Patch Tuesday cycleSeptember 2025 Patch TuesdayComplete

Canonical Patch Tuesday catalogue

September 2025 Patch Tuesday catalogue.

Complete for the active Patch Tuesday cohort: Microsoft, Adobe and SAP. 86 operational patch records link 130 unique CVEs. No claim is made for vendors outside that cohort. Each row is one deployable update or vendor advisory with linked CVEs. BlackTree timing remains separate from CVSS and vendor severity.

86Patch recordsStable operational entries, not CVE duplicates
130Linked unique CVEsEvery CVE opens in BlackTree CVE Intelligence
0Accelerated actionsNo accelerated action in this view
5Revised entriesCanonical history remains visible

September 2025 Patch Tuesday

Patch catalogue

Search and filters execute on the server. Each response is capped at the selected bounded page size, with a maximum of 100 compact patch rows.

Hide update groups
No groups hidden

Select every group you want removed from this view, its shared URL and its filtered exports.

Adobe
Microsoft
SAP
Several vendor and product groups can be hidden together.
Additional filtersProduct, platform, exploitation, restart, issues, date and cycle state
Reset filters
86 matching recordsPage 1 of 5
Selected PDF report0 of 20 visible records selectedSelect up to 20 approved records. Filter-hidden selections remain selected until cleared.
AdobeUpdate Adobe Commerce to the fixed Adobe releaseAPSB25-88 · Updated 2025-09-09
Product and releaseAdobe CommerceHotfix for CVE-2025-54236 Compatible with all Adobe Commerce and Magento Open Source versions between 2.4.4 - 2.4.7
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

Adobe published APSB25-88 on Patch Tuesday for Adobe Commerce. The bulletin links 1 CVE and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB25-88
Platform
All
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 9.1; Adobe priority 1

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (1)1 confirmed exploited · 1 with PoC or lab evidence · max CVSS 9.1
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe Substance 3D Viewer to the fixed Adobe releaseAPSB25-89 · Updated 2025-09-09
Product and releaseAdobe Substance 3D Viewer0.25.2
Review linked CVEs (3) No confirmed exploitation stated

Operational summary

Adobe published APSB25-89 on Patch Tuesday for Adobe Substance 3D Viewer. The bulletin links 3 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB25-89
Platform
All
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 7.8; Adobe priority 3

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (3)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe Experience Manager to the fixed Adobe releaseAPSB25-90 · Updated 2025-09-09
Product and releaseAdobe Experience ManagerAEM Cloud Service Release 2025.9, 6.5 LTS SP1 (GRANITE-61551 Hotfix), 6.5.23 (GRANITE-61551 Hotfix)
Review linked CVEs (7) No confirmed exploitation stated

Operational summary

Adobe published APSB25-90 on Patch Tuesday for Adobe Experience Manager. The bulletin links 7 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB25-90
Platform
All
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 7.7; Adobe priority 3

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (7)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.7
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe 3D Substance Modeler to the fixed Adobe releaseAPSB25-92 · Updated 2025-09-09
Product and releaseAdobe 3D Substance Modeler1.22.4
Review linked CVEs (3) No confirmed exploitation stated

Operational summary

Adobe published APSB25-92 on Patch Tuesday for Adobe 3D Substance Modeler. The bulletin links 3 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB25-92
Platform
All
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 7.8; Adobe priority 3

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (3)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe ColdFusion to the fixed Adobe releaseAPSB25-93 · Updated 2025-09-09
Product and releaseAdobe ColdFusionUpdate 4, Update 16, Update 22
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

Adobe published APSB25-93 on Patch Tuesday for Adobe ColdFusion. The bulletin links 1 CVE and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB25-93
Platform
All
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 10.0; Adobe priority 1

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 10.0
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe Acrobat Reader to the fixed Adobe releaseAPSB25-85 · Updated 2025-09-09
Product and releaseAdobe Acrobat ReaderFixed release detail requires source review
Review linked CVEs (2) No confirmed exploitation stated

Operational summary

Adobe published APSB25-85 on Patch Tuesday for Adobe Acrobat Reader. The bulletin links 2 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB25-85
Platform
See Adobe bulletin
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 7.8

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (2)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe After Effects to the fixed Adobe releaseAPSB25-86 · Updated 2025-09-09
Product and releaseAdobe After Effects24.6.8, 25.4
Review linked CVEs (3) No confirmed exploitation stated

Operational summary

Adobe published APSB25-86 on Patch Tuesday for Adobe After Effects. The bulletin links 3 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB25-86
Platform
Windows and macOS
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important; CVSS 5.5; Adobe priority 3

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (3)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 5.5
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe Premiere Pro to the fixed Adobe releaseAPSB25-87 · Updated 2025-09-09
Product and releaseAdobe Premiere Pro25.4, 24.6.8
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

Adobe published APSB25-87 on Patch Tuesday for Adobe Premiere Pro. The bulletin links 1 CVE and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB25-87
Platform
Windows and macOS
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 7.8; Adobe priority 3

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe Dreamweaver to the fixed Adobe releaseAPSB25-91 · Updated 2025-09-09
Product and releaseAdobe Dreamweaver21.6
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

Adobe published APSB25-91 on Patch Tuesday for Adobe Dreamweaver. The bulletin links 1 CVE and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB25-91
Platform
Windows and macOS
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; Adobe priority 3

