Patch Tuesday cycleOctober 2025 Patch TuesdayComplete

Canonical Patch Tuesday catalogue

October 2025 Patch Tuesday catalogue.

Complete for the active Patch Tuesday cohort: Microsoft, Adobe and SAP. 129 operational patch records link 220 unique CVEs. No claim is made for vendors outside that cohort. Each row is one deployable update or vendor advisory with linked CVEs. BlackTree timing remains separate from CVSS and vendor severity.

129Patch recordsStable operational entries, not CVE duplicates
220Linked unique CVEsEvery CVE opens in BlackTree CVE Intelligence
16Accelerated actionsOut-of-band action
4Revised entriesCanonical history remains visible

October 2025 Patch Tuesday

Patch catalogue

Search and filters execute on the server. Each response is capped at the selected bounded page size, with a maximum of 100 compact patch rows.

Hide update groups
No groups hidden

Select every group you want removed from this view, its shared URL and its filtered exports.

Adobe
Microsoft
SAP
Several vendor and product groups can be hidden together.
Additional filtersProduct, platform, exploitation, restart, issues, date and cycle state
Reset filters
129 matching recordsPage 1 of 7
Selected PDF report0 of 20 visible records selectedSelect up to 20 approved records. Filter-hidden selections remain selected until cleared.
AdobeUpdate Adobe Substance 3D Modeler to the fixed Adobe releaseAPSB25-100 · Updated 2025-10-14
Product and releaseAdobe Substance 3D Modeler1.22.4
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

Adobe published APSB25-100 on Patch Tuesday for Adobe Substance 3D Modeler. The bulletin links 1 CVE and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB25-100
Platform
All
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 7.8; Adobe priority 3

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe Commerce to the fixed Adobe releaseAPSB25-94 · Updated 2025-10-14
Product and releaseAdobe Commerce2.4.9-alpha3 for 2.4.9-alpha2 2.4.8-p3 for 2.4.8-p2 and earlier 2.4.7-p8 for 2.4.7-p7 and earlier 2.4.6-p13 for 2.4.6-p12 and earlier 2.4.5-p15 for 2.4.5-p14 and earlier 2.4.4 p16 for 2.4.4-p15 and earlier, 1.5.3-alpha3 for 1.5.3-alpha2 1.5.2-p3 for 1.5.2-p2 and earlier 1.4.2-p8 for 1.4.2-p7 and earlier 1.3.4-p15 for 1.3.4-p14 and earlier 1.3.3-p14 for 1.3.3-p13 and earlier 1.3.3-p16 for 1.3.3-p15 and earlier, 2.4.9-alpha3 for 2.4.9-alpha2 2.4.8-p3 for 2.4.8-p2 and earlier 2.4.7-p8 for 2.4.7-p7 and earlier 2.4.6-p13 for 2.4.6-p12 and earlier
Review linked CVEs (5) No confirmed exploitation stated

Operational summary

Adobe published APSB25-94 on Patch Tuesday for Adobe Commerce. The bulletin links 5 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB25-94
Platform
All
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 8.1; Adobe priority 2

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (5)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 8.1
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe Experience Manager Screens to the fixed Adobe releaseAPSB25-98 · Updated 2025-10-14
Product and releaseAdobe Experience Manager ScreensAEM 6.5.22 Screens FP11.7
Review linked CVEs (3) No confirmed exploitation stated

Operational summary

Adobe published APSB25-98 on Patch Tuesday for Adobe Experience Manager Screens. The bulletin links 3 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB25-98
Platform
All
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important; CVSS 5.4; Adobe priority 3

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (3)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 5.4
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe Substance 3D Viewer to the fixed Adobe releaseAPSB25-99 · Updated 2025-10-14
Product and releaseAdobe Substance 3D Viewer0.25.3
Review linked CVEs (4) No confirmed exploitation stated

Operational summary

Adobe published APSB25-99 on Patch Tuesday for Adobe Substance 3D Viewer. The bulletin links 4 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB25-99
Platform
All
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 7.8; Adobe priority 3

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (4)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe FrameMaker to the fixed Adobe releaseAPSB25-101 · Updated 2025-10-14
Product and releaseAdobe FrameMakerFrameMaker 2020 Update 10, FrameMaker 2022 Update 8
Review linked CVEs (2) No confirmed exploitation stated

Operational summary

Adobe published APSB25-101 on Patch Tuesday for Adobe FrameMaker. The bulletin links 2 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB25-101
Platform
Windows
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 7.8; Adobe priority 3

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (2)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe Illustrator to the fixed Adobe releaseAPSB25-102 · Updated 2025-10-14
Product and releaseAdobe Illustrator29.8 and above, 28.7.10 and above
Review linked CVEs (2) No confirmed exploitation stated

Operational summary

Adobe published APSB25-102 on Patch Tuesday for Adobe Illustrator. The bulletin links 2 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB25-102
Platform
Windows and macOS
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 7.8; Adobe priority 3

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (2)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe Dimension to the fixed Adobe releaseAPSB25-103 · Updated 2025-10-14
Product and releaseAdobe Dimension4.1.5
Review linked CVEs (4) No confirmed exploitation stated

Operational summary

Adobe published APSB25-103 on Patch Tuesday for Adobe Dimension. The bulletin links 4 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB25-103
Platform
Windows and macOS
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 7.8; Adobe priority 3

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (4)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe Substance 3D Stager to the fixed Adobe releaseAPSB25-104 · Updated 2025-10-14
Product and releaseAdobe Substance 3D Stager3.1.5
Review linked CVEs (5) No confirmed exploitation stated

