Home › Microsoft Patch Tuesday › July 2025

Microsoft Patch Tuesday, July 2025

·

Microsoft's July 2025 security release, published July 8, 2025: 51 updates fixing 118 CVEs, ranked by confirmed exploitation, ransomware use, and severity. Provided by Senserva.

Still active now. 4 CVEs from this release are on the Senserva hot list today (as of 2026-10-08), still ranked among the most dangerous vulnerabilities right now by confirmed exploitation, ransomware use, EPSS, and severity. See the current hot list.
51
Updates (KBs)
118
CVEs fixed
5
On the CISA KEV list
3
Ransomware-linked
17
Critical updates

Actively exploited CVEs (CISA KEV)

CVE-2025-53770Microsoft SharePoint Server Remote Code Execution VulnerabilityCVSS 9.8ExploitedRansomware Hot now
CVE-2025-49704Microsoft SharePoint Remote Code Execution VulnerabilityCVSS 8.8ExploitedRansomware Hot now
CVE-2025-33053Internet Shortcut Files Remote Code Execution VulnerabilityCVSS 8.8Exploited
CVE-2025-33073Windows SMB Client Elevation of Privilege VulnerabilityCVSS 8.8Exploited Hot now
CVE-2025-49706Microsoft SharePoint Server Spoofing VulnerabilityCVSS 6.5ExploitedRansomware Hot now

Other high-risk CVEs (CVSS 8.8+)

CVE-2025-49701Microsoft SharePoint Remote Code Execution VulnerabilityCVSS 8.8
CVE-2025-33064Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityCVSS 8.8
CVE-2025-33066Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityCVSS 8.8
CVE-2024-49000SQL Server Native Client Remote Code Execution VulnerabilityCVSS 8.8
CVE-2025-49739Visual Studio Elevation of Privilege VulnerabilityCVSS 8.8

Products fixed this month

Microsoft Word 2016 (32-bit edition) (5)Microsoft SharePoint Enterprise Server 2016 (4)Microsoft SharePoint Server 2019 (4)Microsoft Word 2016 (64-bit edition) (4)Microsoft SharePoint Server Subscription Edition (2)Microsoft Office 2016 (32-bit edition) (2)Microsoft Excel 2016 (32-bit edition) (2)Microsoft Excel 2016 (64-bit edition) (2)Windows Server 2019 (1)Windows Server 2019 (Server Core installation) (1)

Every update in this release

All 37 update articles, worst first: anything on the CISA KEV list, then by highest CVSS. Each row links our page for the update, Microsoft's support article, and the Update Catalog for a standalone download.