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 8.6
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Apps update for Xbox Gaming ServicesMSRC-2025-09-apps-release-notes · Updated 2025-09-09
Product and releaseXbox Gaming Services30.104.13001.0.
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for Xbox Gaming Services.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2025-09-apps-release-notes
Platform
Apps
Restart
no
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Azure update for Microsoft HPC Pack 2019MSRC-2025-09-azure-release-notes · Updated 2025-09-09
Product and releaseMicrosoft HPC Pack 20196.3.8352 Quick Fix QFE
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft HPC Pack 2019.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2025-09-azure-release-notes
Platform
Azure
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 9.8
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Azure update for Azure Connected Machine AgentMSRC-2025-09-azure-release-notes · Updated 2025-09-09
Product and releaseAzure Connected Machine Agent1.49, 1.56
Review linked CVEs (2) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 2 linked CVEs for Azure Connected Machine Agent.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2025-09-azure-release-notes
Platform
Azure
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (2)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Developer Tools update for PowerShell 7.4MSRC-2025-09-developer-tools-release-notes · Updated 2025-09-09
Product and releasePowerShell 7.47.4.12
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for PowerShell 7.4.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2025-09-developer-tools-release-notes
Platform
Developer Tools
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.0
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Developer Tools update for PowerShell 7.5MSRC-2025-09-developer-tools-release-notes · Updated 2025-09-09
Product and releasePowerShell 7.57.5.3
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for PowerShell 7.5.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2025-09-developer-tools-release-notes
Platform
Developer Tools
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.0
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft ESU security update KB5065429KB5065429 · Updated 2025-09-09
Product and releaseWindows 10 Version 22H2 for 32-bit Systems, Windows 10 Version 22H2 for ARM64-based Systems, Windows 10 Version 22H2 for x64-based Systems10.0.19045.6332
Review linked CVEs (44) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 44 linked CVEs for Windows 10 Version 22H2 for 32-bit Systems, Windows 10 Version 22H2 for ARM64-based Systems, Windows 10 Version 22H2 for x64-based Systems. Microsoft marks CVE-2025-55234 as publicly disclosed, without that disclosure alone changing the BlackTree action window.

Open official sourceCanonical detail record

Evidence and release

Advisory
KB5065429
Platform
ESU
Restart
yes
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
MicrosoftDeploy Microsoft ESU security update KB5065431KB5065431 · Updated 2025-09-09
Product and releaseWindows 11 Version 22H2 for ARM64-based Systems, Windows 11 Version 22H2 for x64-based Systems10.0.22621.5909
Review linked CVEs (45) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 45 linked CVEs for Windows 11 Version 22H2 for ARM64-based Systems, Windows 11 Version 22H2 for x64-based Systems. Microsoft marks CVE-2025-55234 as publicly disclosed, without that disclosure alone changing the BlackTree action window.

Open official sourceCanonical detail record

Evidence and release

Advisory
KB5065431
Platform
ESU
Restart
yes
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
MicrosoftDeploy Microsoft ESU security update KB5065435KB5065435 · Updated 2025-09-09
Product and releaseWindows Server 2008 R2 for x64-based Systems Service Pack 1, Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation), Windows Server 2008 for 32-bit Systems Service Pack 2, plus 7 more1.000
Review linked CVEs (2) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 2 linked CVEs for Windows Server 2008 R2 for x64-based Systems Service Pack 1, Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation), Windows Server 2008 for 32-bit Systems Service Pack 2, plus 7 more.

Open official sourceCanonical detail record

Evidence and release

Advisory
KB5065435
Platform
ESU
Restart
yes
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
Vendor-linked CVEs (2)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 4.3
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft ESU security update KB5065468KB5065468 · Updated 2025-09-09
Product and releaseWindows Server 2008 R2 for x64-based Systems Service Pack 1, Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)6.1.7601.27929
Review linked CVEs (30) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 30 linked CVEs for Windows Server 2008 R2 for x64-based Systems Service Pack 1, Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation). Microsoft marks CVE-2025-55234 as publicly disclosed, without that disclosure alone changing the BlackTree action window.

Open official sourceCanonical detail record

Evidence and release

Advisory
KB5065468
Platform
ESU
Restart
yes
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
MicrosoftDeploy Microsoft ESU security update KB5065507KB5065507 · Updated 2025-09-09
Product and releaseWindows Server 2012 R2, Windows Server 2012 R2 (Server Core installation)6.3.9600.22774
Review linked CVEs (35) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 35 linked CVEs for Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation). Microsoft marks CVE-2025-55234 as publicly disclosed, without that disclosure alone changing the BlackTree action window.

Open official sourceCanonical detail record

Evidence and release

Advisory
KB5065507
Platform
ESU
Restart
yes
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
MicrosoftDeploy Microsoft ESU security update KB5065508KB5065508 · Updated 2025-09-09
Product and releaseWindows Server 2008 for 32-bit Systems Service Pack 2, Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation), Windows Server 2008 for x64-based Systems Service Pack 2, plus 1 more6.0.6003.23529
Review linked CVEs (26) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 26 linked CVEs for Windows Server 2008 for 32-bit Systems Service Pack 2, Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation), Windows Server 2008 for x64-based Systems Service Pack 2, plus 1 more. Microsoft marks CVE-2025-55234 as publicly disclosed, without that disclosure alone changing the BlackTree action window.

Open official sourceCanonical detail record

Evidence and release

Advisory
KB5065508
Platform
ESU
Restart
yes
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.