Operational summary

Adobe published APSB25-104 on Patch Tuesday for Adobe Substance 3D Stager. The bulletin links 5 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB25-104
Platform
Windows and macOS
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 7.8; Adobe priority 3

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (5)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe Connect to the fixed Adobe releaseAPSB25-70 · Updated 2025-10-14
Product and releaseAdobe Connect12.10
Review linked CVEs (3) No confirmed exploitation stated

Operational summary

Adobe published APSB25-70 on Patch Tuesday for Adobe Connect. The bulletin links 3 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB25-70
Platform
Windows and macOS
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 9.3; Adobe priority 3

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (3)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 9.3
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe Bridge to the fixed Adobe releaseAPSB25-96 · Updated 2025-10-14
Product and releaseAdobe Bridge14.1.9 (LTS), 15.1.2
Review linked CVEs (2) No confirmed exploitation stated

Operational summary

Adobe published APSB25-96 on Patch Tuesday for Adobe Bridge. The bulletin links 2 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB25-96
Platform
Windows and macOS
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 7.8

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (2)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe Animate to the fixed Adobe releaseAPSB25-97 · Updated 2025-10-14
Product and releaseAdobe Animate23.0.15, 24.0.12
Review linked CVEs (4) No confirmed exploitation stated

Operational summary

Adobe published APSB25-97 on Patch Tuesday for Adobe Animate. The bulletin links 4 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB25-97
Platform
Windows and macOS
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 7.8; Adobe priority 3

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (4)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe Creative Cloud Desktop to the fixed Adobe releaseAPSB25-95 · Updated 2025-10-14
Product and releaseAdobe Creative Cloud Desktop6.8.0.821
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

Adobe published APSB25-95 on Patch Tuesday for Adobe Creative Cloud Desktop. The bulletin links 1 CVE and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB25-95
Platform
macOS
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important; CVSS 5.6; Adobe priority 3

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 5.6
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Apps update for Xbox Gaming ServicesMSRC-2025-10-apps-store · Updated 2025-10-14
Product and releaseXbox Gaming Services31.105.17001.0
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for Xbox Gaming Services.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2025-10-apps-store
Platform
Apps
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Azure update for Arc Enabled Servers - Azure Connected Machine AgentMSRC-2025-10-azure-release-notes · Updated 2025-10-14
Product and releaseArc Enabled Servers - Azure Connected Machine Agent1.57
Review linked CVEs (2) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 2 linked CVEs for Arc Enabled Servers - Azure Connected Machine Agent.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2025-10-azure-release-notes
Platform
Azure
Restart
no
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (2)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Azure update for Azure Monitor AgentMSRC-2025-10-azure-release-notes · Updated 2025-10-14
Product and releaseAzure Monitor Agent1.36.3, 1.38.1.0
Review linked CVEs (2) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 2 linked CVEs for Azure Monitor Agent.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2025-10-azure-release-notes
Platform
Azure
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (2)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Developer Tools security update KB5066128KB5066128 · Updated 2025-10-14
Product and releaseMicrosoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 25H2 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 25H2 for x64-based Systems4.8.1.09321.01
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 25H2 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 25H2 for x64-based Systems.

Open official sourceCanonical detail record

Evidence and release

Advisory
KB5066128
Platform
Developer Tools
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 4.8
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Developer Tools security update KB5066129KB5066129 · Updated 2025-10-14
Product and releaseMicrosoft .NET Framework 3.5 AND 4.8.1 on Windows Server 2022, 23H2 Edition (Server Core installation)4.8.1.09321.01
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft .NET Framework 3.5 AND 4.8.1 on Windows Server 2022, 23H2 Edition (Server Core installation).

Open official sourceCanonical detail record

Evidence and release

Advisory
KB5066129
Platform
Developer Tools
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 4.8
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Developer Tools security update KB5066131KB5066131 · Updated 2025-10-14
Product and releaseMicrosoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 24H2 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 24H2 for x64-based Systems4.8.1.09321.01
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 24H2 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 24H2 for x64-based Systems.

Open official sourceCanonical detail record

Evidence and release

Advisory
KB5066131
Platform
Developer Tools
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 4.8
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Developer Tools security update KB5066133KB5066133 · Updated 2025-10-14
Product and releaseMicrosoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 22H2 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 22H2 for x64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 23H2 for ARM64-based Systems, plus 1 more4.8.1.09321.01
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 22H2 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 22H2 for x64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 23H2 for ARM64-based Systems, plus 1 more.

Open official sourceCanonical detail record

Evidence and release

Advisory
KB5066133
Platform
Developer Tools
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 4.8
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Developer Tools security update KB5066136KB5066136 · Updated 2025-10-14
Product and releaseMicrosoft .NET Framework 4.8 on Windows 10 Version 1607 for 32-bit Systems, Microsoft .NET Framework 4.8 on Windows 10 Version 1607 for x64-based Systems, Microsoft .NET Framework 4.8 on Windows Server 2016, plus 1 more4.8.04798.02
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft .NET Framework 4.8 on Windows 10 Version 1607 for 32-bit Systems, Microsoft .NET Framework 4.8 on Windows 10 Version 1607 for x64-based Systems, Microsoft .NET Framework 4.8 on Windows Server 2016, plus 1 more.

Open official sourceCanonical detail record

Evidence and release

Advisory
KB5066136
Platform
Developer Tools
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 4.8
Confirmed exploitedCVSS above 9.0