Home › Microsoft Patch Tuesday › October 2025

Microsoft Patch Tuesday, October 2025

·

Microsoft's October 2025 security release, published October 14, 2025: 65 updates fixing 152 CVEs, ranked by confirmed exploitation, ransomware use, and severity. Provided by Senserva.

Still active now. 1 CVE from this release is on the Senserva hot list today (as of 2026-10-08), still ranked among the most dangerous vulnerabilities right now by confirmed exploitation, ransomware use, EPSS, and severity. See the current hot list.
65
Updates (KBs)
152
CVEs fixed
4
On the CISA KEV list
17
Critical updates

Actively exploited CVEs (CISA KEV)

CVE-2025-59287Windows Server Update Service (WSUS) Remote Code Execution VulnerabilityCVSS 9.8Exploited Hot now
CVE-2025-24990Windows Agere Modem Driver Elevation of Privilege VulnerabilityCVSS 7.8Exploited
CVE-2025-59230Windows Remote Access Connection Manager Elevation of Privilege VulnerabilityCVSS 7.8Exploited
CVE-2025-47827MITRE CVE-2025-47827: Secure Boot bypass in IGEL OS before 11CVSS 4.6Exploited

Other high-risk CVEs (CVSS 8.8+)

CVE-2025-55315ASP.NET Security Feature Bypass VulnerabilityCVSS 9.9
CVE-2025-58718Remote Desktop Client Remote Code Execution VulnerabilityCVSS 8.8
CVE-2025-59295Windows URL Parsing Remote Code Execution VulnerabilityCVSS 8.8
CVE-2025-54106Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityCVSS 8.8
CVE-2025-54110Windows Kernel Elevation of Privilege VulnerabilityCVSS 8.8
CVE-2025-54113Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityCVSS 8.8
CVE-2025-54918Windows NTLM Elevation of Privilege VulnerabilityCVSS 8.8
CVE-2025-55234Windows SMB Elevation of Privilege VulnerabilityCVSS 8.8
CVE-2025-21293Active Directory Domain Services Elevation of Privilege VulnerabilityCVSS 8.8
CVE-2025-59228Microsoft SharePoint Remote Code Execution VulnerabilityCVSS 8.8
CVE-2025-59237Microsoft SharePoint Remote Code Execution VulnerabilityCVSS 8.8
CVE-2025-59249Microsoft Exchange Server Elevation of Privilege VulnerabilityCVSS 8.8

Products fixed this month

Windows Server 2022 (4)Windows Server 2022 (Server Core installation) (4)Windows Server 2025 (Server Core installation) (4)Microsoft Excel 2016 (32-bit edition) (4)Microsoft Excel 2016 (64-bit edition) (4)Windows Server 2025 (3)Windows Server 2008 for 32-bit Systems Service Pack 2 (3)Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation) (3)Windows Server 2008 for x64-based Systems Service Pack 2 (3)Windows Server 2019 (2)

Every update in this release

All 57 update articles, worst first: anything on the CISA KEV list, then by highest CVSS. Each row links our page for the update, Microsoft's support article, and the Update Catalog for a standalone download.

