BlackTreeCVE IntelligenceCanonical Patch Tuesday catalogue
May 2025 Patch Tuesday catalogue.
Complete for the active Patch Tuesday cohort: Microsoft, Adobe and SAP. 99 operational patch records link 131 unique CVEs. No claim is made for vendors outside that cohort. Each row is one deployable update or vendor advisory with linked CVEs. BlackTree timing remains separate from CVSS and vendor severity.
May 2025 Patch Tuesday
Patch catalogue
Search and filters execute on the server. Each response is capped at the selected bounded page size, with a maximum of 100 compact patch rows.
AdobeUpdate Adobe Lightroom to the fixed Adobe releaseAPSB25-29 · Updated 2025-05-13Product and releaseAdobe Lightroom8.3Review linked CVEs (1) No confirmed exploitation stated
Operational summary
Adobe published APSB25-29 on Patch Tuesday for Adobe Lightroom. The bulletin links 1 CVE and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB25-29
- Platform
- All
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; Adobe priority 3
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe Connect to the fixed Adobe releaseAPSB25-36 · Updated 2025-05-13Product and releaseAdobe Connect12.9Review linked CVEs (4) No confirmed exploitation stated
Operational summary
Adobe published APSB25-36 on Patch Tuesday for Adobe Connect. The bulletin links 4 CVEs and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB25-36
- Platform
- All
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 9.3; Adobe priority 3
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe Substance 3D Painter to the fixed Adobe releaseAPSB25-38 · Updated 2025-05-13Product and releaseAdobe Substance 3D Painter11.0.1Review linked CVEs (1) No confirmed exploitation stated
Operational summary
Adobe published APSB25-38 on Patch Tuesday for Adobe Substance 3D Painter. The bulletin links 1 CVE and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB25-38
- Platform
- All
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 7.8; Adobe priority 3
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe ColdFusion to the fixed Adobe releaseAPSB25-52 · Updated 2025-05-13Product and releaseAdobe ColdFusionUpdate 2, Update 14, Update 20Review linked CVEs (9) No confirmed exploitation stated
Operational summary
Adobe published APSB25-52 on Patch Tuesday for Adobe ColdFusion. The bulletin links 9 CVEs and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB25-52
- Platform
- All
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 9.1; Adobe priority 1
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe Photoshop to the fixed Adobe releaseAPSB25-40 · Updated 2025-05-13Product and releaseAdobe PhotoshopFixed release detail requires source reviewReview linked CVEs (3) No confirmed exploitation stated
Operational summary
Adobe published APSB25-40 on Patch Tuesday for Adobe Photoshop. The bulletin links 3 CVEs and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB25-40
- Platform
- See Adobe bulletin
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 7.8
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe Dreamweaver to the fixed Adobe releaseAPSB25-35 · Updated 2025-05-13Product and releaseAdobe Dreamweaver21.5Review linked CVEs (1) No confirmed exploitation stated
Operational summary
Adobe published APSB25-35 on Patch Tuesday for Adobe Dreamweaver. The bulletin links 1 CVE and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB25-35
- Platform
- Windows and macOS
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; Adobe priority 3
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe InDesign to the fixed Adobe releaseAPSB25-37 · Updated 2025-05-13Product and releaseAdobe InDesignID20.3, ID19.5.3Review linked CVEs (3) No confirmed exploitation stated
Operational summary
Adobe published APSB25-37 on Patch Tuesday for Adobe InDesign. The bulletin links 3 CVEs and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB25-37
- Platform
- Windows and macOS
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 7.8; Adobe priority 3
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe Animate to the fixed Adobe releaseAPSB25-42 · Updated 2025-05-13Product and releaseAdobe Animate23.0.12, 24.0.9Review linked CVEs (5) No confirmed exploitation stated
Operational summary
Adobe published APSB25-42 on Patch Tuesday for Adobe Animate. The bulletin links 5 CVEs and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB25-42
- Platform
- Windows and macOS
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 7.8; Adobe priority 3
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe Illustrator to the fixed Adobe releaseAPSB25-43 · Updated 2025-05-13Product and releaseAdobe Illustrator29.4 and above, 28.7.6 and aboveReview linked CVEs (1) No confirmed exploitation stated
Operational summary
Adobe published APSB25-43 on Patch Tuesday for Adobe Illustrator. The bulletin links 1 CVE and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB25-43
- Platform
- Windows and macOS
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 7.8; Adobe priority 3
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe Bridge to the fixed Adobe releaseAPSB25-44 · Updated 2025-05-13Product and releaseAdobe Bridge14.1.7, 15.0.4Review linked CVEs (3) No confirmed exploitation stated
Operational summary
Adobe published APSB25-44 on Patch Tuesday for Adobe Bridge. The bulletin links 3 CVEs and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB25-44
- Platform
- Windows and macOS
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 7.8
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe Dimension to the fixed Adobe releaseAPSB25-45 · Updated 2025-05-13Product and releaseAdobe Dimension4.1.2Review linked CVEs (2) No confirmed exploitation stated
Operational summary
Adobe published APSB25-45 on Patch Tuesday for Adobe Dimension. The bulletin links 2 CVEs and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB25-45
- Platform
- Windows and macOS
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 7.8; Adobe priority 3
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe Substance 3D Stager to the fixed Adobe releaseAPSB25-46 · Updated 2025-05-13Product and releaseAdobe Substance 3D Stager3.1.2Review linked CVEs (6) No confirmed exploitation stated
Operational summary
Adobe published APSB25-46 on Patch Tuesday for Adobe Substance 3D Stager. The bulletin links 6 CVEs and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB25-46
- Platform
- Windows and macOS
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 7.8; Adobe priority 3
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
MicrosoftDeploy Microsoft Apps update for Microsoft PC ManagerMSRC-2025-05-apps-release-notes · Updated 2025-05-13Product and releaseMicrosoft PC Manager3.16.1.0Review linked CVEs (1) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft PC Manager.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- MSRC-2025-05-apps-release-notes
- Platform
- Apps
- Restart
- varies by product
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- This update uses vendor release notes or a fixed build instead of a standalone KB identity.
