Patch Tuesday cycleJune 2025 Patch TuesdayComplete

Canonical Patch Tuesday catalogue

June 2025 Patch Tuesday catalogue.

Complete for the active Patch Tuesday cohort: Microsoft, Adobe and SAP. 88 operational patch records link 349 unique CVEs. No claim is made for vendors outside that cohort. Each row is one deployable update or vendor advisory with linked CVEs. BlackTree timing remains separate from CVSS and vendor severity.

88Patch recordsStable operational entries, not CVE duplicates
349Linked unique CVEsEvery CVE opens in BlackTree CVE Intelligence
17Accelerated actionsOut-of-band action
0Revised entriesCanonical history remains visible

June 2025 Patch Tuesday

Patch catalogue

Search and filters execute on the server. Each response is capped at the selected bounded page size, with a maximum of 100 compact patch rows.

Hide update groups
No groups hidden

Select every group you want removed from this view, its shared URL and its filtered exports.

Adobe
Microsoft
SAP
Several vendor and product groups can be hidden together.
Additional filtersProduct, platform, exploitation, restart, issues, date and cycle state
Reset filters
88 matching recordsPage 1 of 5
Selected PDF report0 of 20 visible records selectedSelect up to 20 approved records. Filter-hidden selections remain selected until cleared.
AdobeUpdate Adobe Experience Manager to the fixed Adobe releaseAPSB25-48 · Updated 2025-06-10
Product and releaseAdobe Experience ManagerAEM Cloud Service Release 2025.5
Review linked CVEs (236) No confirmed exploitation stated

Operational summary

Adobe published APSB25-48 on Patch Tuesday for Adobe Experience Manager. The bulletin links 236 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB25-48
Platform
All
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 8.7; Adobe priority 3

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (236)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 8.7
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe Commerce to the fixed Adobe releaseAPSB25-50 · Updated 2025-06-10
Product and releaseAdobe Commerce2.4.9-alpha1 2.4.8-p1 for 2.4.8 2.4.7-p6 for 2.4.7-p5 and earlier 2.4.6-p11 for 2.4.6-p10 and earlier 2.4.5-p13 for 2.4.5-p12 and earlier 2.4.4-p14 for 2.4.4-p13 and earlier, Isolated patch on CVE-2025-47110
Review linked CVEs (7) No confirmed exploitation stated

Operational summary

Adobe published APSB25-50 on Patch Tuesday for Adobe Commerce. The bulletin links 7 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB25-50
Platform
All
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 9.1; Adobe priority 1

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (7)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 8.4
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe Substance 3D Sampler to the fixed Adobe releaseAPSB25-55 · Updated 2025-06-10
Product and releaseAdobe Substance 3D Sampler5.0.3
Review linked CVEs (2) No confirmed exploitation stated

Operational summary

Adobe published APSB25-55 on Patch Tuesday for Adobe Substance 3D Sampler. The bulletin links 2 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB25-55
Platform
All
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 7.8; Adobe priority 3

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (2)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe Substance 3D Painter to the fixed Adobe releaseAPSB25-58 · Updated 2025-06-10
Product and releaseAdobe Substance 3D Painter11.0.2
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

Adobe published APSB25-58 on Patch Tuesday for Adobe Substance 3D Painter. The bulletin links 1 CVE and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB25-58
Platform
All
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 7.8; Adobe priority 3

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe Acrobat Reader to the fixed Adobe releaseAPSB25-57 · Updated 2025-06-10
Product and releaseAdobe Acrobat ReaderFixed release detail requires source review
Review linked CVEs (10) No confirmed exploitation stated

Operational summary

Adobe published APSB25-57 on Patch Tuesday for Adobe Acrobat Reader. The bulletin links 10 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB25-57
Platform
See Adobe bulletin
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 7.8

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (10)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe InCopy to the fixed Adobe releaseAPSB25-41 · Updated 2025-06-10
Product and releaseAdobe InCopy20.3, 19.5.4
Review linked CVEs (2) No confirmed exploitation stated

Operational summary

Adobe published APSB25-41 on Patch Tuesday for Adobe InCopy. The bulletin links 2 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB25-41
Platform
Windows and macOS
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 7.8; Adobe priority 3

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (2)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe InDesign to the fixed Adobe releaseAPSB25-53 · Updated 2025-06-10
Product and releaseAdobe InDesignID20.3, ID19.5.4
Review linked CVEs (9) No confirmed exploitation stated

Operational summary

Adobe published APSB25-53 on Patch Tuesday for Adobe InDesign. The bulletin links 9 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB25-53
Platform
Windows and macOS
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 7.8; Adobe priority 3

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (9)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Azure update for Nuance Digital Engagement PlatformMSRC-2025-06-azure-release-notes · Updated 2025-06-10
Product and releaseNuance Digital Engagement Platform5.64.x
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for Nuance Digital Engagement Platform.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2025-06-azure-release-notes
Platform
Azure
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 8.2
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Developer Tools security update KB5061935KB5061935 · Updated 2025-06-10
Product and release.NET 8.0 installed on Linux, .NET 8.0 installed on Mac OS, .NET 8.0 installed on Windows8.0.17
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for .NET 8.0 installed on Linux, .NET 8.0 installed on Mac OS, .NET 8.0 installed on Windows.

