BlackTreeCVE IntelligenceCanonical Patch Tuesday catalogue
December 2025 Patch Tuesday catalogue.
Complete for the active Patch Tuesday cohort: Microsoft, Adobe and SAP. 86 operational patch records link 211 unique CVEs. No claim is made for vendors outside that cohort. Each row is one deployable update or vendor advisory with linked CVEs. BlackTree timing remains separate from CVSS and vendor severity.
December 2025 Patch Tuesday
Patch catalogue
Search and filters execute on the server. Each response is capped at the selected bounded page size, with a maximum of 100 compact patch rows.
AdobeUpdate Adobe ColdFusion to the fixed Adobe releaseAPSB25-105 · Updated 2025-12-09Product and releaseAdobe ColdFusionUpdate 5, Update 17, Update 23Review linked CVEs (12) No confirmed exploitation stated
Operational summary
Adobe published APSB25-105 on Patch Tuesday for Adobe ColdFusion. The bulletin links 12 CVEs and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB25-105
- Platform
- All
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 9.1; Adobe priority 1
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe Experience Manager to the fixed Adobe releaseAPSB25-115 · Updated 2025-12-09Product and releaseAdobe Experience ManagerAEM Cloud Service Release 2025.12, 6.5 LTS SP1 (GRANITE-61551 Hotfix), 6.5.24Review linked CVEs (117) No confirmed exploitation stated
Operational summary
Adobe published APSB25-115 on Patch Tuesday for Adobe Experience Manager. The bulletin links 117 CVEs and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB25-115
- Platform
- All
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 9.3; Adobe priority 3
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
- CVE-2025-64537
- CVE-2025-64538
- CVE-2025-64539
- CVE-2025-64541
- CVE-2025-64542
- CVE-2025-64543
- CVE-2025-64544
- CVE-2025-64545
- CVE-2025-64546
- CVE-2025-64547
- CVE-2025-64548
- CVE-2025-64549
- CVE-2025-64550
- CVE-2025-64551
- CVE-2025-64552
- CVE-2025-64553
- CVE-2025-64554
- CVE-2025-64555
- CVE-2025-64556
- CVE-2025-64557
- CVE-2025-64558
- CVE-2025-64559
- CVE-2025-64560
- CVE-2025-64562
- CVE-2025-64563
- CVE-2025-64564
- CVE-2025-64565
- CVE-2025-64569
- CVE-2025-64572
- CVE-2025-64574
- CVE-2025-64575
- CVE-2025-64576
- CVE-2025-64577
- CVE-2025-64578
- CVE-2025-64579
- CVE-2025-64580
- CVE-2025-64581
- CVE-2025-64582
- CVE-2025-64583
- CVE-2025-64585
- CVE-2025-64586
- CVE-2025-64590
- CVE-2025-64591
- CVE-2025-64592
- CVE-2025-64593
- CVE-2025-64594
- CVE-2025-64596
- CVE-2025-64597
- CVE-2025-64598
- CVE-2025-64599
- CVE-2025-64600
- CVE-2025-64601
- CVE-2025-64602
- CVE-2025-64603
- CVE-2025-64604
- CVE-2025-64605
- CVE-2025-64606
- CVE-2025-64607
- CVE-2025-64609
- CVE-2025-64610
- CVE-2025-64611
- CVE-2025-64612
- CVE-2025-64614
- CVE-2025-64615
- CVE-2025-64616
- CVE-2025-64619
- CVE-2025-64620
- CVE-2025-64622
- CVE-2025-64623
- CVE-2025-64626
- CVE-2025-64627
- CVE-2025-64789
- CVE-2025-64790
- CVE-2025-64791
- CVE-2025-64792
- CVE-2025-64793
- CVE-2025-64794
- CVE-2025-64796
- CVE-2025-64797
- CVE-2025-64799
- CVE-2025-64800
- CVE-2025-64801
- CVE-2025-64802
- CVE-2025-64803
- CVE-2025-64804
- CVE-2025-64808
- CVE-2025-64814
- CVE-2025-64817
- CVE-2025-64820
- CVE-2025-64821
- CVE-2025-64822
- CVE-2025-64823
- CVE-2025-64825
- CVE-2025-64826
- CVE-2025-64827
- CVE-2025-64829
- CVE-2025-64833
- CVE-2025-64839
- CVE-2025-64840
- CVE-2025-64841
- CVE-2025-64845
- CVE-2025-64847
- CVE-2025-64850
- CVE-2025-64852
- CVE-2025-64853
- CVE-2025-64857
- CVE-2025-64858
- CVE-2025-64860
- CVE-2025-64861
- CVE-2025-64863
- CVE-2025-64869
- CVE-2025-64872
- CVE-2025-64873
- CVE-2025-64875
- CVE-2025-64881
- CVE-2025-64887
- CVE-2025-64888
AdobeUpdate Adobe Acrobat Reader to the fixed Adobe releaseAPSB25-119 · Updated 2025-12-09Product and releaseAdobe Acrobat ReaderFixed release detail requires source reviewReview linked CVEs (4) No confirmed exploitation stated
Operational summary
Adobe published APSB25-119 on Patch Tuesday for Adobe Acrobat Reader. The bulletin links 4 CVEs and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB25-119
- Platform
- See Adobe bulletin
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 7.8
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe DNG SDK to the fixed Adobe releaseAPSB25-118 · Updated 2025-12-09Product and releaseAdobe DNG SDKDNG SDK 1.7.1 build 2410Review linked CVEs (4) No confirmed exploitation stated
