Patch Tuesday cycleNovember 2025 Patch TuesdayComplete

Canonical Patch Tuesday catalogue

November 2025 Patch Tuesday catalogue.

Complete for the active Patch Tuesday cohort: Microsoft, Adobe and SAP. 105 operational patch records link 103 unique CVEs. No claim is made for vendors outside that cohort. Each row is one deployable update or vendor advisory with linked CVEs. BlackTree timing remains separate from CVSS and vendor severity.

105Patch recordsStable operational entries, not CVE duplicates
103Linked unique CVEsEvery CVE opens in BlackTree CVE Intelligence
9Accelerated actionsOut-of-band action
2Revised entriesCanonical history remains visible

November 2025 Patch Tuesday

Patch catalogue

Search and filters execute on the server. Each response is capped at the selected bounded page size, with a maximum of 100 compact patch rows.

Hide update groups
No groups hidden

Select every group you want removed from this view, its shared URL and its filtered exports.

Adobe
Microsoft
SAP
Several vendor and product groups can be hidden together.
Additional filtersProduct, platform, exploitation, restart, issues, date and cycle state
Reset filters
105 matching recordsPage 1 of 6
Selected PDF report0 of 20 visible records selectedSelect up to 20 approved records. Filter-hidden selections remain selected until cleared.
AdobeUpdate Adobe Photoshop to the fixed Adobe releaseAPSB25-108 · Updated 2025-11-11
Product and releaseAdobe PhotoshopFixed release detail requires source review
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

Adobe published APSB25-108 on Patch Tuesday for Adobe Photoshop. The bulletin links 1 CVE and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB25-108
Platform
See Adobe bulletin
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 7.8

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe InDesign to the fixed Adobe releaseAPSB25-106 · Updated 2025-11-11
Product and releaseAdobe InDesignID21.0, ID20.5.1
Review linked CVEs (4) No confirmed exploitation stated

Operational summary

Adobe published APSB25-106 on Patch Tuesday for Adobe InDesign. The bulletin links 4 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB25-106
Platform
Windows and macOS
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 7.8; Adobe priority 3

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (4)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe InCopy to the fixed Adobe releaseAPSB25-107 · Updated 2025-11-11
Product and releaseAdobe InCopy21.0, 20.5.1
Review linked CVEs (3) No confirmed exploitation stated

Operational summary

Adobe published APSB25-107 on Patch Tuesday for Adobe InCopy. The bulletin links 3 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB25-107
Platform
Windows and macOS
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 7.8; Adobe priority 3

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (3)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe Illustrator to the fixed Adobe releaseAPSB25-109 · Updated 2025-11-11
Product and releaseAdobe Illustrator29.8.3 and above, 30.0 and above
Review linked CVEs (2) No confirmed exploitation stated

Operational summary

Adobe published APSB25-109 on Patch Tuesday for Adobe Illustrator. The bulletin links 2 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB25-109
Platform
Windows and macOS
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 7.8; Adobe priority 3

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (2)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe Substance 3D Stager to the fixed Adobe releaseAPSB25-113 · Updated 2025-11-11
Product and releaseAdobe Substance 3D Stager3.1.6
Review linked CVEs (4) No confirmed exploitation stated

Operational summary

Adobe published APSB25-113 on Patch Tuesday for Adobe Substance 3D Stager. The bulletin links 4 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB25-113
Platform
Windows and macOS
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 7.8; Adobe priority 3

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (4)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe Illustrator Mobile to the fixed Adobe releaseAPSB25-111 · Updated 2025-11-11
Product and releaseAdobe Illustrator Mobile3.0.10
Review linked CVEs (5) No confirmed exploitation stated

Operational summary

Adobe published APSB25-111 on Patch Tuesday for Adobe Illustrator Mobile. The bulletin links 5 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB25-111
Platform
iOS
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 7.8; Adobe priority 3

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (5)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Azure update for Azure MonitorMSRC-2025-11-azure-release-notes · Updated 2025-11-11
Product and releaseAzure Monitorv1.37.1
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for Azure Monitor.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2025-11-azure-release-notes
Platform
Azure
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.3
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Developer Tools update for Microsoft Visual Studio 2022 version 17.14MSRC-2025-11-developer-tools-release-notes · Updated 2025-11-11
Product and releaseMicrosoft Visual Studio 2022 version 17.1417.14.17
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft Visual Studio 2022 version 17.14.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2025-11-developer-tools-release-notes
Platform
Developer Tools
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 6.7
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Developer Tools update for Microsoft Visual Studio Code CoPilot Chat ExtensionMSRC-2025-11-developer-tools-release-notes · Updated 2025-11-11
Product and releaseMicrosoft Visual Studio Code CoPilot Chat Extension0.32.5
Review linked CVEs (2) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 2 linked CVEs for Microsoft Visual Studio Code CoPilot Chat Extension.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2025-11-developer-tools-release-notes
Platform
Developer Tools
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (2)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 8.8
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Developer Tools update for Visual Studio CodeMSRC-2025-11-developer-tools-release-notes · Updated 2025-11-11
Product and releaseVisual Studio Code1.105.0
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for Visual Studio Code.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2025-11-developer-tools-release-notes
Platform
Developer Tools
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 5.0
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft ESU security update KB5066791KB5066791 · Updated 2025-11-11
Product and releaseWindows 10 Version 22H2 for 32-bit Systems, Windows 10 Version 22H2 for ARM64-based Systems, Windows 10 Version 22H2 for x64-based Systems10.0.19045.6456
Review linked CVEs (2) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 2 linked CVEs for Windows 10 Version 22H2 for 32-bit Systems, Windows 10 Version 22H2 for ARM64-based Systems, Windows 10 Version 22H2 for x64-based Systems.