UpdateSeverityMax CVSSCVEs fixedProductsAlso
KB5070883 ExploitedCritical9.81Windows Server 2019, Windows Server 2019 (Server Core installation)Support · Catalog
KB5070884 ExploitedCritical9.81Windows Server 2022, Windows Server 2022 (Server Core installation)Support · Catalog
KB5070892 ExploitedCritical9.81Windows Server 2022, Windows Server 2022 (Server Core installation)Support · Catalog
KB5070881 ExploitedCritical9.81Windows Server 2025 (Server Core installation), Windows Server 2025Support · Catalog
KB5070893 ExploitedCritical9.81Windows Server 2025 (Server Core installation), Windows Server 2025Support · Catalog
KB5070879 ExploitedCritical9.81Windows Server 2022, 23H2 Edition (Server Core installation)Support · Catalog
KB5070882 ExploitedCritical9.81Windows Server 2016, Windows Server 2016 (Server Core installation)Support · Catalog
KB5070887 ExploitedCritical9.81Windows Server 2012, Windows Server 2012 (Server Core installation)Support · Catalog
KB5070886 ExploitedCritical9.81Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation)Support · Catalog
KB5066874 ExploitedHigh8.834Windows Server 2008 for 32-bit Systems Service Pack 2, Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation), Windows Server 2008 for x64-based Systems Service Pack 2Support · Catalog
KB5066877 ExploitedHigh8.834Windows Server 2008 for 32-bit Systems Service Pack 2, Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation), Windows Server 2008 for x64-based Systems Service Pack 2Support · Catalog
KB5066872 ExploitedHigh8.837Windows Server 2008 R2 for x64-based Systems Service Pack 1, Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)Support · Catalog
KB5066876 ExploitedHigh8.837Windows Server 2008 R2 for x64-based Systems Service Pack 1, Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)Support · Catalog
KB5066875 ExploitedHigh8.846Windows Server 2012, Windows Server 2012 (Server Core installation)Support · Catalog
KB5066873 ExploitedHigh8.850Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation)Support · Catalog
KB5068331Critical9.93.NET 8.0 installed on Linux, .NET 8.0 installed on Mac OS, .NET 8.0 installed on WindowsSupport · Catalog
KB5068332Critical9.93.NET 9.0 installed on Linux, .NET 9.0 installed on Mac OS, .NET 9.0 installed on WindowsSupport · Catalog
KB5065432High8.859Windows Server 2022, Windows Server 2022 (Server Core installation)Support · Catalog
KB5065306High8.859Windows Server 2022, Windows Server 2022 (Server Core installation)Support · Catalog
KB5065429High8.849Windows 10 Version 21H2 for 32-bit Systems, Windows 10 Version 21H2 for ARM64-based Systems, Windows 10 Version 21H2 for x64-based SystemsSupport · Catalog
KB5065431High8.850Windows 11 Version 22H2 for ARM64-based Systems, Windows 11 Version 22H2 for x64-based Systems, Windows 11 Version 23H2 for ARM64-based SystemsSupport · Catalog
KB5065426High8.864Windows Server 2025 (Server Core installation), Windows 11 Version 24H2 for ARM64-based Systems, Windows 11 Version 24H2 for x64-based SystemsSupport · Catalog
KB5065474High8.864Windows Server 2025 (Server Core installation), Windows 11 Version 24H2 for x64-based Systems, Windows Server 2025Support · Catalog
KB5065425High8.861Windows Server 2022, 23H2 Edition (Server Core installation)Support · Catalog
KB5065428High8.852Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5002788High8.86Microsoft SharePoint Enterprise Server 2016Support · Catalog
KB5002796High8.86Microsoft SharePoint Server 2019Support · Catalog
KB5002786High8.82Microsoft SharePoint Server Subscription EditionSupport · Catalog
KB5066840High8.83Windows Server 2008 for 32-bit Systems Service Pack 2, Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation), Windows Server 2008 for x64-based Systems Service Pack 2Support · Catalog
KB5066367High8.83Microsoft Exchange Server 2019 Cumulative Update 15Support · Catalog
KB5066368High8.83Microsoft Exchange Server 2019 Cumulative Update 14Support · Catalog
KB5066366High8.83Microsoft Exchange Server Subscription Edition RTMSupport · Catalog
KB5066369High8.83Microsoft Exchange Server 2016 Cumulative Update 23Support · Catalog
KB5002797High8.48Office Online ServerSupport · Catalog
KB5002794High7.87Microsoft Excel 2016 (32-bit edition), Microsoft Excel 2016 (64-bit edition)Support · Catalog
KB5002792High7.82Microsoft Office 2016 (64-bit edition), Microsoft Office 2016 (32-bit edition)Support · Catalog
KB5002787High7.82Microsoft SharePoint Enterprise Server 2016Support · Catalog
KB5002798High7.82Microsoft SharePoint Server 2019Support · Catalog
KB5002789High7.82Microsoft Word 2016 (32-bit edition), Microsoft Word 2016 (64-bit edition)Support · Catalog