Operational summary
Adobe published APSB25-118 on Patch Tuesday for Adobe DNG SDK. The bulletin links 4 CVEs and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB25-118
- Platform
- Windows and macOS
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 7.8; Adobe priority 3
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe Creative Cloud Desktop to the fixed Adobe releaseAPSB25-120 · Updated 2025-12-09Product and releaseAdobe Creative Cloud Desktop6.8.0.821Review linked CVEs (1) No confirmed exploitation stated
Operational summary
Adobe published APSB25-120 on Patch Tuesday for Adobe Creative Cloud Desktop. The bulletin links 1 CVE and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB25-120
- Platform
- macOS
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important; CVSS 5.0; Adobe priority 3
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
MicrosoftDeploy Microsoft Azure update for Azure Monitor AgentMSRC-2025-12-azure-release-notes · Updated 2025-12-09Product and releaseAzure Monitor Agent1.35.9Review linked CVEs (1) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 1 linked CVE for Azure Monitor Agent.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- MSRC-2025-12-azure-release-notes
- Platform
- Azure
- Restart
- no
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- This update uses vendor release notes or a fixed build instead of a standalone KB identity.
MicrosoftDeploy Microsoft ESU security update KB5066791KB5066791 · Updated 2025-12-09Product and releaseWindows 10 Version 22H2 for 32-bit Systems, Windows 10 Version 22H2 for ARM64-based Systems, Windows 10 Version 22H2 for x64-based Systems10.0.19045.6456Review linked CVEs (2) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 2 linked CVEs for Windows 10 Version 22H2 for 32-bit Systems, Windows 10 Version 22H2 for ARM64-based Systems, Windows 10 Version 22H2 for x64-based Systems.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- KB5066791
- Platform
- ESU
- Restart
- yes
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
MicrosoftDeploy Microsoft ESU security update KB5066793KB5066793 · Updated 2025-12-09Product and releaseWindows 11 Version 22H2 for ARM64-based Systems, Windows 11 Version 22H2 for x64-based Systems10.0.22621.6060Review linked CVEs (2) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 2 linked CVEs for Windows 11 Version 22H2 for ARM64-based Systems, Windows 11 Version 22H2 for x64-based Systems.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- KB5066793
- Platform
- ESU
- Restart
- yes
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
MicrosoftDeploy Microsoft ESU security update KB5068781KB5068781 · Updated 2025-12-09Product and releaseWindows 10 Version 22H2 for 32-bit Systems, Windows 10 Version 22H2 for ARM64-based Systems, Windows 10 Version 22H2 for x64-based Systems10.0.19045.6575Review linked CVEs (1) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 1 linked CVE for Windows 10 Version 22H2 for 32-bit Systems, Windows 10 Version 22H2 for ARM64-based Systems, Windows 10 Version 22H2 for x64-based Systems.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- KB5068781
- Platform
- ESU
- Restart
- yes
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
MicrosoftDeploy Microsoft ESU security update KB5068904KB5068904 · Updated 2025-12-09Product and releaseWindows Server 2008 R2 for x64-based Systems Service Pack 1, Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)6.1.7601.28021Review linked CVEs (1) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 1 linked CVE for Windows Server 2008 R2 for x64-based Systems Service Pack 1, Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation).
Open official sourceCanonical detail recordEvidence and release
- Advisory
- KB5068904
- Platform
- ESU
- Restart
- yes
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
MicrosoftDeploy Microsoft ESU security update KB5068905KB5068905 · Updated 2025-12-09Product and releaseWindows Server 2012 R2, Windows Server 2012 R2 (Server Core installation)6.3.9600.22869Review linked CVEs (1) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 1 linked CVE for Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation).
