BlackTreeCVE IntelligenceCanonical Patch Tuesday catalogue
April 2025 Patch Tuesday catalogue.
Complete for the active Patch Tuesday cohort: Microsoft, Adobe and SAP. 97 operational patch records link 193 unique CVEs. No claim is made for vendors outside that cohort. Each row is one deployable update or vendor advisory with linked CVEs. BlackTree timing remains separate from CVSS and vendor severity.
April 2025 Patch Tuesday
Patch catalogue
Search and filters execute on the server. Each response is capped at the selected bounded page size, with a maximum of 100 compact patch rows.
AdobeUpdate Adobe ColdFusion to the fixed Adobe releaseAPSB25-15 · Updated 2025-04-08Product and releaseAdobe ColdFusionUpdate 1, Update 13, Update 19Review linked CVEs (15) No confirmed exploitation stated
Operational summary
Adobe published APSB25-15 on Patch Tuesday for Adobe ColdFusion. The bulletin links 15 CVEs and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB25-15
- Platform
- All
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 9.1; Adobe priority 1
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe Commerce to the fixed Adobe releaseAPSB25-26 · Updated 2025-04-08Product and releaseAdobe Commerce2.4.8 for 2.4.8-beta2 2.4.7-p5 for 2.4.7-p4 and earlier 2.4.6-p10 for 2.4.6-p9 and earlier 2.4.5-p12 for 2.4.5-p11 and earlier 2.4.4-p13 for 2.4.4-p12 and earlierReview linked CVEs (5) No confirmed exploitation stated
Operational summary
Adobe published APSB25-26 on Patch Tuesday for Adobe Commerce. The bulletin links 5 CVEs and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB25-26
- Platform
- All
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important; CVSS 5.3; Adobe priority 2
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe Experience Manager Forms to the fixed Adobe releaseAPSB25-27 · Updated 2025-04-08Product and releaseAdobe Experience Manager Forms6.5.22.0 (AEMForms-6.5.0-0095)Review linked CVEs (2) No confirmed exploitation stated
Operational summary
Adobe published APSB25-27 on Patch Tuesday for Adobe Experience Manager Forms. The bulletin links 2 CVEs and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB25-27
- Platform
- All
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: CVSS 6.5; Adobe priority 2
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe Experience Manager Screens to the fixed Adobe releaseAPSB25-32 · Updated 2025-04-08Product and releaseAdobe Experience Manager ScreensAEM 6.5 Screens FP11.4Review linked CVEs (1) No confirmed exploitation stated
Operational summary
Adobe published APSB25-32 on Patch Tuesday for Adobe Experience Manager Screens. The bulletin links 1 CVE and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB25-32
- Platform
- All
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important; CVSS 5.4; Adobe priority 3
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe XMP Toolkit SDK to the fixed Adobe releaseAPSB25-34 · Updated 2025-04-08Product and releaseAdobe XMP Toolkit SDK2025.03Review linked CVEs (5) No confirmed exploitation stated
Operational summary
Adobe published APSB25-34 on Patch Tuesday for Adobe XMP Toolkit SDK. The bulletin links 5 CVEs and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB25-34
- Platform
- All
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important; CVSS 5.5; Adobe priority 3
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe Photoshop to the fixed Adobe releaseAPSB25-30 · Updated 2025-04-08Product and releaseAdobe PhotoshopFixed release detail requires source reviewReview linked CVEs (1) No confirmed exploitation stated
Operational summary
Adobe published APSB25-30 on Patch Tuesday for Adobe Photoshop. The bulletin links 1 CVE and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB25-30
- Platform
- See Adobe bulletin
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 7.8
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe FrameMaker to the fixed Adobe releaseAPSB25-33 · Updated 2025-04-08Product and releaseAdobe FrameMakerFrameMaker 2020 Update 8, FrameMaker 2022 Update 6Review linked CVEs (10) No confirmed exploitation stated
Operational summary
Adobe published APSB25-33 on Patch Tuesday for Adobe FrameMaker. The bulletin links 10 CVEs and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB25-33
- Platform
- Windows
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 7.8; Adobe priority 3
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe After Effects to the fixed Adobe releaseAPSB25-23 · Updated 2025-04-08Product and releaseAdobe After Effects24.6.5, 25.2Review linked CVEs (7) No confirmed exploitation stated
Operational summary
Adobe published APSB25-23 on Patch Tuesday for Adobe After Effects. The bulletin links 7 CVEs and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB25-23
- Platform
- Windows and macOS
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 7.8; Adobe priority 3
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe Media Encoder to the fixed Adobe releaseAPSB25-24 · Updated 2025-04-08Product and releaseAdobe Media Encoder24.6.5, 25.2Review linked CVEs (2) No confirmed exploitation stated
Operational summary
Adobe published APSB25-24 on Patch Tuesday for Adobe Media Encoder. The bulletin links 2 CVEs and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB25-24
- Platform
- Windows and macOS
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 7.8; Adobe priority 3
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe Bridge to the fixed Adobe releaseAPSB25-25 · Updated 2025-04-08Product and releaseAdobe Bridge14.1.6, 15.0.3Review linked CVEs (1) No confirmed exploitation stated
Operational summary
Adobe published APSB25-25 on Patch Tuesday for Adobe Bridge. The bulletin links 1 CVE and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB25-25
