BlackTreeCVE IntelligenceCanonical Patch Tuesday catalogue
October 2025 Patch Tuesday catalogue.
Complete for the active Patch Tuesday cohort: Microsoft, Adobe and SAP. 129 operational patch records link 220 unique CVEs. No claim is made for vendors outside that cohort. Each row is one deployable update or vendor advisory with linked CVEs. BlackTree timing remains separate from CVSS and vendor severity.
October 2025 Patch Tuesday
Patch catalogue
Search and filters execute on the server. Each response is capped at the selected bounded page size, with a maximum of 100 compact patch rows.
AdobeUpdate Adobe Substance 3D Modeler to the fixed Adobe releaseAPSB25-100 · Updated 2025-10-14Product and releaseAdobe Substance 3D Modeler1.22.4Review linked CVEs (1) No confirmed exploitation stated
Operational summary
Adobe published APSB25-100 on Patch Tuesday for Adobe Substance 3D Modeler. The bulletin links 1 CVE and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB25-100
- Platform
- All
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 7.8; Adobe priority 3
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe Commerce to the fixed Adobe releaseAPSB25-94 · Updated 2025-10-14Product and releaseAdobe Commerce2.4.9-alpha3 for 2.4.9-alpha2 2.4.8-p3 for 2.4.8-p2 and earlier 2.4.7-p8 for 2.4.7-p7 and earlier 2.4.6-p13 for 2.4.6-p12 and earlier 2.4.5-p15 for 2.4.5-p14 and earlier 2.4.4 p16 for 2.4.4-p15 and earlier, 1.5.3-alpha3 for 1.5.3-alpha2 1.5.2-p3 for 1.5.2-p2 and earlier 1.4.2-p8 for 1.4.2-p7 and earlier 1.3.4-p15 for 1.3.4-p14 and earlier 1.3.3-p14 for 1.3.3-p13 and earlier 1.3.3-p16 for 1.3.3-p15 and earlier, 2.4.9-alpha3 for 2.4.9-alpha2 2.4.8-p3 for 2.4.8-p2 and earlier 2.4.7-p8 for 2.4.7-p7 and earlier 2.4.6-p13 for 2.4.6-p12 and earlierReview linked CVEs (5) No confirmed exploitation stated
Operational summary
Adobe published APSB25-94 on Patch Tuesday for Adobe Commerce. The bulletin links 5 CVEs and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB25-94
- Platform
- All
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 8.1; Adobe priority 2
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe Experience Manager Screens to the fixed Adobe releaseAPSB25-98 · Updated 2025-10-14Product and releaseAdobe Experience Manager ScreensAEM 6.5.22 Screens FP11.7Review linked CVEs (3) No confirmed exploitation stated
Operational summary
Adobe published APSB25-98 on Patch Tuesday for Adobe Experience Manager Screens. The bulletin links 3 CVEs and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB25-98
- Platform
- All
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important; CVSS 5.4; Adobe priority 3
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe Substance 3D Viewer to the fixed Adobe releaseAPSB25-99 · Updated 2025-10-14Product and releaseAdobe Substance 3D Viewer0.25.3Review linked CVEs (4) No confirmed exploitation stated
Operational summary
Adobe published APSB25-99 on Patch Tuesday for Adobe Substance 3D Viewer. The bulletin links 4 CVEs and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB25-99
- Platform
- All
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 7.8; Adobe priority 3
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe FrameMaker to the fixed Adobe releaseAPSB25-101 · Updated 2025-10-14Product and releaseAdobe FrameMakerFrameMaker 2020 Update 10, FrameMaker 2022 Update 8Review linked CVEs (2) No confirmed exploitation stated
Operational summary
Adobe published APSB25-101 on Patch Tuesday for Adobe FrameMaker. The bulletin links 2 CVEs and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB25-101
- Platform
- Windows
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 7.8; Adobe priority 3
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe Illustrator to the fixed Adobe releaseAPSB25-102 · Updated 2025-10-14Product and releaseAdobe Illustrator29.8 and above, 28.7.10 and aboveReview linked CVEs (2) No confirmed exploitation stated
Operational summary
Adobe published APSB25-102 on Patch Tuesday for Adobe Illustrator. The bulletin links 2 CVEs and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB25-102
- Platform
- Windows and macOS
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 7.8; Adobe priority 3
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe Dimension to the fixed Adobe releaseAPSB25-103 · Updated 2025-10-14Product and releaseAdobe Dimension4.1.5Review linked CVEs (4) No confirmed exploitation stated
Operational summary
Adobe published APSB25-103 on Patch Tuesday for Adobe Dimension. The bulletin links 4 CVEs and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB25-103
- Platform
- Windows and macOS
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 7.8; Adobe priority 3
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe Substance 3D Stager to the fixed Adobe releaseAPSB25-104 · Updated 2025-10-14Product and releaseAdobe Substance 3D Stager3.1.5Review linked CVEs (5) No confirmed exploitation stated
Operational summary
Adobe published APSB25-104 on Patch Tuesday for Adobe Substance 3D Stager. The bulletin links 5 CVEs and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB25-104
- Platform
- Windows and macOS
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 7.8; Adobe priority 3
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe Connect to the fixed Adobe releaseAPSB25-70 · Updated 2025-10-14Product and releaseAdobe Connect12.10Review linked CVEs (3) No confirmed exploitation stated
Operational summary
Adobe published APSB25-70 on Patch Tuesday for Adobe Connect. The bulletin links 3 CVEs and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB25-70
- Platform
- Windows and macOS
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 9.3; Adobe priority 3
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe Bridge to the fixed Adobe releaseAPSB25-96 · Updated 2025-10-14Product and releaseAdobe Bridge14.1.9 (LTS), 15.1.2Review linked CVEs (2) No confirmed exploitation stated
Operational summary
Adobe published APSB25-96 on Patch Tuesday for Adobe Bridge. The bulletin links 2 CVEs and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB25-96
- Platform
- Windows and macOS
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 7.8