Open official sourceCanonical detail recordEvidence and release
- Advisory
- KB5068905
- Platform
- ESU
- Restart
- yes
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
MicrosoftDeploy Microsoft ESU security update KB5068906KB5068906 · Updated 2025-12-09Product and releaseWindows Server 2008 for 32-bit Systems Service Pack 2, Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation), Windows Server 2008 for x64-based Systems Service Pack 2, plus 1 more6.0.6003.23624Review linked CVEs (1) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 1 linked CVE for Windows Server 2008 for 32-bit Systems Service Pack 2, Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation), Windows Server 2008 for x64-based Systems Service Pack 2, plus 1 more.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- KB5068906
- Platform
- ESU
- Restart
- yes
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
MicrosoftDeploy Microsoft ESU security update KB5068907KB5068907 · Updated 2025-12-09Product and releaseWindows Server 2012, Windows Server 2012 (Server Core installation)6.2.9200.25768Review linked CVEs (1) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 1 linked CVE for Windows Server 2012, Windows Server 2012 (Server Core installation).
Open official sourceCanonical detail recordEvidence and release
- Advisory
- KB5068907
- Platform
- ESU
- Restart
- yes
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
MicrosoftDeploy Microsoft ESU security update KB5068908KB5068908 · Updated 2025-12-09Product and releaseWindows Server 2008 R2 for x64-based Systems Service Pack 1, Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)6.1.7601.28021Review linked CVEs (1) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 1 linked CVE for Windows Server 2008 R2 for x64-based Systems Service Pack 1, Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation).
Open official sourceCanonical detail recordEvidence and release
- Advisory
- KB5068908
- Platform
- ESU
- Restart
- yes
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
MicrosoftDeploy Microsoft ESU security update KB5068909KB5068909 · Updated 2025-12-09Product and releaseWindows Server 2008 for 32-bit Systems Service Pack 2, Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation), Windows Server 2008 for x64-based Systems Service Pack 2, plus 1 more6.0.6003.23624Review linked CVEs (1) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 1 linked CVE for Windows Server 2008 for 32-bit Systems Service Pack 2, Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation), Windows Server 2008 for x64-based Systems Service Pack 2, plus 1 more.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- KB5068909
- Platform
- ESU
- Restart
- yes
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
MicrosoftDeploy Microsoft ESU security update KB5071501KB5071501 · Updated 2025-12-09Product and releaseWindows Server 2008 R2 for x64-based Systems Service Pack 1, Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)6.1.7601.28064Review linked CVEs (10) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 10 linked CVEs for Windows Server 2008 R2 for x64-based Systems Service Pack 1, Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation). Microsoft marks CVE-2025-54100 as publicly disclosed, without that disclosure alone changing the BlackTree action window.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- KB5071501
- Platform
- ESU
- Restart
- yes
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
MicrosoftDeploy Microsoft ESU security update KB5071503KB5071503 · Updated 2025-12-09Product and releaseWindows Server 2012 R2, Windows Server 2012 R2 (Server Core installation)6.3.9600.22920Review linked CVEs (11) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 11 linked CVEs for Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation). Microsoft marks CVE-2025-54100 as publicly disclosed, without that disclosure alone changing the BlackTree action window.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- KB5071503
- Platform
- ESU
- Restart
- yes
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
MicrosoftDeploy Microsoft ESU security update KB5071504KB5071504 · Updated 2025-12-09Product and releaseWindows Server 2008 for 32-bit Systems Service Pack 2, Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation), Windows Server 2008 for x64-based Systems Service Pack 2, plus 1 more6.0.6003.23666Review linked CVEs (8) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 8 linked CVEs for Windows Server 2008 for 32-bit Systems Service Pack 2, Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation), Windows Server 2008 for x64-based Systems Service Pack 2, plus 1 more. Microsoft marks CVE-2025-54100 as publicly disclosed, without that disclosure alone changing the BlackTree action window.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- KB5071504
- Platform
- ESU
- Restart
- yes
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
MicrosoftDeploy Microsoft ESU security update KB5071505KB5071505 · Updated 2025-12-09Product and releaseWindows Server 2012, Windows Server 2012 (Server Core installation)6.2.9200.25815Review linked CVEs (10) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 10 linked CVEs for Windows Server 2012, Windows Server 2012 (Server Core installation). Microsoft marks CVE-2025-54100 as publicly disclosed, without that disclosure alone changing the BlackTree action window.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- KB5071505
- Platform
- ESU
- Restart
- yes
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
MicrosoftDeploy Microsoft ESU security update KB5071506KB5071506 · Updated 2025-12-09Product and releaseWindows Server 2008 R2 for x64-based Systems Service Pack 1, Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)6.1.7601.28064Review linked CVEs (10) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 10 linked CVEs for Windows Server 2008 R2 for x64-based Systems Service Pack 1, Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation). Microsoft marks CVE-2025-54100 as publicly disclosed, without that disclosure alone changing the BlackTree action window.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- KB5071506
- Platform
- ESU
- Restart
- yes
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.