MicrosoftDeploy Microsoft Azure update for Azure File Sync v19MSRC-2025-05-azure-release-notes · Updated 2025-05-13Product and releaseAzure File Sync v1926100Review linked CVEs (1) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 1 linked CVE for Azure File Sync v19.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- MSRC-2025-05-azure-release-notes
- Platform
- Azure
- Restart
- varies by product
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- This update uses vendor release notes or a fixed build instead of a standalone KB identity.
MicrosoftDeploy Microsoft Azure update for Azure File Sync v20MSRC-2025-05-azure-release-notes · Updated 2025-05-13Product and releaseAzure File Sync v205041884Review linked CVEs (1) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 1 linked CVE for Azure File Sync v20.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- MSRC-2025-05-azure-release-notes
- Platform
- Azure
- Restart
- varies by product
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- This update uses vendor release notes or a fixed build instead of a standalone KB identity.
MicrosoftDeploy Microsoft Azure update for Azure AI Document Intelligence StudioMSRC-2025-05-azure-release-notes · Updated 2025-05-13Product and releaseAzure AI Document Intelligence Studio1.0.03019.1-official-7241c17aReview linked CVEs (1) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 1 linked CVE for Azure AI Document Intelligence Studio.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- MSRC-2025-05-azure-release-notes
- Platform
- Azure
- Restart
- varies by product
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- This update uses vendor release notes or a fixed build instead of a standalone KB identity.
MicrosoftDeploy Microsoft Azure update for Windows HLK for Windows Server 2022MSRC-2025-05-azure-release-notes · Updated 2025-05-13Product and releaseWindows HLK for Windows Server 202210.1.20348.3330Review linked CVEs (1) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 1 linked CVE for Windows HLK for Windows Server 2022.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- MSRC-2025-05-azure-release-notes
- Platform
- Azure
- Restart
- varies by product
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- This update uses vendor release notes or a fixed build instead of a standalone KB identity.
MicrosoftDeploy Microsoft Developer Tools security update KB5059200KB5059200 · Updated 2025-05-13Product and release.NET 8.0 installed on Linux, .NET 8.0 installed on Mac OS, .NET 8.0 installed on Windows8.0.16Review linked CVEs (1) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 1 linked CVE for .NET 8.0 installed on Linux, .NET 8.0 installed on Mac OS, .NET 8.0 installed on Windows.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- KB5059200
- Platform
- Developer Tools
- Restart
- varies by product
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
MicrosoftDeploy Microsoft Developer Tools security update KB5059201KB5059201 · Updated 2025-05-13Product and release.NET 9.0 installed on Linux, .NET 9.0 installed on Mac OS, .NET 9.0 installed on Windows9.0.5Review linked CVEs (1) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 1 linked CVE for .NET 9.0 installed on Linux, .NET 9.0 installed on Mac OS, .NET 9.0 installed on Windows.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- KB5059201
- Platform
- Developer Tools
- Restart
- varies by product
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
MicrosoftDeploy Microsoft Developer Tools update for Microsoft Visual Studio 2022 version 17.12MSRC-2025-05-developer-tools-release-notes · Updated 2025-05-13Product and releaseMicrosoft Visual Studio 2022 version 17.1217.12.8Review linked CVEs (3) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 3 linked CVEs for Microsoft Visual Studio 2022 version 17.12. Microsoft marks CVE-2025-32702 as publicly disclosed, without that disclosure alone changing the BlackTree action window.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- MSRC-2025-05-developer-tools-release-notes
- Platform
- Developer Tools
- Restart
- varies by product
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- This update uses vendor release notes or a fixed build instead of a standalone KB identity.