Spiceworks Microsoft's Record Patch Tuesday Addresses 167 CVEs Including Zero-Days
Article Content
- •Microsoft's October 2025 Patch Tuesday addressed 167 CVEs, the largest release to date.
- •Three zero-day vulnerabilities were included, with two actively exploited in the wild.
- •The volume of Microsoft patches has surged significantly, necessitating improved patch management strategies.
On October 2025 Patch Tuesday, Microsoft released patches for 167 CVEs, marking its largest update to date. Among these, three zero-day vulnerabilities were identified, with two actively exploited in the wild. The vulnerabilities span various Microsoft products, including Windows, Office, and Azure services. Notably, CVE-2025-24990 and CVE-2025-59230 were both added to the CISA KEV list on their publication date, October 14, 2025. The update included seven critical vulnerabilities, with elevation of privilege vulnerabilities making up nearly half of the total. The growing volume of patches reflects a significant increase in vulnerability counts, with September 2026 alone approaching 1,000 new CVEs. Security professionals are urged to prioritize patch management and adapt their strategies to cope with this surge in vulnerabilities.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Microsoft and CVE-2023-32056 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in F5 BIG-IP APM Exploited for Remote Code Execution F5 Networks has reported a critical vulnerability in its BIG-IP Access Policy Manager (APM), tracked as CVE-2026-94127, which is being actively exploited in the wild. The flaw allows unauthenticated attackers to execute remote code on systems configured with both an APM access policy and an OAuth profile. This…
Massive Network of AI Proxy Servers Used for Malicious Activities Uncovered Security researchers from Team Cymru have identified over 10,000 proxy servers in China facilitating malicious AI activities. These servers, termed 'transfer stations,' are primarily used to bypass geographic restrictions and conduct model distillation attacks against frontier AI models. The infrastructure allows…