BlackTreeCVE IntelligenceCanonical Patch Tuesday catalogue
July 2025 Patch Tuesday catalogue.
Complete for the active Patch Tuesday cohort: Microsoft, Adobe and SAP. 112 operational patch records link 226 unique CVEs. No claim is made for vendors outside that cohort. Each row is one deployable update or vendor advisory with linked CVEs. BlackTree timing remains separate from CVSS and vendor severity.
July 2025 Patch Tuesday
Patch catalogue
Search and filters execute on the server. Each response is capped at the selected bounded page size, with a maximum of 100 compact patch rows.
AdobeUpdate Adobe Substance 3D Viewer to the fixed Adobe releaseAPSB25-54 · Updated 2025-07-08Product and releaseAdobe Substance 3D Viewer0.25Review linked CVEs (3) No confirmed exploitation stated
Operational summary
Adobe published APSB25-54 on Patch Tuesday for Adobe Substance 3D Viewer. The bulletin links 3 CVEs and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB25-54
- Platform
- All
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 7.8; Adobe priority 3
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe Experience Manager Forms to the fixed Adobe releaseAPSB25-67 · Updated 2025-07-08Product and releaseAdobe Experience Manager Forms6.5.0.0.20250527.0Review linked CVEs (1) No confirmed exploitation stated
Operational summary
Adobe published APSB25-67 on Patch Tuesday for Adobe Experience Manager Forms. The bulletin links 1 CVE and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB25-67
- Platform
- All
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 9.8; Adobe priority 1
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe Experience Manager Screens to the fixed Adobe releaseAPSB25-68 · Updated 2025-07-08Product and releaseAdobe Experience Manager ScreensAEM 6.5.22 Screens FP11.6Review linked CVEs (2) No confirmed exploitation stated
Operational summary
Adobe published APSB25-68 on Patch Tuesday for Adobe Experience Manager Screens. The bulletin links 2 CVEs and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB25-68
- Platform
- All
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important; CVSS 5.4; Adobe priority 3
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe ColdFusion to the fixed Adobe releaseAPSB25-69 · Updated 2025-07-08Product and releaseAdobe ColdFusionUpdate 3, Update 15, Update 21Review linked CVEs (13) No confirmed exploitation stated
Operational summary
Adobe published APSB25-69 on Patch Tuesday for Adobe ColdFusion. The bulletin links 13 CVEs and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB25-69
- Platform
- All
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 9.3; Adobe priority 1
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe Connect to the fixed Adobe releaseAPSB25-61 · Updated 2025-07-08Product and releaseAdobe Connect25.1Review linked CVEs (1) No confirmed exploitation stated
Operational summary
Adobe published APSB25-61 on Patch Tuesday for Adobe Connect. The bulletin links 1 CVE and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB25-61
- Platform
- Windows
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 9.3; Adobe priority 3
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe FrameMaker to the fixed Adobe releaseAPSB25-66 · Updated 2025-07-08Product and releaseAdobe FrameMakerFrameMaker 2020 Update 9, FrameMaker 2022 Update 7Review linked CVEs (15) No confirmed exploitation stated
Operational summary
Adobe published APSB25-66 on Patch Tuesday for Adobe FrameMaker. The bulletin links 15 CVEs and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB25-66
- Platform
- Windows
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 7.8; Adobe priority 3
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe After Effects to the fixed Adobe releaseAPSB25-49 · Updated 2025-07-08Product and releaseAdobe After Effects24.6.7, 25.3Review linked CVEs (2) No confirmed exploitation stated
Operational summary
Adobe published APSB25-49 on Patch Tuesday for Adobe After Effects. The bulletin links 2 CVEs and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB25-49
- Platform
- Windows and macOS
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important; CVSS 5.5; Adobe priority 3
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe Audition to the fixed Adobe releaseAPSB25-56 · Updated 2025-07-08Product and releaseAdobe Audition24.6.7, 25.3Review linked CVEs (1) No confirmed exploitation stated
Operational summary
Adobe published APSB25-56 on Patch Tuesday for Adobe Audition. The bulletin links 1 CVE and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB25-56
- Platform
- Windows and macOS
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important; CVSS 5.5; Adobe priority 3
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe InCopy to the fixed Adobe releaseAPSB25-59 · Updated 2025-07-08Product and releaseAdobe InCopy20.4, 19.5.4Review linked CVEs (3) No confirmed exploitation stated
Operational summary
Adobe published APSB25-59 on Patch Tuesday for Adobe InCopy. The bulletin links 3 CVEs and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB25-59
- Platform
- Windows and macOS
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 7.8; Adobe priority 3
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe InDesign to the fixed Adobe releaseAPSB25-60 · Updated 2025-07-08Product and releaseAdobe InDesignID20.4, ID19.5.4Review linked CVEs (6) No confirmed exploitation stated
Operational summary
Adobe published APSB25-60 on Patch Tuesday for Adobe InDesign. The bulletin links 6 CVEs and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB25-60
- Platform
- Windows and macOS
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 7.8; Adobe priority 3
