logo

Microsoft warns of 66 flaws to fix for this Patch Tuesday, and two are under active attack

ID: 77e39c0b-9dd3-5a79-bfc0-d5b267733473

STIX ID: report--77e39c0b-9dd3-5a79-bfc0-d5b267733473

Feed Name: The Register (Security)

Threat Score
85/100

Date Published: 2025-06-10

Date Updated: 2026-04-26

Author: Iain Thomson

...
...

Microsoft's June Patch Tuesday addresses 66 flaws — including two actively exploited zero-days: CVE-2025-33053 (WebDAV RCE used by Stealth Falcon since March) and CVE-2025-5419 (Chromium V8 memory corruption). Multiple high-severity RCE and privilege-escalation bugs (CVSS up to 9.8) affect Office, SMB, RDP, SharePoint and more; Adobe, Fortinet and SAP also issued critical updates. Organizations should prioritize patching the actively exploited and high-CVSS vulnerabilities immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.