BlackTreeCVE IntelligenceCanonical Patch Tuesday catalogue
September 2025 Patch Tuesday catalogue.
Complete for the active Patch Tuesday cohort: Microsoft, Adobe and SAP. 86 operational patch records link 130 unique CVEs. No claim is made for vendors outside that cohort. Each row is one deployable update or vendor advisory with linked CVEs. BlackTree timing remains separate from CVSS and vendor severity.
September 2025 Patch Tuesday
Patch catalogue
Search and filters execute on the server. Each response is capped at the selected bounded page size, with a maximum of 100 compact patch rows.
AdobeUpdate Adobe Commerce to the fixed Adobe releaseAPSB25-88 · Updated 2025-09-09Product and releaseAdobe CommerceHotfix for CVE-2025-54236 Compatible with all Adobe Commerce and Magento Open Source versions between 2.4.4 - 2.4.7Review linked CVEs (1) No confirmed exploitation stated
Operational summary
Adobe published APSB25-88 on Patch Tuesday for Adobe Commerce. The bulletin links 1 CVE and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB25-88
- Platform
- All
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 9.1; Adobe priority 1
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe Substance 3D Viewer to the fixed Adobe releaseAPSB25-89 · Updated 2025-09-09Product and releaseAdobe Substance 3D Viewer0.25.2Review linked CVEs (3) No confirmed exploitation stated
Operational summary
Adobe published APSB25-89 on Patch Tuesday for Adobe Substance 3D Viewer. The bulletin links 3 CVEs and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB25-89
- Platform
- All
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 7.8; Adobe priority 3
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe Experience Manager to the fixed Adobe releaseAPSB25-90 · Updated 2025-09-09Product and releaseAdobe Experience ManagerAEM Cloud Service Release 2025.9, 6.5 LTS SP1 (GRANITE-61551 Hotfix), 6.5.23 (GRANITE-61551 Hotfix)Review linked CVEs (7) No confirmed exploitation stated
Operational summary
Adobe published APSB25-90 on Patch Tuesday for Adobe Experience Manager. The bulletin links 7 CVEs and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB25-90
- Platform
- All
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 7.7; Adobe priority 3
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe 3D Substance Modeler to the fixed Adobe releaseAPSB25-92 · Updated 2025-09-09Product and releaseAdobe 3D Substance Modeler1.22.4Review linked CVEs (3) No confirmed exploitation stated
Operational summary
Adobe published APSB25-92 on Patch Tuesday for Adobe 3D Substance Modeler. The bulletin links 3 CVEs and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB25-92
- Platform
- All
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 7.8; Adobe priority 3
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe ColdFusion to the fixed Adobe releaseAPSB25-93 · Updated 2025-09-09Product and releaseAdobe ColdFusionUpdate 4, Update 16, Update 22Review linked CVEs (1) No confirmed exploitation stated
Operational summary
Adobe published APSB25-93 on Patch Tuesday for Adobe ColdFusion. The bulletin links 1 CVE and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB25-93
- Platform
- All
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 10.0; Adobe priority 1
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe Acrobat Reader to the fixed Adobe releaseAPSB25-85 · Updated 2025-09-09Product and releaseAdobe Acrobat ReaderFixed release detail requires source reviewReview linked CVEs (2) No confirmed exploitation stated
Operational summary
Adobe published APSB25-85 on Patch Tuesday for Adobe Acrobat Reader. The bulletin links 2 CVEs and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB25-85
- Platform
- See Adobe bulletin
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 7.8
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe After Effects to the fixed Adobe releaseAPSB25-86 · Updated 2025-09-09Product and releaseAdobe After Effects24.6.8, 25.4Review linked CVEs (3) No confirmed exploitation stated
Operational summary