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe Animate to the fixed Adobe releaseAPSB25-97 · Updated 2025-10-14Product and releaseAdobe Animate23.0.15, 24.0.12Review linked CVEs (4) No confirmed exploitation stated
Operational summary
Adobe published APSB25-97 on Patch Tuesday for Adobe Animate. The bulletin links 4 CVEs and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB25-97
- Platform
- Windows and macOS
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 7.8; Adobe priority 3
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe Creative Cloud Desktop to the fixed Adobe releaseAPSB25-95 · Updated 2025-10-14Product and releaseAdobe Creative Cloud Desktop6.8.0.821Review linked CVEs (1) No confirmed exploitation stated
Operational summary
Adobe published APSB25-95 on Patch Tuesday for Adobe Creative Cloud Desktop. The bulletin links 1 CVE and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB25-95
- Platform
- macOS
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important; CVSS 5.6; Adobe priority 3
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
MicrosoftDeploy Microsoft Apps update for Xbox Gaming ServicesMSRC-2025-10-apps-store · Updated 2025-10-14Product and releaseXbox Gaming Services31.105.17001.0Review linked CVEs (1) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 1 linked CVE for Xbox Gaming Services.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- MSRC-2025-10-apps-store
- Platform
- Apps
- Restart
- varies by product
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- This update uses vendor release notes or a fixed build instead of a standalone KB identity.
MicrosoftDeploy Microsoft Azure update for Arc Enabled Servers - Azure Connected Machine AgentMSRC-2025-10-azure-release-notes · Updated 2025-10-14Product and releaseArc Enabled Servers - Azure Connected Machine Agent1.57Review linked CVEs (2) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 2 linked CVEs for Arc Enabled Servers - Azure Connected Machine Agent.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- MSRC-2025-10-azure-release-notes
- Platform
- Azure
- Restart
- no
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- This update uses vendor release notes or a fixed build instead of a standalone KB identity.
MicrosoftDeploy Microsoft Azure update for Azure Monitor AgentMSRC-2025-10-azure-release-notes · Updated 2025-10-14Product and releaseAzure Monitor Agent1.36.3, 1.38.1.0Review linked CVEs (2) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 2 linked CVEs for Azure Monitor Agent.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- MSRC-2025-10-azure-release-notes
- Platform
- Azure
- Restart
- varies by product
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- This update uses vendor release notes or a fixed build instead of a standalone KB identity.
MicrosoftDeploy Microsoft Developer Tools security update KB5066128KB5066128 · Updated 2025-10-14Product and releaseMicrosoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 25H2 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 25H2 for x64-based Systems4.8.1.09321.01Review linked CVEs (1) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 25H2 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 25H2 for x64-based Systems.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- KB5066128
- Platform
- Developer Tools
- Restart
- varies by product
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
MicrosoftDeploy Microsoft Developer Tools security update KB5066129KB5066129 · Updated 2025-10-14Product and releaseMicrosoft .NET Framework 3.5 AND 4.8.1 on Windows Server 2022, 23H2 Edition (Server Core installation)4.8.1.09321.01Review linked CVEs (1) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft .NET Framework 3.5 AND 4.8.1 on Windows Server 2022, 23H2 Edition (Server Core installation).
Open official sourceCanonical detail recordEvidence and release
- Advisory
- KB5066129
- Platform
- Developer Tools
- Restart
- varies by product
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
MicrosoftDeploy Microsoft Developer Tools security update KB5066131KB5066131 · Updated 2025-10-14Product and releaseMicrosoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 24H2 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 24H2 for x64-based Systems4.8.1.09321.01Review linked CVEs (1) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 24H2 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 24H2 for x64-based Systems.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- KB5066131
- Platform
- Developer Tools
- Restart
- varies by product
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
MicrosoftDeploy Microsoft Developer Tools security update KB5066133KB5066133 · Updated 2025-10-14Product and releaseMicrosoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 22H2 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 22H2 for x64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 23H2 for ARM64-based Systems, plus 1 more4.8.1.09321.01Review linked CVEs (1) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 22H2 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 22H2 for x64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 23H2 for ARM64-based Systems, plus 1 more.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- KB5066133
- Platform
- Developer Tools
- Restart
- varies by product
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
MicrosoftDeploy Microsoft Developer Tools security update KB5066136KB5066136 · Updated 2025-10-14Product and releaseMicrosoft .NET Framework 4.8 on Windows 10 Version 1607 for 32-bit Systems, Microsoft .NET Framework 4.8 on Windows 10 Version 1607 for x64-based Systems, Microsoft .NET Framework 4.8 on Windows Server 2016, plus 1 more4.8.04798.02Review linked CVEs (1) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft .NET Framework 4.8 on Windows 10 Version 1607 for 32-bit Systems, Microsoft .NET Framework 4.8 on Windows 10 Version 1607 for x64-based Systems, Microsoft .NET Framework 4.8 on Windows Server 2016, plus 1 more.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- KB5066136
- Platform
- Developer Tools
- Restart
- varies by product
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.