Open official sourceCanonical detail record

Evidence and release

Advisory
KB5061935
Platform
Developer Tools
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.5
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Developer Tools security update KB5061936KB5061936 · Updated 2025-06-10
Product and release.NET 9.0 installed on Linux, .NET 9.0 installed on Mac OS, .NET 9.0 installed on Windows9.0.6
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for .NET 9.0 installed on Linux, .NET 9.0 installed on Mac OS, .NET 9.0 installed on Windows.

Open official sourceCanonical detail record

Evidence and release

Advisory
KB5061936
Platform
Developer Tools
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.5
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Developer Tools update for PowerShell 7.4MSRC-2025-06-developer-tools-release-notes · Updated 2025-06-10
Product and releasePowerShell 7.47.4.11
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for PowerShell 7.4.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2025-06-developer-tools-release-notes
Platform
Developer Tools
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.5
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Developer Tools update for PowerShell 7.5MSRC-2025-06-developer-tools-release-notes · Updated 2025-06-10
Product and releasePowerShell 7.57.5.2
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for PowerShell 7.5.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2025-06-developer-tools-release-notes
Platform
Developer Tools
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.5
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Developer Tools update for Microsoft Visual Studio 2022 version 17.12MSRC-2025-06-developer-tools-release-notes · Updated 2025-06-10
Product and releaseMicrosoft Visual Studio 2022 version 17.1217.12.9
Review linked CVEs (2) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 2 linked CVEs for Microsoft Visual Studio 2022 version 17.12.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2025-06-developer-tools-release-notes
Platform
Developer Tools
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (2)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.5
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Developer Tools update for Microsoft Visual Studio 2022 version 17.8MSRC-2025-06-developer-tools-release-notes · Updated 2025-06-10
Product and releaseMicrosoft Visual Studio 2022 version 17.817.8.22
Review linked CVEs (2) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 2 linked CVEs for Microsoft Visual Studio 2022 version 17.8.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2025-06-developer-tools-release-notes
Platform
Developer Tools
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (2)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.5
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Developer Tools update for Microsoft Visual Studio 2022 version 17.10MSRC-2025-06-developer-tools-release-notes · Updated 2025-06-10
Product and releaseMicrosoft Visual Studio 2022 version 17.1017.10.16
Review linked CVEs (2) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 2 linked CVEs for Microsoft Visual Studio 2022 version 17.10.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2025-06-developer-tools-release-notes
Platform
Developer Tools
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (2)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.5
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Developer Tools update for Microsoft Visual Studio 2022 version 17.14MSRC-2025-06-developer-tools-release-notes · Updated 2025-06-10
Product and releaseMicrosoft Visual Studio 2022 version 17.1417.14.5
Review linked CVEs (2) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 2 linked CVEs for Microsoft Visual Studio 2022 version 17.14.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2025-06-developer-tools-release-notes
Platform
Developer Tools
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (2)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.5
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Developer Tools update for Windows SDKMSRC-2025-06-developer-tools-release-notes · Updated 2025-06-10
Product and releaseWindows SDK10.0.26100.4188
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for Windows SDK.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2025-06-developer-tools-release-notes
Platform
Developer Tools
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft ESU security update KB5058379KB5058379 · Updated 2025-06-10
Product and releaseWindows 10 Version 22H2 for 32-bit Systems, Windows 10 Version 22H2 for ARM64-based Systems, Windows 10 Version 22H2 for x64-based Systems10.0.19045.5854
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for Windows 10 Version 22H2 for 32-bit Systems, Windows 10 Version 22H2 for ARM64-based Systems, Windows 10 Version 22H2 for x64-based Systems.

Open official sourceCanonical detail record

Evidence and release

Advisory
KB5058379
Platform
ESU
Restart
yes
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft ESU security update KB5058403KB5058403 · Updated 2025-06-10
Product and releaseWindows Server 2012 R2, Windows Server 2012 R2 (Server Core installation)6.3.9600.22577
Review linked CVEs (2) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 2 linked CVEs for Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation).

Open official sourceCanonical detail record

Evidence and release

Advisory
KB5058403
Platform
ESU
Restart
yes
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
Vendor-linked CVEs (2)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 8.1
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft ESU security update KB5058405KB5058405 · Updated 2025-06-10
Product and releaseWindows 11 Version 22H2 for ARM64-based Systems, Windows 11 Version 22H2 for x64-based Systems10.0.22621.5335
Review linked CVEs (2) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 2 linked CVEs for Windows 11 Version 22H2 for ARM64-based Systems, Windows 11 Version 22H2 for x64-based Systems.

Open official sourceCanonical detail record

Evidence and release

Advisory
KB5058405
Platform
ESU
Restart
yes
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
Vendor-linked CVEs (2)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0