Adobe published APSB25-86 on Patch Tuesday for Adobe After Effects. The bulletin links 3 CVEs and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB25-86
- Platform
- Windows and macOS
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important; CVSS 5.5; Adobe priority 3
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe Premiere Pro to the fixed Adobe releaseAPSB25-87 · Updated 2025-09-09Product and releaseAdobe Premiere Pro25.4, 24.6.8Review linked CVEs (1) No confirmed exploitation stated
Operational summary
Adobe published APSB25-87 on Patch Tuesday for Adobe Premiere Pro. The bulletin links 1 CVE and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB25-87
- Platform
- Windows and macOS
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 7.8; Adobe priority 3
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe Dreamweaver to the fixed Adobe releaseAPSB25-91 · Updated 2025-09-09Product and releaseAdobe Dreamweaver21.6Review linked CVEs (1) No confirmed exploitation stated
Operational summary
Adobe published APSB25-91 on Patch Tuesday for Adobe Dreamweaver. The bulletin links 1 CVE and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB25-91
- Platform
- Windows and macOS
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; Adobe priority 3
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
MicrosoftDeploy Microsoft Apps update for Xbox Gaming ServicesMSRC-2025-09-apps-release-notes · Updated 2025-09-09Product and releaseXbox Gaming Services30.104.13001.0.Review linked CVEs (1) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 1 linked CVE for Xbox Gaming Services.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- MSRC-2025-09-apps-release-notes
- Platform
- Apps
- Restart
- no
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- This update uses vendor release notes or a fixed build instead of a standalone KB identity.
MicrosoftDeploy Microsoft Azure update for Microsoft HPC Pack 2019MSRC-2025-09-azure-release-notes · Updated 2025-09-09Product and releaseMicrosoft HPC Pack 20196.3.8352 Quick Fix QFEReview linked CVEs (1) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft HPC Pack 2019.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- MSRC-2025-09-azure-release-notes
- Platform
- Azure
- Restart
- varies by product
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- This update uses vendor release notes or a fixed build instead of a standalone KB identity.
MicrosoftDeploy Microsoft Azure update for Azure Connected Machine AgentMSRC-2025-09-azure-release-notes · Updated 2025-09-09Product and releaseAzure Connected Machine Agent1.49, 1.56Review linked CVEs (2) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 2 linked CVEs for Azure Connected Machine Agent.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- MSRC-2025-09-azure-release-notes
- Platform
- Azure
- Restart
- varies by product
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- This update uses vendor release notes or a fixed build instead of a standalone KB identity.
MicrosoftDeploy Microsoft Developer Tools update for PowerShell 7.4MSRC-2025-09-developer-tools-release-notes · Updated 2025-09-09Product and releasePowerShell 7.47.4.12Review linked CVEs (1) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 1 linked CVE for PowerShell 7.4.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- MSRC-2025-09-developer-tools-release-notes
- Platform
- Developer Tools
- Restart
- varies by product
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- This update uses vendor release notes or a fixed build instead of a standalone KB identity.
MicrosoftDeploy Microsoft Developer Tools update for PowerShell 7.5MSRC-2025-09-developer-tools-release-notes · Updated 2025-09-09Product and releasePowerShell 7.57.5.3Review linked CVEs (1) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 1 linked CVE for PowerShell 7.5.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- MSRC-2025-09-developer-tools-release-notes
- Platform
- Developer Tools
- Restart
- varies by product
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- This update uses vendor release notes or a fixed build instead of a standalone KB identity.
