logo

Patch Tuesday Brings 971 CVEs And 3 Critical Microsoft Flaws

ID: d3252edc-a2ee-52e5-b039-dfdd8a51599b

STIX ID: report--d3252edc-a2ee-52e5-b039-dfdd8a51599b

Feed Name: Cyble Blog

Threat Score
78/100

Date Published: 2025-11-18

Date Updated: 2026-07-16

...
...

Cyble's weekly vulnerability roundup reports 971 vulnerabilities tracked, with 60 critical (CVSSv3.1) and multiple critical CVEs receiving public PoCs and CISA KEV listings; notable issues include Microsoft GDI+ heap overflow (CVE-2025-60724), Chrome V8 type confusion (CVE-2025-6554), QNAP QuMagie SQL injection (CVE-2025-52425), and a critical Cisco ASA buffer overflow (CVE-2025-20333). The briefing also notes dark-web discussions of weaponization, a reported Samsung spyware delivery CVE, and an ICS exposure (CVE-2025-12636), urging risk-based patching, segmentation, zero-trust controls, and monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.