Home › Microsoft Patch Tuesday › September 2025

Microsoft Patch Tuesday, September 2025

·

Microsoft's September 2025 security release, published September 9, 2025: 38 updates fixing 77 CVEs, ranked by confirmed exploitation, ransomware use, and severity. Provided by Senserva.

38
Updates (KBs)
77
CVEs fixed
0
On the CISA KEV list
0
Critical updates

Actively exploited CVEs (CISA KEV)

None of this month's CVEs were in the CISA Known Exploited Vulnerabilities catalog as of the last refresh.

Other high-risk CVEs (CVSS 8.8+)

CVE-2025-55227Microsoft SQL Server Elevation of Privilege VulnerabilityCVSS 8.8
CVE-2025-54106Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityCVSS 8.8
CVE-2025-54110Windows Kernel Elevation of Privilege VulnerabilityCVSS 8.8
CVE-2025-54113Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityCVSS 8.8
CVE-2025-54918Windows NTLM Elevation of Privilege VulnerabilityCVSS 8.8
CVE-2025-55234Windows SMB Elevation of Privilege VulnerabilityCVSS 8.8
CVE-2025-54897Microsoft SharePoint Remote Code Execution VulnerabilityCVSS 8.8

Products fixed this month

Windows Server 2008 for 32-bit Systems Service Pack 2 (3)Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation) (3)Windows Server 2008 for x64-based Systems Service Pack 2 (3)Microsoft Office 2016 (32-bit edition) (3)Microsoft Office 2016 (64-bit edition) (3)Windows Server 2008 R2 for x64-based Systems Service Pack 1 (2)Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) (2)Microsoft SharePoint Enterprise Server 2016 (2)Microsoft SharePoint Server 2019 (2)Microsoft Excel 2016 (32-bit edition) (2)

Every update in this release

All 30 update articles, worst first: anything on the CISA KEV list, then by highest CVSS. Each row links our page for the update, Microsoft's support article, and the Update Catalog for a standalone download.

UpdateSeverityMax CVSSCVEs fixedProductsAlso
KB5065224High8.83Microsoft SQL Server 2017 for x64-based Systems (GDR)Support · Catalog
KB5065223High8.83Microsoft SQL Server 2019 for x64-based Systems (GDR)Support · Catalog
KB5065226High8.83Microsoft SQL Server 2016 for x64-based Systems Service Pack 3 (GDR)Support · Catalog
KB5065227High8.83Microsoft SQL Server 2016 for x64-based Systems Service Pack 3 Azure Connect Feature PackSupport · Catalog
KB5065225High8.83Microsoft SQL Server 2017 for x64-based Systems (CU 31)Support · Catalog
KB5065222High8.83Microsoft SQL Server 2019 for x64-based Systems (CU 32)Support · Catalog
KB5065427High8.845Windows 10 Version 1607 for 32-bit Systems, Windows 10 Version 1607 for x64-based Systems, Windows Server 2016Support · Catalog
KB5065508High8.826Windows Server 2008 for 32-bit Systems Service Pack 2, Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation), Windows Server 2008 for x64-based Systems Service Pack 2Support · Catalog
KB5065511High8.826Windows Server 2008 for 32-bit Systems Service Pack 2, Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation), Windows Server 2008 for x64-based Systems Service Pack 2Support · Catalog
KB5065468High8.830Windows Server 2008 R2 for x64-based Systems Service Pack 1, Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)Support · Catalog
KB5065510High8.830Windows Server 2008 R2 for x64-based Systems Service Pack 1, Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)Support · Catalog
KB5065509High8.834Windows Server 2012, Windows Server 2012 (Server Core installation)Support · Catalog
KB5065507High8.835Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation)Support · Catalog
KB5065430High8.830Windows 10 for 32-bit Systems, Windows 10 for x64-based SystemsSupport · Catalog
KB5002778High8.83Microsoft SharePoint Enterprise Server 2016Support · Catalog
KB5002775High8.83Microsoft SharePoint Server 2019Support · Catalog
KB5002784High8.81Microsoft SharePoint Server Subscription EditionSupport · Catalog
KB5065221High8.82Microsoft SQL Server 2022 for x64-based Systems (GDR)Support · Catalog
KB5065220High8.82Microsoft SQL Server 2022 for x64-based Systems (CU 20)Support · Catalog
KB5002781High8.42Microsoft Office 2016 (32-bit edition), Microsoft Office 2016 (64-bit edition)Support · Catalog
KB5002576High7.81Microsoft Office 2016 (32-bit edition), Microsoft Office 2016 (64-bit edition)Support · Catalog
KB5002766High7.81Microsoft Office 2016 (32-bit edition), Microsoft Office 2016 (64-bit edition)Support · Catalog
KB5002779High7.81Microsoft PowerPoint 2016 (32-bit edition), Microsoft PowerPoint 2016 (64-bit edition)Support · Catalog
KB5002776High7.86Office Online ServerSupport · Catalog
KB5002782High7.87Microsoft Excel 2016 (32-bit edition), Microsoft Excel 2016 (64-bit edition)Support · Catalog
KB5002777High7.11Microsoft SharePoint Enterprise Server 2016Support · Catalog
KB5002774High7.11Microsoft SharePoint Server 2019Support · Catalog
KB5002780High7.11Microsoft Word 2016 (32-bit edition), Microsoft Word 2016 (64-bit edition)Support · Catalog
KB5002762Medium5.51Microsoft Excel 2016 (32-bit edition), Microsoft Excel 2016 (64-bit edition)Support · Catalog
KB5065435Medium4.32Windows Server 2008 for 32-bit Systems Service Pack 2, Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation), Windows Server 2008 for x64-based Systems Service Pack 2Support · Catalog
Take this release to your AI

Composed from the September 2025 release data above. Copy it into Claude, ChatGPT, or Copilot. Free, no sign-in.

Now see your own patch state.

Senserva reads your Microsoft 365, Intune, Defender, and Entra ID environment and turns this release into your list: every update still missing, on every device, ranked by what attackers are actually exploiting. The 650+ configuration checks come with it.

1Find it2Fix it3Prove it
Start my free patch auditAll you do is register.
Reference: Microsoft CVE and vulnerability management, ranked by real-world risk, and the Microsoft patching guide.
Data notice: this page is provided as is, for informational purposes only, without warranty of any kind. Senserva, LLC does not guarantee the accuracy, completeness, or timeliness of third-party data (MSRC, NVD, CISA KEV, EPSS) and accepts no liability for actions taken based on it; verify against the authoritative Microsoft advisory before acting. Built daily with Senserva Trustworthy AI. All use of this data is subject to the Senserva EULA.