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe Dimension to the fixed Adobe releaseAPSB25-63 · Updated 2025-07-08Product and releaseAdobe Dimension4.1.3Review linked CVEs (2) No confirmed exploitation stated
Operational summary
Adobe published APSB25-63 on Patch Tuesday for Adobe Dimension. The bulletin links 2 CVEs and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB25-63
- Platform
- Windows and macOS
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 7.8; Adobe priority 3
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe Substance 3D Stager to the fixed Adobe releaseAPSB25-64 · Updated 2025-07-08Product and releaseAdobe Substance 3D Stager3.1.3Review linked CVEs (1) No confirmed exploitation stated
Operational summary
Adobe published APSB25-64 on Patch Tuesday for Adobe Substance 3D Stager. The bulletin links 1 CVE and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB25-64
- Platform
- Windows and macOS
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important; CVSS 5.5; Adobe priority 3
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe Illustrator to the fixed Adobe releaseAPSB25-65 · Updated 2025-07-08Product and releaseAdobe Illustrator29.6 and above, 28.7.8 and aboveReview linked CVEs (10) No confirmed exploitation stated
Operational summary
Adobe published APSB25-65 on Patch Tuesday for Adobe Illustrator. The bulletin links 10 CVEs and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB25-65
- Platform
- Windows and macOS
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 7.8; Adobe priority 3
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
MicrosoftDeploy Microsoft Apps update for Microsoft PC ManagerMSRC-2025-07-apps-release-notes · Updated 2025-07-08Product and releaseMicrosoft PC Manager3.17.4Review linked CVEs (1) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft PC Manager.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- MSRC-2025-07-apps-release-notes
- Platform
- Apps
- Restart
- varies by product
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- This update uses vendor release notes or a fixed build instead of a standalone KB identity.
MicrosoftDeploy Microsoft Azure update for Azure Service FabricMSRC-2025-07-azure-release-notes · Updated 2025-07-08Product and releaseAzure Service Fabric10.1 Cumulative Update 7.0Review linked CVEs (1) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 1 linked CVE for Azure Service Fabric.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- MSRC-2025-07-azure-release-notes
- Platform
- Azure
- Restart
- varies by product
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- This update uses vendor release notes or a fixed build instead of a standalone KB identity.
MicrosoftDeploy Microsoft Azure update for Azure Monitor AgentMSRC-2025-07-azure-release-notes · Updated 2025-07-08Product and releaseAzure Monitor Agent1.35.1Review linked CVEs (1) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 1 linked CVE for Azure Monitor Agent.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- MSRC-2025-07-azure-release-notes
- Platform
- Azure
- Restart
- no
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- This update uses vendor release notes or a fixed build instead of a standalone KB identity.
MicrosoftDeploy Microsoft Developer Tools security update KB5063035KB5063035 · Updated 2025-07-08Product and releaseMicrosoft Visual Studio 2015 Update 314.0.27564.0Review linked CVEs (1) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft Visual Studio 2015 Update 3.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- KB5063035
- Platform
- Developer Tools
- Restart
- varies by product
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
MicrosoftDeploy Microsoft Developer Tools update for Microsoft Visual Studio 2022 version 17.8MSRC-2025-07-developer-tools-release-notes · Updated 2025-07-08Product and releaseMicrosoft Visual Studio 2022 version 17.817.8.23Review linked CVEs (2) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 2 linked CVEs for Microsoft Visual Studio 2022 version 17.8.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- MSRC-2025-07-developer-tools-release-notes
- Platform
- Developer Tools
- Restart
- varies by product
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- This update uses vendor release notes or a fixed build instead of a standalone KB identity.
MicrosoftDeploy Microsoft Developer Tools update for Microsoft Visual Studio 2022 version 17.10MSRC-2025-07-developer-tools-release-notes · Updated 2025-07-08Product and releaseMicrosoft Visual Studio 2022 version 17.1017.10.17Review linked CVEs (2) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 2 linked CVEs for Microsoft Visual Studio 2022 version 17.10.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- MSRC-2025-07-developer-tools-release-notes
- Platform
- Developer Tools
- Restart
- varies by product
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- This update uses vendor release notes or a fixed build instead of a standalone KB identity.
MicrosoftDeploy Microsoft Developer Tools update for Microsoft Visual Studio 2022 version 17.12MSRC-2025-07-developer-tools-release-notes · Updated 2025-07-08Product and releaseMicrosoft Visual Studio 2022 version 17.1217.12.10Review linked CVEs (2) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 2 linked CVEs for Microsoft Visual Studio 2022 version 17.12.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- MSRC-2025-07-developer-tools-release-notes
- Platform
- Developer Tools
- Restart
- varies by product
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- This update uses vendor release notes or a fixed build instead of a standalone KB identity.