Open official sourceCanonical detail record

Evidence and release

Advisory
KB5066791
Platform
ESU
Restart
yes
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
Vendor-linked CVEs (2)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 5.5
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft ESU security update KB5066793KB5066793 · Updated 2025-11-11
Product and releaseWindows 11 Version 22H2 for ARM64-based Systems, Windows 11 Version 22H2 for x64-based Systems10.0.22621.6060
Review linked CVEs (2) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 2 linked CVEs for Windows 11 Version 22H2 for ARM64-based Systems, Windows 11 Version 22H2 for x64-based Systems.

Open official sourceCanonical detail record

Evidence and release

Advisory
KB5066793
Platform
ESU
Restart
yes
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
Vendor-linked CVEs (2)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 5.5
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft ESU security update KB5068781KB5068781 · Updated 2025-11-11
Product and releaseWindows 10 Version 22H2 for 32-bit Systems, Windows 10 Version 22H2 for ARM64-based Systems, Windows 10 Version 22H2 for x64-based Systems10.0.19045.6575
Review linked CVEs (32) Confirmed exploitation

Operational summary

This official Microsoft Patch Tuesday update addresses 32 linked CVEs for Windows 10 Version 22H2 for 32-bit Systems, Windows 10 Version 22H2 for ARM64-based Systems, Windows 10 Version 22H2 for x64-based Systems. Microsoft reports exploitation for CVE-2025-62215.

Open official sourceCanonical detail record

Evidence and release

Advisory
KB5068781
Platform
ESU
Restart
yes
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Active Exploitation Confirmed

Vendor signal: Critical

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
MicrosoftDeploy Microsoft ESU security update KB5068904KB5068904 · Updated 2025-11-11
Product and releaseWindows Server 2008 R2 for x64-based Systems Service Pack 1, Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)6.1.7601.28021
Review linked CVEs (14) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 14 linked CVEs for Windows Server 2008 R2 for x64-based Systems Service Pack 1, Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation).

Open official sourceCanonical detail record

Evidence and release

Advisory
KB5068904
Platform
ESU
Restart
yes
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
MicrosoftDeploy Microsoft ESU security update KB5068905KB5068905 · Updated 2025-11-11
Product and releaseWindows Server 2012 R2, Windows Server 2012 R2 (Server Core installation)6.3.9600.22869
Review linked CVEs (17) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 17 linked CVEs for Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation).

Open official sourceCanonical detail record

Evidence and release

Advisory
KB5068905
Platform
ESU
Restart
yes
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
MicrosoftDeploy Microsoft ESU security update KB5068906KB5068906 · Updated 2025-11-11
Product and releaseWindows Server 2008 for 32-bit Systems Service Pack 2, Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation), Windows Server 2008 for x64-based Systems Service Pack 2, plus 1 more6.0.6003.23624
Review linked CVEs (14) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 14 linked CVEs for Windows Server 2008 for 32-bit Systems Service Pack 2, Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation), Windows Server 2008 for x64-based Systems Service Pack 2, plus 1 more.

Open official sourceCanonical detail record

Evidence and release

Advisory
KB5068906
Platform
ESU
Restart
yes
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
MicrosoftDeploy Microsoft ESU security update KB5068907KB5068907 · Updated 2025-11-11
Product and releaseWindows Server 2012, Windows Server 2012 (Server Core installation)6.2.9200.25768
Review linked CVEs (16) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 16 linked CVEs for Windows Server 2012, Windows Server 2012 (Server Core installation).

Open official sourceCanonical detail record

Evidence and release

Advisory
KB5068907
Platform
ESU
Restart
yes
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
MicrosoftDeploy Microsoft ESU security update KB5068908KB5068908 · Updated 2025-11-11
Product and releaseWindows Server 2008 R2 for x64-based Systems Service Pack 1, Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)6.1.7601.28021
Review linked CVEs (14) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 14 linked CVEs for Windows Server 2008 R2 for x64-based Systems Service Pack 1, Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation).

Open official sourceCanonical detail record

Evidence and release

Advisory
KB5068908
Platform
ESU
Restart
yes
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
MicrosoftDeploy Microsoft ESU security update KB5068909KB5068909 · Updated 2025-11-11
Product and releaseWindows Server 2008 for 32-bit Systems Service Pack 2, Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation), Windows Server 2008 for x64-based Systems Service Pack 2, plus 1 more6.0.6003.23624
Review linked CVEs (14) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 14 linked CVEs for Windows Server 2008 for 32-bit Systems Service Pack 2, Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation), Windows Server 2008 for x64-based Systems Service Pack 2, plus 1 more.

Open official sourceCanonical detail record

Evidence and release

Advisory
KB5068909
Platform
ESU
Restart
yes
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
MicrosoftDeploy Microsoft Microsoft Dynamics security update KB5067331KB5067331 · Updated 2025-11-11
Product and releaseMicrosoft Dynamics 365 (on-premises) version 9.19.1.41.07
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft Dynamics 365 (on-premises) version 9.1.

Open official sourceCanonical detail record

Evidence and release

Advisory
KB5067331
Platform
Microsoft Dynamics
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 6.5
Confirmed exploitedCVSS above 9.0