logo

The May 2025 Security Update Review

ID: 1f28d415-5859-5ee6-9d7d-0af3cf3dfc19

STIX ID: report--1f28d415-5859-5ee6-9d7d-0af3cf3dfc19

Feed Name: Zero Day Initiative (ZDI) Blog

Threat Score
70/100

Date Published: 2025-05-13

Date Updated: 2026-05-01

Author: Dustin Childs

...
...

Adobe released 13 bulletins fixing 40 CVEs across multiple Creative Cloud and Substance 3D products, with ColdFusion singled out as high priority; Microsoft released ~75 new CVEs (82 including third-party) across Windows, Office, Azure and other components, including 12 Critical fixes and several CVEs reported under active exploitation (notably CVE-2025-30397 and several privilege-escalation bugs). The report recommends prioritizing patches that enable remote code execution and elevation to SYSTEM because those are commonly chained in phishing and ransomware campaigns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.