, 3 denial of service, 2 spoofing.
Update problems? Ask in Patch Tuesday & Updates. From October 2026 a “what broke for you?” thread opens there at 1 pm Eastern every Patch Tuesday.
Patch these first
Being exploited, already public, or on CISA’s list of vulnerabilities attackers are using. Whatever else waits for testing, these should not.
| CVE | What | Severity | CVSS | Why first |
|---|---|---|---|---|
CVE-2025-64671 | GitHub Copilot for Jetbrains Remote Code Execution | Important | 8.4 | Publicly disclosed |
CVE-2025-54100 | PowerShell Remote Code Execution | Important | 7.8 | Publicly disclosed |
CVE-2025-62221 | Windows Cloud Files Mini Filter Driver Elevation of Privilege | Important | 7.8 | Exploited On CISA KEV federal deadline 30 Dec |
Critical (2)
Microsoft’s top rating: usually code execution with little or no user action.
| CVE | What | Impact | CVSS |
|---|---|---|---|
CVE-2025-62554 | Microsoft Office Remote Code Execution | Remote Code Execution | 8.4 |
CVE-2025-62557 | Microsoft Office Remote Code Execution | Remote Code Execution | 8.4 |
Added to CISA KEV in December 2025 (20)
Every vendor, not only Microsoft. CISA adds a vulnerability when it has evidence attackers are using it. US federal agencies must fix it by the deadline shown; for everyone else, it is the best free “patch this now” list there is.
| CVE | Vendor and product | What | Added | Federal deadline | Ransomware |
|---|---|---|---|---|---|
CVE-2025-14847 | MongoDB MongoDB and MongoDB Server | MongoDB and MongoDB Server Improper Handling of Length Parameter Inconsistency | 29 Dec | 19 Jan 2026 | |
CVE-2023-52163 | Digiever DS-2105 Pro | Missing Authorization | 22 Dec | 12 Jan 2026 | |
CVE-2025-14733 | WatchGuard Firebox | Out of Bounds Write | 19 Dec | 26 Dec 2025 | Known |
CVE-2025-20393 | Cisco Multiple Products | Improper Input Validation | 17 Dec | 24 Dec 2025 | |
CVE-2025-40602 | SonicWall SMA1000 appliance | SonicWall SMA1000 Missing Authorization | 17 Dec | 24 Dec 2025 | |
CVE-2025-59374 | ASUS Live Update | Embedded Malicious Code | 17 Dec | 7 Jan 2026 | |
CVE-2025-59718 | Fortinet Multiple Products | Improper Verification of Cryptographic Signature | 16 Dec | 23 Dec 2025 | |
CVE-2025-14611 | Gladinet CentreStack and Triofox | Hard Coded Cryptographic | 15 Dec | 5 Jan 2026 | |
CVE-2025-43529 | Apple Multiple Products | Use-After-Free WebKit | 15 Dec | 5 Jan 2026 | |
CVE-2018-4063 | Sierra Wireless AirLink ALEOS | Unrestricted Upload of File with Dangerous Type | 12 Dec | 2 Jan 2026 | |
CVE-2025-14174 | Google Chromium | Out of Bounds Memory Access | 12 Dec | 2 Jan 2026 | |
CVE-2025-58360 | OSGeo GeoServer | Improper Restriction of XML External Entity Reference | 11 Dec | 1 Jan 2026 | |
CVE-2025-6218 | RARLAB WinRAR | Path Traversal | 9 Dec | 30 Dec 2025 | |
CVE-2025-62221 | Microsoft Windows | Use After Free | 9 Dec | 30 Dec 2025 | |
CVE-2022-37055 | D-Link Routers | Buffer Overflow | 8 Dec | 29 Dec 2025 | |
CVE-2025-66644 | Array Networks ArrayOS AG | Array Networks ArrayOS AG OS Command Injection | 8 Dec | 29 Dec 2025 | |
CVE-2025-55182 | Meta React Server Components | Remote Code Execution | 5 Dec | 12 Dec 2025 | Known |
CVE-2021-26828 | OpenPLC ScadaBR | Unrestricted Upload of File with Dangerous Type | 3 Dec | 24 Dec 2025 | |
CVE-2025-48572 | Android Framework | Privilege Escalation | 2 Dec | 23 Dec 2025 | |
CVE-2025-48633 | Android Framework | Information Disclosure | 2 Dec | 23 Dec 2025 |
All 57 fixes
Show the full list, with a filter
| CVE | Product | What | Severity | CVSS |
|---|---|---|---|---|
CVE-2025-62554 | Microsoft Office | Microsoft Office Remote Code Execution | Critical | 8.4 |
CVE-2025-62557 | Microsoft Office | Microsoft Office Remote Code Execution | Critical | 8.4 |
