logo

Choose your own Patch Tuesday adventure: Start with six zero-day fixes, or six critical flaws

ID: 57c68931-3a5a-5375-9445-245c8a95e2ba

STIX ID: report--57c68931-3a5a-5375-9445-245c8a95e2ba

Feed Name: The Register (Security)

Threat Score
85/100

Date Published: 2025-03-12

Date Updated: 2026-04-26

Author: Iain Thomson

...
...

Microsoft's March Patch Tuesday addresses a dozen high-profile flaws — six already being actively exploited — including NTFS heap overflow (CVE-2025-24993), other NTFS info-disclosure/log-insertion bugs, an MMC security-bypass (CVE-2025-26633) used in attacks impacting over 600 organizations, and additional critical RDS/RDP/Office/WSL issues; Apple patched an exploited Safari sandbox bypass (CVE-2025-24201), Adobe fixed numerous critical code-execution bugs across products, and Google released Android fixes for vulnerabilities including ones under targeted exploitation (e.g., CVE-2024-50302). Organizations are advised to prioritize these updates due to active exploitation and high-impact RCE/privilege escalation risks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.