MicrosoftDeploy Microsoft ESU security update KB5065429KB5065429 · Updated 2025-09-09Product and releaseWindows 10 Version 22H2 for 32-bit Systems, Windows 10 Version 22H2 for ARM64-based Systems, Windows 10 Version 22H2 for x64-based Systems10.0.19045.6332Review linked CVEs (44) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 44 linked CVEs for Windows 10 Version 22H2 for 32-bit Systems, Windows 10 Version 22H2 for ARM64-based Systems, Windows 10 Version 22H2 for x64-based Systems. Microsoft marks CVE-2025-55234 as publicly disclosed, without that disclosure alone changing the BlackTree action window.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- KB5065429
- Platform
- ESU
- Restart
- yes
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- CVE-2025-49734
- CVE-2025-53799
- CVE-2025-53800
- CVE-2025-53801
- CVE-2025-53802
- CVE-2025-53803
- CVE-2025-53804
- CVE-2025-53807
- CVE-2025-53808
- CVE-2025-53810
- CVE-2025-54091
- CVE-2025-54092
- CVE-2025-54093
- CVE-2025-54094
- CVE-2025-54098
- CVE-2025-54099
- CVE-2025-54101
- CVE-2025-54102
- CVE-2025-54103
- CVE-2025-54104
- CVE-2025-54107
- CVE-2025-54109
- CVE-2025-54110
- CVE-2025-54111
- CVE-2025-54112
- CVE-2025-54114
- CVE-2025-54115
- CVE-2025-54116
- CVE-2025-54894
- CVE-2025-54895
- CVE-2025-54911
- CVE-2025-54912
- CVE-2025-54913
- CVE-2025-54915
- CVE-2025-54916
- CVE-2025-54917
- CVE-2025-54918
- CVE-2025-54919
- CVE-2025-55223
- CVE-2025-55224
- CVE-2025-55226
- CVE-2025-55228
- CVE-2025-55234
- CVE-2025-55236
MicrosoftDeploy Microsoft ESU security update KB5065431KB5065431 · Updated 2025-09-09Product and releaseWindows 11 Version 22H2 for ARM64-based Systems, Windows 11 Version 22H2 for x64-based Systems10.0.22621.5909Review linked CVEs (45) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 45 linked CVEs for Windows 11 Version 22H2 for ARM64-based Systems, Windows 11 Version 22H2 for x64-based Systems. Microsoft marks CVE-2025-55234 as publicly disclosed, without that disclosure alone changing the BlackTree action window.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- KB5065431
- Platform
- ESU
- Restart
- yes
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- CVE-2025-49734
- CVE-2025-53799
- CVE-2025-53800
- CVE-2025-53801
- CVE-2025-53802
- CVE-2025-53803
- CVE-2025-53804
- CVE-2025-53805
- CVE-2025-53807
- CVE-2025-53808
- CVE-2025-53810
- CVE-2025-54091
- CVE-2025-54092
- CVE-2025-54093
- CVE-2025-54094
- CVE-2025-54098
- CVE-2025-54099
- CVE-2025-54101
- CVE-2025-54102
- CVE-2025-54103
- CVE-2025-54104
- CVE-2025-54107
- CVE-2025-54109
- CVE-2025-54110
- CVE-2025-54111
- CVE-2025-54112
- CVE-2025-54114
- CVE-2025-54115
- CVE-2025-54116
- CVE-2025-54894
- CVE-2025-54895
- CVE-2025-54911
- CVE-2025-54912
- CVE-2025-54913
- CVE-2025-54915
- CVE-2025-54916
- CVE-2025-54917
- CVE-2025-54918
- CVE-2025-54919
- CVE-2025-55223
- CVE-2025-55224
- CVE-2025-55226
- CVE-2025-55228
- CVE-2025-55234
- CVE-2025-55236
MicrosoftDeploy Microsoft ESU security update KB5065435KB5065435 · Updated 2025-09-09Product and releaseWindows Server 2008 R2 for x64-based Systems Service Pack 1, Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation), Windows Server 2008 for 32-bit Systems Service Pack 2, plus 7 more1.000Review linked CVEs (2) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 2 linked CVEs for Windows Server 2008 R2 for x64-based Systems Service Pack 1, Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation), Windows Server 2008 for 32-bit Systems Service Pack 2, plus 7 more.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- KB5065435
- Platform
- ESU
- Restart
- yes
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
