logo

Microsoft reports 7.8-rated zero day, plus 56 more in December Patch Tuesday

ID: 0900e455-df10-5743-b6dd-de0fe70a7f42

STIX ID: report--0900e455-df10-5743-b6dd-de0fe70a7f42

Feed Name: The Register (Security)

Threat Score
78/100

Date Published: 2025-12-09

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

December Patch Tuesday coverage: Microsoft fixed a zero-day Windows Cloud Files mini-filter privilege escalation (CVE-2025-62221) plus two publicly known RCE issues; Notepad++ released v8.8.9 to mitigate an update-hijack used in active attacks reportedly linked to Chinese actors; Fortinet patched critical SAML bypass flaws (CVE-2025-59718/59719) affecting multiple products; and Ivanti patched a critical unauthenticated stored XSS in EPM (CVE-2025-10573) that can grant admin session control — administrators are advised to prioritize patching and to disable affected features (e.g., FortiCloud SSO) until updates are applied.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.