logo

Microsoft Patches 137 CVEs in July, but No Zero-Days

ID: 2cb2a69b-6f72-5af5-8dc3-aa9567fbe148

STIX ID: report--2cb2a69b-6f72-5af5-8dc3-aa9567fbe148

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2025-07-08

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

Microsoft's July security update discloses 137 vulnerabilities — 14 rated critical — including an urgent unauthenticated remote code execution in the NEGOEX/SPNEGO extended negotiation (CVE-2025-47981) that can execute code in LSASS, multiple high-risk RCEs in Office and SharePoint, privilege escalation and security-bypass flaws (including BitLocker bypasses), and a publicly disclosed SQL Server information-leak issue; vendors and defenders are urged to patch immediately and monitor for NEGOEX/SPNEGO activity and unusual authentication traffic due to the likelihood of rapid weaponization.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.