MicrosoftDeploy Microsoft ESU security update KB5065468KB5065468 · Updated 2025-09-09Product and releaseWindows Server 2008 R2 for x64-based Systems Service Pack 1, Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)6.1.7601.27929Review linked CVEs (30) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 30 linked CVEs for Windows Server 2008 R2 for x64-based Systems Service Pack 1, Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation). Microsoft marks CVE-2025-55234 as publicly disclosed, without that disclosure alone changing the BlackTree action window.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- KB5065468
- Platform
- ESU
- Restart
- yes
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- CVE-2025-53796
- CVE-2025-53797
- CVE-2025-53798
- CVE-2025-53799
- CVE-2025-53806
- CVE-2025-53808
- CVE-2025-53810
- CVE-2025-54093
- CVE-2025-54094
- CVE-2025-54095
- CVE-2025-54096
- CVE-2025-54097
- CVE-2025-54098
- CVE-2025-54099
- CVE-2025-54104
- CVE-2025-54107
- CVE-2025-54109
- CVE-2025-54110
- CVE-2025-54113
- CVE-2025-54894
- CVE-2025-54895
- CVE-2025-54911
- CVE-2025-54912
- CVE-2025-54915
- CVE-2025-54916
- CVE-2025-54917
- CVE-2025-54918
- CVE-2025-55225
- CVE-2025-55226
- CVE-2025-55234
MicrosoftDeploy Microsoft ESU security update KB5065507KB5065507 · Updated 2025-09-09Product and releaseWindows Server 2012 R2, Windows Server 2012 R2 (Server Core installation)6.3.9600.22774Review linked CVEs (35) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 35 linked CVEs for Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation). Microsoft marks CVE-2025-55234 as publicly disclosed, without that disclosure alone changing the BlackTree action window.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- KB5065507
- Platform
- ESU
- Restart
- yes
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- CVE-2025-53796
- CVE-2025-53797
- CVE-2025-53798
- CVE-2025-53799
- CVE-2025-53803
- CVE-2025-53804
- CVE-2025-53806
- CVE-2025-53808
- CVE-2025-53810
- CVE-2025-54091
- CVE-2025-54093
- CVE-2025-54094
- CVE-2025-54095
- CVE-2025-54096
- CVE-2025-54097
- CVE-2025-54098
- CVE-2025-54099
- CVE-2025-54101
- CVE-2025-54104
- CVE-2025-54106
- CVE-2025-54107
- CVE-2025-54109
- CVE-2025-54110
- CVE-2025-54113
- CVE-2025-54894
- CVE-2025-54895
- CVE-2025-54911
- CVE-2025-54912
- CVE-2025-54915
- CVE-2025-54916
- CVE-2025-54917
- CVE-2025-54918
- CVE-2025-55225
- CVE-2025-55226
- CVE-2025-55234
MicrosoftDeploy Microsoft ESU security update KB5065508KB5065508 · Updated 2025-09-09Product and releaseWindows Server 2008 for 32-bit Systems Service Pack 2, Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation), Windows Server 2008 for x64-based Systems Service Pack 2, plus 1 more6.0.6003.23529Review linked CVEs (26) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 26 linked CVEs for Windows Server 2008 for 32-bit Systems Service Pack 2, Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation), Windows Server 2008 for x64-based Systems Service Pack 2, plus 1 more. Microsoft marks CVE-2025-55234 as publicly disclosed, without that disclosure alone changing the BlackTree action window.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- KB5065508
- Platform
- ESU
- Restart
- yes
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- CVE-2025-53796
- CVE-2025-53797
- CVE-2025-53798
- CVE-2025-53799
- CVE-2025-53806
- CVE-2025-53808
- CVE-2025-53810
- CVE-2025-54093
- CVE-2025-54094
- CVE-2025-54095
- CVE-2025-54096
- CVE-2025-54097
- CVE-2025-54099
- CVE-2025-54104
- CVE-2025-54107
- CVE-2025-54109
- CVE-2025-54110
- CVE-2025-54113
- CVE-2025-54894
- CVE-2025-54915
- CVE-2025-54916
- CVE-2025-54917
- CVE-2025-54918
- CVE-2025-55225
- CVE-2025-55226
- CVE-2025-55234