UpdateSeverityMax CVSSCVEs fixedProductsAlso
KB5002760 Exploited RansomwareCritical9.82Microsoft SharePoint Enterprise Server 2016Support · Catalog
KB5002759 Exploited RansomwareCritical9.82Microsoft SharePoint Enterprise Server 2016Support · Catalog
KB5002754 Exploited RansomwareCritical9.82Microsoft SharePoint Server 2019Support · Catalog
KB5002753 Exploited RansomwareCritical9.82Microsoft SharePoint Server 2019Support · Catalog
KB5002768 Exploited RansomwareCritical9.82Microsoft SharePoint Server Subscription EditionSupport · Catalog
KB5002744 Exploited RansomwareHigh8.84Microsoft SharePoint Enterprise Server 2016Support · Catalog
KB5002741 Exploited RansomwareHigh8.84Microsoft SharePoint Server 2019Support · Catalog
KB5002751 Exploited RansomwareHigh8.82Microsoft SharePoint Server Subscription EditionSupport · Catalog
KB5060531 ExploitedHigh8.839Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 1809 for 32-bit SystemsSupport · Catalog
KB5060526 ExploitedHigh8.840Windows Server 2022, Windows Server 2022 (Server Core installation)Support · Catalog
KB5060842 ExploitedHigh8.840Windows Server 2025 (Server Core installation), Windows Server 2025, Windows 11 Version 24H2 for ARM64-based SystemsSupport · Catalog
KB5060118 ExploitedHigh8.839Windows Server 2022, 23H2 Edition (Server Core installation)Support · Catalog
KB5061010 ExploitedHigh8.837Windows Server 2016, Windows Server 2016 (Server Core installation), Windows 10 Version 1607 for 32-bit SystemsSupport · Catalog
KB5061059 ExploitedHigh8.820Windows Server 2012, Windows Server 2012 (Server Core installation)Support · Catalog
KB5061018 ExploitedHigh8.823Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation)Support · Catalog
KB5058718High8.82Microsoft SQL Server 2016 for x64-based Systems Service Pack 2 (GDR), Microsoft SQL Server 2016 for x64-based Systems Service Pack 3 (GDR)Support · Catalog
KB5063035High8.81Microsoft Visual Studio 2015 Update 3Support · Catalog
KB5058713High8.53Microsoft SQL Server 2019 for x64-based Systems (GDR)Support · Catalog
KB5058712High8.53Microsoft SQL Server 2022 for x64-based Systems (GDR)Support · Catalog
KB5058722High8.53Microsoft SQL Server 2019 for x64-based Systems (CU 32)Support · Catalog
KB5058721High8.53Microsoft SQL Server 2022 for x64-based Systems (CU 19)Support · Catalog
KB5002742High8.47Microsoft Office 2016 (32-bit edition), Microsoft Office 2016 (64-bit edition), Microsoft Word 2016 (32-bit edition)Support · Catalog
KB5002740High8.43Office Online ServerSupport · Catalog
KB5002749High8.43Microsoft Excel 2016 (32-bit edition), Microsoft Excel 2016 (64-bit edition), Microsoft Office 2016 (32-bit edition)Support · Catalog
KB31909343High8.01Microsoft Configuration Manager 2503Support · Catalog
KB5002743High7.81Microsoft SharePoint Enterprise Server 2016Support · Catalog
KB5002739High7.81Microsoft SharePoint Server 2019Support · Catalog
KB5002745High7.81Microsoft Word 2016 (32-bit edition), Microsoft Word 2016 (64-bit edition)Support · Catalog
KB5002746High7.82Microsoft PowerPoint 2016 (32-bit edition), Microsoft PowerPoint 2016 (64-bit edition)Support · Catalog
KB5002655High7.81Microsoft Word 2016 (32-bit edition), Microsoft Word 2016 (64-bit edition)Support · Catalog
KB5058716High7.51Microsoft SQL Server 2017 for x64-based Systems (GDR)Support · Catalog
KB5058717High7.51Microsoft SQL Server 2016 for x64-based Systems Service Pack 3 Azure Connect Feature PackSupport · Catalog
KB5058714High7.51Microsoft SQL Server 2017 for x64-based Systems (CU 31)Support · Catalog
KB5001941High7.01Microsoft Word 2016 (32-bit edition), Microsoft Word 2016 (64-bit edition)Support · Catalog
KB4464583High7.01Microsoft Word 2016 (32-bit edition), Microsoft Word 2016 (64-bit edition)Support · Catalog
KB5002747High7.01Microsoft Outlook 2016 (32-bit edition), Microsoft Outlook 2016 (64-bit edition)Support · Catalog
KB5002734Medium5.51Microsoft Excel 2016 (32-bit edition), Microsoft Excel 2016 (64-bit edition)Support · Catalog
Take this release to your AI

Composed from the July 2025 release data above. Copy it into Claude, ChatGPT, or Copilot. Free, no sign-in.

Now see your own patch state.

Senserva reads your Microsoft 365, Intune, Defender, and Entra ID environment and turns this release into your list: every update still missing, on every device, ranked by what attackers are actually exploiting. The 650+ configuration checks come with it.

1Find it2Fix it3Prove it
Start my free patch auditAll you do is register.
Reference: Microsoft CVE and vulnerability management, ranked by real-world risk, and the Microsoft patching guide.
Data notice: this page is provided as is, for informational purposes only, without warranty of any kind. Senserva, LLC does not guarantee the accuracy, completeness, or timeliness of third-party data (MSRC, NVD, CISA KEV, EPSS) and accepts no liability for actions taken based on it; verify against the authoritative Microsoft advisory before acting. Built daily with Senserva Trustworthy AI. All use of this data is subject to the Senserva EULA.