logo

The December 2025 Security Update Review

ID: 187364b6-1f4f-58a9-8fe6-72d23a221995

STIX ID: report--187364b6-1f4f-58a9-8fe6-72d23a221995

Feed Name: Zero Day Initiative (ZDI) Blog

Threat Score
70/100

Date Published: 2025-12-09

Date Updated: 2026-05-01

Author: Dustin Childs

...
...

Adobe and Microsoft December 2025 security bulletins: Adobe released five updates covering 139 CVEs (mostly XSS in Experience Manager, a few code-execution fixes and a ColdFusion priority-1 update), while Microsoft released 56 new Windows/Office/Edge/Azure-related CVEs (three Critical, the rest Important) including one bug under active attack (CVE-2025-62221) and a publicly known Copilot command-injection (CVE-2025-64671); administrators are advised to prioritize the actively exploited and high-severity fixes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.