CVE-2025-62456 | Windows Resilient File System (ReFS) | Windows Resilient File System (ReFS) Remote Code Execution | Important | 8.8 |
CVE-2025-62549 | Windows Routing and Remote Access Service (RRAS) | Windows Routing and Remote Access Service (RRAS) Remote Code Execution | Important | 8.8 |
CVE-2025-62550 | Azure Monitor Agent | Azure Monitor Agent Remote Code Execution | Important | 8.8 |
CVE-2025-64672 | Microsoft Office SharePoint | Microsoft SharePoint Server Spoofing | Important | 8.8 |
CVE-2025-64678 | Windows Routing and Remote Access Service (RRAS) | Windows Routing and Remote Access Service (RRAS) Remote Code Execution | Important | 8.8 |
CVE-2025-64671 | Copilot | GitHub Copilot for Jetbrains Remote Code Execution | Important | 8.4 |
CVE-2025-54100 | Windows PowerShell | PowerShell Remote Code Execution | Important | 7.8 |
CVE-2025-55233 | Windows Projected File System | Windows Projected File System Elevation of Privilege | Important | 7.8 |
CVE-2025-59516 | Windows Storage VSP Driver | Windows Storage VSP Driver Elevation of Privilege | Important | 7.8 |
CVE-2025-59517 | Windows Storage VSP Driver | Windows Storage VSP Driver Elevation of Privilege | Important | 7.8 |
CVE-2025-62221 | Windows Cloud Files Mini Filter Driver | Windows Cloud Files Mini Filter Driver Elevation of Privilege | Important | 7.8 |
CVE-2025-62454 | Windows Cloud Files Mini Filter Driver | Windows Cloud Files Mini Filter Driver Elevation of Privilege | Important | 7.8 |
CVE-2025-62455 | Windows Message Queuing | Microsoft Message Queuing (MSMQ) Elevation of Privilege | Important | 7.8 |
CVE-2025-62457 | Windows Cloud Files Mini Filter Driver | Windows Cloud Files Mini Filter Driver Elevation of Privilege | Important | 7.8 |
CVE-2025-62458 | Windows Win32K – GRFX | Win32k Elevation of Privilege | Important | 7.8 |
CVE-2025-62461 | Windows Projected File System Filter Driver | Windows Projected File System Elevation of Privilege | Important | 7.8 |
CVE-2025-62462 | Windows Projected File System | Windows Projected File System Elevation of Privilege | Important | 7.8 |
CVE-2025-62464 | Windows Projected File System | Windows Projected File System Elevation of Privilege | Important | 7.8 |
CVE-2025-62466 | Windows Client-Side Caching (CSC) Service | Windows Client-Side Caching Elevation of Privilege | Important | 7.8 |
CVE-2025-62467 | Windows Projected File System | Windows Projected File System Elevation of Privilege | Important | 7.8 |
CVE-2025-62470 | Windows Common Log File System Driver | Windows Common Log File System Driver Elevation of Privilege | Important | 7.8 |
CVE-2025-62472 | Windows Remote Access Connection Manager | Windows Remote Access Connection Manager Elevation of Privilege | Important | 7.8 |
CVE-2025-62474 | Windows Remote Access Connection Manager | Windows Remote Access Connection Manager Elevation of Privilege | Important | 7.8 |
CVE-2025-62552 | Microsoft Office Access | Microsoft Access Remote Code Execution | Important | 7.8 |
CVE-2025-62553 | Microsoft Office Excel | Microsoft Excel Remote Code Execution | Important | 7.8 |
CVE-2025-62556 | Microsoft Office Excel | Microsoft Excel Remote Code Execution | Important | 7.8 |
CVE-2025-62558 | Microsoft Office Word | Microsoft Word Remote Code Execution | Important | 7.8 |
CVE-2025-62559 | Microsoft Office Word | Microsoft Word Remote Code Execution | Important | 7.8 |
CVE-2025-62560 | Microsoft Office Excel | Microsoft Excel Remote Code Execution | Important | 7.8 |
CVE-2025-62561 | Microsoft Office Excel | Microsoft Excel Remote Code Execution | Important | 7.8 |
CVE-2025-62562 | Microsoft Office Outlook | Microsoft Outlook Remote Code Execution | Important | 7.8 |
CVE-2025-62563 | Microsoft Office Excel | Microsoft Excel Remote Code Execution | Important | 7.8 |
CVE-2025-62564 | Microsoft Office Excel | Microsoft Excel Remote Code Execution | Important | 7.8 |
