Patch Tuesday cycleAugust 2025 Patch TuesdayComplete

Canonical Patch Tuesday catalogue

August 2025 Patch Tuesday catalogue.

Complete for the active Patch Tuesday cohort: Microsoft, Adobe and SAP. 132 operational patch records link 194 unique CVEs. No claim is made for vendors outside that cohort. Each row is one deployable update or vendor advisory with linked CVEs. BlackTree timing remains separate from CVSS and vendor severity.

132Patch recordsStable operational entries, not CVE duplicates
194Linked unique CVEsEvery CVE opens in BlackTree CVE Intelligence
0Accelerated actionsNo accelerated action in this view
4Revised entriesCanonical history remains visible

August 2025 Patch Tuesday

Patch catalogue

Search and filters execute on the server. Each response is capped at the selected bounded page size, with a maximum of 100 compact patch rows.

Hide update groups
No groups hidden

Select every group you want removed from this view, its shared URL and its filtered exports.

Adobe
Microsoft
SAP
Several vendor and product groups can be hidden together.
Additional filtersProduct, platform, exploitation, restart, issues, date and cycle state
Reset filters
132 matching recordsPage 1 of 7
Selected PDF report0 of 20 visible records selectedSelect up to 20 approved records. Filter-hidden selections remain selected until cleared.
AdobeUpdate Adobe Commerce to the fixed Adobe releaseAPSB25-71 · Updated 2025-08-12
Product and releaseAdobe Commerce2.4.9-alpha2 2.4.8-p2 2.4.7-p7 2.4.6-p12 2.4.5-p14 2.4.4-p15
Review linked CVEs (6) No confirmed exploitation stated

Operational summary

Adobe published APSB25-71 on Patch Tuesday for Adobe Commerce. The bulletin links 6 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB25-71
Platform
All
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 8.7; Adobe priority 2

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (6)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 8.7
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe Substance 3D Viewer to the fixed Adobe releaseAPSB25-72 · Updated 2025-08-12
Product and releaseAdobe Substance 3D Viewer0.25.1
Review linked CVEs (2) No confirmed exploitation stated

Operational summary

Adobe published APSB25-72 on Patch Tuesday for Adobe Substance 3D Viewer. The bulletin links 2 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB25-72
Platform
All
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 7.8; Adobe priority 3

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (2)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe Substance 3D Modeler to the fixed Adobe releaseAPSB25-76 · Updated 2025-08-12
Product and releaseAdobe Substance 3D Modeler1.22.2
Review linked CVEs (13) No confirmed exploitation stated

Operational summary

Adobe published APSB25-76 on Patch Tuesday for Adobe Substance 3D Modeler. The bulletin links 13 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB25-76
Platform
All
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 7.8; Adobe priority 3

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (13)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe Substance 3D Painter to the fixed Adobe releaseAPSB25-77 · Updated 2025-08-12
Product and releaseAdobe Substance 3D Painter11.0.3
Review linked CVEs (9) No confirmed exploitation stated

Operational summary

Adobe published APSB25-77 on Patch Tuesday for Adobe Substance 3D Painter. The bulletin links 9 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB25-77
Platform
All
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 7.8; Adobe priority 3

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (9)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe Substance 3D Sampler to the fixed Adobe releaseAPSB25-78 · Updated 2025-08-12
Product and releaseAdobe Substance 3D Sampler5.1.0
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

Adobe published APSB25-78 on Patch Tuesday for Adobe Substance 3D Sampler. The bulletin links 1 CVE and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB25-78
Platform
All
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important; CVSS 5.5; Adobe priority 3

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 5.5
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe Photoshop to the fixed Adobe releaseAPSB25-75 · Updated 2025-08-12
Product and releaseAdobe PhotoshopFixed release detail requires source review
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

Adobe published APSB25-75 on Patch Tuesday for Adobe Photoshop. The bulletin links 1 CVE and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB25-75
Platform
See Adobe bulletin
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 7.8

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe FrameMaker to the fixed Adobe releaseAPSB25-83 · Updated 2025-08-12
Product and releaseAdobe FrameMakerFrameMaker 2020 Update 9, FrameMaker 2022 Update 7
Review linked CVEs (5) No confirmed exploitation stated

Operational summary

Adobe published APSB25-83 on Patch Tuesday for Adobe FrameMaker. The bulletin links 5 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB25-83
Platform
Windows
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 7.8; Adobe priority 3