KB5002790High7.81Microsoft PowerPoint 2016 (32-bit edition), Microsoft PowerPoint 2016 (64-bit edition)Support · Catalog
KB5002719High7.12Microsoft Excel 2016 (32-bit edition), Microsoft Excel 2016 (64-bit edition)Support · Catalog
KB5002757High7.12Microsoft Excel 2016 (32-bit edition), Microsoft Excel 2016 (64-bit edition)Support · Catalog
KB5002341High7.12Microsoft Excel 2016 (32-bit edition), Microsoft Excel 2016 (64-bit edition)Support · Catalog
KB5002720High7.12Microsoft Access 2016 (32-bit edition), Microsoft Access 2016 (64-bit edition)Support · Catalog
KB5066136Medium4.81Microsoft .NET Framework 4.8 on Windows 10 Version 1607 for 32-bit Systems, Microsoft .NET Framework 4.8 on Windows 10 Version 1607 for x64-based Systems, Microsoft .NET Framework 4.8 on Windows Server 2016Support · Catalog
KB5066739Medium4.81Microsoft .NET Framework 4.8 on Windows Server 2008 R2 for x64-based Systems Service Pack 1, Microsoft .NET Framework 4.8 on Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation), Microsoft .NET Framework 3.5.1 on Windows Server 2008 R2 for x64-based Systems Service Pack 1Support · Catalog
KB5066740Medium4.81Microsoft .NET Framework 4.8 on Windows Server 2012, Microsoft .NET Framework 4.8 on Windows Server 2012 (Server Core installation), Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012Support · Catalog
KB5066741Medium4.81Microsoft .NET Framework 4.8 on Windows Server 2012 R2, Microsoft .NET Framework 4.8 on Windows Server 2012 R2 (Server Core installation), Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012 R2Support · Catalog
KB5066738Medium4.81Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1809 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1809 for x64-based Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows Server 2019Support · Catalog
KB5066743Medium4.81Microsoft .NET Framework 3.5 AND 4.8 on Windows Server 2022, Microsoft .NET Framework 3.5 AND 4.8 on Windows Server 2022 (Server Core installation), Microsoft .NET Framework 3.5 AND 4.8.1 on Windows Server 2022Support · Catalog
KB5066746Medium4.81Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 21H2 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 21H2 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 21H2 for x64-based SystemsSupport · Catalog
KB5066747Medium4.81Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 22H2 for x64-based Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 22H2 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 22H2 for 32-bit SystemsSupport · Catalog
KB5066742Medium4.81Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2008 R2 for x64-based Systems Service Pack 1, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation), Microsoft .NET Framework 4.6.2 on Windows Server 2008 for 32-bit Systems Service Pack 2Support · Catalog
KB5066133Medium4.81Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 22H2 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 22H2 for x64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 23H2 for ARM64-based SystemsSupport · Catalog
KB5066129Medium4.81Microsoft .NET Framework 3.5 AND 4.8.1 on Windows Server 2022, 23H2 Edition (Server Core installation)Support · Catalog
KB5066131Medium4.81Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 24H2 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 24H2 for x64-based SystemsSupport · Catalog
KB5066128Medium4.81Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 25H2 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 25H2 for x64-based SystemsSupport · Catalog
Take this release to your AI

Composed from the October 2025 release data above. Copy it into Claude, ChatGPT, or Copilot. Free, no sign-in.

Now see your own patch state.

Senserva reads your Microsoft 365, Intune, Defender, and Entra ID environment and turns this release into your list: every update still missing, on every device, ranked by what attackers are actually exploiting. The 650+ configuration checks come with it.

1Find it2Fix it3Prove it
Start my free patch auditAll you do is register.
Reference: Microsoft CVE and vulnerability management, ranked by real-world risk, and the Microsoft patching guide.
Data notice: this page is provided as is, for informational purposes only, without warranty of any kind. Senserva, LLC does not guarantee the accuracy, completeness, or timeliness of third-party data (MSRC, NVD, CISA KEV, EPSS) and accepts no liability for actions taken based on it; verify against the authoritative Microsoft advisory before acting. Built daily with Senserva Trustworthy AI. All use of this data is subject to the Senserva EULA.