- Platform
- Windows and macOS
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 7.8
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe Premiere Pro to the fixed Adobe releaseAPSB25-28 · Updated 2025-04-08Product and releaseAdobe Premiere Pro25.2, 24.6.5Review linked CVEs (1) No confirmed exploitation stated
Operational summary
Adobe published APSB25-28 on Patch Tuesday for Adobe Premiere Pro. The bulletin links 1 CVE and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB25-28
- Platform
- Windows and macOS
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 7.8; Adobe priority 3
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe Animate to the fixed Adobe releaseAPSB25-31 · Updated 2025-04-08Product and releaseAdobe Animate23.0.11, 24.0.8Review linked CVEs (4) No confirmed exploitation stated
Operational summary
Adobe published APSB25-31 on Patch Tuesday for Adobe Animate. The bulletin links 4 CVEs and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB25-31
- Platform
- Windows and macOS
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 7.8; Adobe priority 3
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
MicrosoftDeploy Microsoft Apps update for Microsoft Outlook for AndroidMSRC-2025-04-apps-release-notes · Updated 2025-04-08Product and releaseMicrosoft Outlook for Android4.2509.0Review linked CVEs (1) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft Outlook for Android.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- MSRC-2025-04-apps-release-notes
- Platform
- Apps
- Restart
- varies by product
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- This update uses vendor release notes or a fixed build instead of a standalone KB identity.
MicrosoftDeploy Microsoft Azure security update KB5055526KB5055526 · Updated 2025-04-08Product and releaseAzure Stack HCI OS 22H210.0.20348.3328Review linked CVEs (1) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 1 linked CVE for Azure Stack HCI OS 22H2.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- KB5055526
- Platform
- Azure
- Restart
- yes
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
MicrosoftDeploy Microsoft Azure update for Azure Local ClusterMSRC-2025-04-azure-release-notes · Updated 2025-04-08Product and releaseAzure Local Cluster2411.2Review linked CVEs (2) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 2 linked CVEs for Azure Local Cluster.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- MSRC-2025-04-azure-release-notes
- Platform
- Azure
- Restart
- varies by product
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- This update uses vendor release notes or a fixed build instead of a standalone KB identity.
MicrosoftDeploy Microsoft Azure update for Azure Stack HCI OS 23H2MSRC-2025-04-azure-release-notes · Updated 2025-04-08Product and releaseAzure Stack HCI OS 23H210.0.25398.1486Review linked CVEs (1) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 1 linked CVE for Azure Stack HCI OS 23H2.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- MSRC-2025-04-azure-release-notes
- Platform
- Azure
- Restart
- yes
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- This update uses vendor release notes or a fixed build instead of a standalone KB identity.
MicrosoftDeploy Microsoft Azure update for Windows Admin Center in Azure PortalMSRC-2025-04-azure-release-notes · Updated 2025-04-08Product and releaseWindows Admin Center in Azure Portal0.45.0.0Review linked CVEs (1) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 1 linked CVE for Windows Admin Center in Azure Portal.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- MSRC-2025-04-azure-release-notes
- Platform
- Azure
- Restart
- varies by product
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- This update uses vendor release notes or a fixed build instead of a standalone KB identity.
MicrosoftDeploy Microsoft Developer Tools update for Visual Studio Tools for Applications (VSTA) 2019MSRC-2025-04-developer-tools-release-notes · Updated 2025-04-08Product and releaseVisual Studio Tools for Applications (VSTA) 201916.0.35907.0Review linked CVEs (1) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 1 linked CVE for Visual Studio Tools for Applications (VSTA) 2019.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- MSRC-2025-04-developer-tools-release-notes
- Platform
- Developer Tools
- Restart
- varies by product
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- This update uses vendor release notes or a fixed build instead of a standalone KB identity.
MicrosoftDeploy Microsoft Developer Tools update for Visual Studio Tools for Applications (VSTA) 2022MSRC-2025-04-developer-tools-release-notes · Updated 2025-04-08Product and releaseVisual Studio Tools for Applications (VSTA) 202217.0.35906.0Review linked CVEs (1) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 1 linked CVE for Visual Studio Tools for Applications (VSTA) 2022.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- MSRC-2025-04-developer-tools-release-notes
- Platform
- Developer Tools
- Restart
- varies by product
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- This update uses vendor release notes or a fixed build instead of a standalone KB identity.
MicrosoftDeploy Microsoft Developer Tools update for VSTA 2022 SDKMSRC-2025-04-developer-tools-release-notes · Updated 2025-04-08Product and releaseVSTA 2022 SDK17.0.35906.0Review linked CVEs (1) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 1 linked CVE for VSTA 2022 SDK.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- MSRC-2025-04-developer-tools-release-notes
- Platform
- Developer Tools
- Restart
- varies by product
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- This update uses vendor release notes or a fixed build instead of a standalone KB identity.