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (5)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe Animate to the fixed Adobe releaseAPSB25-73 · Updated 2025-08-12
Product and releaseAdobe Animate23.0.13, 24.0.10
Review linked CVEs (2) No confirmed exploitation stated

Operational summary

Adobe published APSB25-73 on Patch Tuesday for Adobe Animate. The bulletin links 2 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB25-73
Platform
Windows and macOS
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 7.8; Adobe priority 3

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (2)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe Illustrator to the fixed Adobe releaseAPSB25-74 · Updated 2025-08-12
Product and releaseAdobe Illustrator29.7 and above, 28.7.9 and above
Review linked CVEs (4) No confirmed exploitation stated

Operational summary

Adobe published APSB25-74 on Patch Tuesday for Adobe Illustrator. The bulletin links 4 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB25-74
Platform
Windows and macOS
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 7.8; Adobe priority 3

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (4)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe InDesign to the fixed Adobe releaseAPSB25-79 · Updated 2025-08-12
Product and releaseAdobe InDesignID20.5, ID19.5.5
Review linked CVEs (14) No confirmed exploitation stated

Operational summary

Adobe published APSB25-79 on Patch Tuesday for Adobe InDesign. The bulletin links 14 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB25-79
Platform
Windows and macOS
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 7.8; Adobe priority 3

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe InCopy to the fixed Adobe releaseAPSB25-80 · Updated 2025-08-12
Product and releaseAdobe InCopy20.5, 19.5.5
Review linked CVEs (8) No confirmed exploitation stated

Operational summary

Adobe published APSB25-80 on Patch Tuesday for Adobe InCopy. The bulletin links 8 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB25-80
Platform
Windows and macOS
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 7.8; Adobe priority 3

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (8)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe Substance 3D Stager to the fixed Adobe releaseAPSB25-81 · Updated 2025-08-12
Product and releaseAdobe Substance 3D Stager3.1.4
Review linked CVEs (3) No confirmed exploitation stated

Operational summary

Adobe published APSB25-81 on Patch Tuesday for Adobe Substance 3D Stager. The bulletin links 3 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB25-81
Platform
Windows and macOS
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 7.8; Adobe priority 3

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (3)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe Dimension to the fixed Adobe releaseAPSB25-84 · Updated 2025-08-12
Product and releaseAdobe Dimension4.1.4
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

Adobe published APSB25-84 on Patch Tuesday for Adobe Dimension. The bulletin links 1 CVE and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB25-84
Platform
Windows and macOS
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important; CVSS 5.5; Adobe priority 3

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 5.5
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Azure update for Azure File Sync v18MSRC-2025-08-azure-release-notes · Updated 2025-08-12
Product and releaseAzure File Sync v1818.3.0.0
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for Azure File Sync v18.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2025-08-azure-release-notes
Platform
Azure
Restart
no
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Azure update for Azure File Sync v19MSRC-2025-08-azure-release-notes · Updated 2025-08-12
Product and releaseAzure File Sync v1919.2.0.0
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for Azure File Sync v19.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2025-08-azure-release-notes
Platform
Azure
Restart
no
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Azure update for Azure File Sync v20MSRC-2025-08-azure-release-notes · Updated 2025-08-12
Product and releaseAzure File Sync v2020.1.0.0
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for Azure File Sync v20.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2025-08-azure-release-notes
Platform
Azure
Restart
no
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Azure update for Azure File Sync v21MSRC-2025-08-azure-release-notes · Updated 2025-08-12
Product and releaseAzure File Sync v2121.1.0.0
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for Azure File Sync v21.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2025-08-azure-release-notes
Platform
Azure
Restart
no
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Azure update for Azure Stack HubMSRC-2025-08-azure-release-notes · Updated 2025-08-12
Product and releaseAzure Stack Hub102.10.2.11
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for Azure Stack Hub.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2025-08-azure-release-notes
Platform
Azure
Restart
no
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 4.4
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Azure update for Azure Stack Hub 2408MSRC-2025-08-azure-release-notes · Updated 2025-08-12
Product and releaseAzure Stack Hub 24081.2408.1.50
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for Azure Stack Hub 2408.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2025-08-azure-release-notes
Platform
Azure
Restart
no
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.5
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Azure update for Azure Stack Hub 2406MSRC-2025-08-azure-release-notes · Updated 2025-08-12
Product and releaseAzure Stack Hub 24061.2406.1.23
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for Azure Stack Hub 2406.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2025-08-azure-release-notes
Platform
Azure
Restart
no
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.5
Confirmed exploitedCVSS above 9.0