CVE-2025-62571 | Windows Installer | Windows Installer Elevation of Privilege | Important | 7.8 |
CVE-2025-62572 | Application Information Services | Application Information Service Elevation of Privilege | Important | 7.8 |
CVE-2025-64661 | Windows Shell | Windows Shell Elevation of Privilege | Important | 7.8 |
CVE-2025-64669 | Windows Admin Center | Windows Admin Center Elevation of Privilege | Important | 7.8 |
CVE-2025-64673 | Storvsp.sys Driver | Windows Storage VSP Driver Elevation of Privilege | Important | 7.8 |
CVE-2025-64679 | Windows DWM Core Library | Windows DWM Core Library Elevation of Privilege | Important | 7.8 |
CVE-2025-64680 | Windows DWM Core Library | Windows DWM Core Library Elevation of Privilege | Important | 7.8 |
CVE-2025-64658 | Windows Shell | Windows File Explorer Elevation of Privilege | Important | 7.5 |
CVE-2025-64666 | Microsoft Exchange Server | Microsoft Exchange Server Elevation of Privilege | Important | 7.5 |
CVE-2025-62565 | Windows Shell | Windows File Explorer Elevation of Privilege | Important | 7.3 |
CVE-2025-62570 | Windows Camera Frame Server Monitor | Windows Camera Frame Server Monitor Information Disclosure | Important | 7.1 |
CVE-2025-62469 | Microsoft Brokering File System | Microsoft Brokering File System Elevation of Privilege | Important | 7.0 |
CVE-2025-62555 | Microsoft Office Word | Microsoft Word Remote Code Execution | Important | 7.0 |
CVE-2025-62569 | Microsoft Brokering File System | Microsoft Brokering File System Elevation of Privilege | Important | 7.0 |
CVE-2025-62573 | Windows DirectX | DirectX Graphics Kernel Elevation of Privilege | Important | 7.0 |
CVE-2025-62463 | Windows DirectX | DirectX Graphics Kernel Denial of Service | Important | 6.5 |
CVE-2025-62465 | Windows DirectX | DirectX Graphics Kernel Denial of Service | Important | 6.5 |
CVE-2025-62473 | Windows Routing and Remote Access Service (RRAS) | Windows Routing and Remote Access Service (RRAS) Information Disclosure | Important | 6.5 |
CVE-2025-64670 | Microsoft Graphics Component | Windows DirectX Information Disclosure | Important | 6.5 |
CVE-2025-62468 | Windows Defender Firewall Service | Windows Defender Firewall Service Information Disclosure | Important | 5.5 |
CVE-2025-62567 | Windows Hyper-V | Windows Hyper-V Denial of Service | Important | 5.3 |
CVE-2025-64667 | Microsoft Exchange Server | Microsoft Exchange Server Spoofing | Important | 5.3 |
Published later in the month (8)
Microsoft Edge updates, out-of-band fixes and cloud services. “Fixed by Microsoft” means a cloud service Microsoft has already patched: there is nothing to install.
| Date | CVE | What | Severity | Action |
|---|---|---|---|---|
| 18 Dec | CVE-2025-65037 | Azure Container Apps Remote Code Execution | Critical | Fixed by Microsoft |
| 18 Dec | CVE-2025-65041 | Microsoft Partner Center Elevation of Privilege | Critical | Fixed by Microsoft |
| 18 Dec | CVE-2025-64663 | Custom Question Answering Elevation of Privilege | Critical | Fixed by Microsoft |
| 18 Dec | CVE-2025-64675 | Azure Cosmos DB Spoofing | Critical | Fixed by Microsoft |
| 18 Dec | CVE-2025-64677 | Office Out-of-Box Experience Spoofing | Critical | Fixed by Microsoft |
| 18 Dec | CVE-2025-64676 | Microsoft Purview eDiscovery Remote Code Execution | Critical | Fixed by Microsoft |
| 4 Dec | CVE-2025-62223 | Microsoft Edge (Chromium-based) for Mac Spoofing | Low | Update |
| 18 Dec | CVE-2025-65046 | Microsoft Edge (Chromium-based) Spoofing | Low | Update |
From Microsoft’s Security Update Guide and CISA’s Known Exploited Vulnerabilities catalog, checked 6 days ago. Only vulnerabilities Microsoft itself issued are counted; Chromium fixes that Edge inherits are left out. For known problems with the updates themselves, see Windows release health.