Skip to main content
QUIETLYTIC
Advisory

Microsoft Patch Tuesday November 2025: 184 Vulnerabilities Fixed

Microsoft's November 11, 2025 Patch Tuesday fixed 184 vulnerabilities (13 critical, 92 important) — none are currently listed as actively exploited, per CISA…

Microsoft Patch Tuesday November 2025: 184 Vulnerabilities Fixed — Advisory research covering CVE-2025-49752, CVE-2025-40165, CVE-2025-40172, CVE-2025-59245, CVE-2025-64657, CVE-2025-64656, CVE-2025-64655, CVE-2025-62207, CVE-2025-62459, CVE-2025-30398, CVE-2025-62199, CVE-2025-60716, CVE-2025-62214, CVE-2025-60724, CVE-2025-60876, CVE-2025-12970, CVE-2025-13226, CVE-2025-59499, CVE-2025-62220, CVE-2025-62222, CVE-2025-62210, CVE-2025-62211, CVE-2025-12816, CVE-2025-13227, CVE-2025-13230, CVE-2025-40135, CVE-2025-40139, CVE-2025-40176, CVE-2025-12977, CVE-2025-40170, CVE-2025-60715, CVE-2025-62204, CVE-2025-62452, CVE-2025-64660, CVE-2025-40198, CVE-2025-40205, CVE-2025-40211, CVE-2025-59505, CVE-2025-59511, CVE-2025-59512, CVE-2025-59514, CVE-2025-60703, CVE-2025-60705, CVE-2025-60707, CVE-2025-60709, CVE-2025-60710, CVE-2025-60713, CVE-2025-60714, CVE-2025-60718, CVE-2025-60720, CVE-2025-60721, CVE-2025-60727, CVE-2025-62200, CVE-2025-62201, CVE-2025-62203, CVE-2025-62205, CVE-2025-62216, CVE-2025-13601, CVE-2025-12638, CVE-2024-47866, CVE-2025-12863, CVE-2025-47913, CVE-2025-59777, CVE-2025-62689, CVE-2025-60704, CVE-2024-25621, CVE-2025-52881, CVE-2025-59504, CVE-2025-40190, CVE-2025-40201, CVE-2025-40204, CVE-2025-64720, CVE-2025-65018, CVE-2025-60726, CVE-2025-62202, CVE-2025-59506, CVE-2025-59507, CVE-2025-59508, CVE-2025-59515, CVE-2025-60717, CVE-2025-60719, CVE-2025-62213, CVE-2025-62215, CVE-2025-62217, CVE-2025-62218, CVE-2025-62219, CVE-2025-62449, CVE-2025-47179, CVE-2025-60708, CVE-2025-60722, CVE-2025-62206, CVE-2025-60723, CVE-2025-59240, CVE-2025-59509, CVE-2025-59510, CVE-2025-59513, CVE-2025-60706, CVE-2025-62208, CVE-2025-62209, CVE-2025-62453, CVE-2025-60728, CVE-2025-31133, CVE-2025-52565, CVE-2025-64324, CVE-2025-66031, CVE-2025-11230, CVE-2025-11935, CVE-2025-40158, CVE-2025-10966, CVE-2025-12969, CVE-2025-64433, CVE-2025-40173, CVE-2025-40213, CVE-2025-64505, CVE-2025-64506, CVE-2025-61915, CVE-2025-12818, CVE-2025-12748, CVE-2025-13193, CVE-2025-40107, CVE-2025-40136, CVE-2025-40146, CVE-2025-40149, CVE-2025-40164, CVE-2025-40167, CVE-2025-40168, CVE-2025-40178, CVE-2025-40179, CVE-2025-40180, CVE-2025-40187, CVE-2025-40188, CVE-2025-40192, CVE-2025-40193, CVE-2025-40194, CVE-2025-40195, CVE-2025-40197, CVE-2025-40200, CVE-2025-40202, CVE-2025-40206, CVE-2025-40207, CVE-2025-40210, CVE-2025-60753, CVE-2025-10158, CVE-2025-11936, CVE-2025-12875, CVE-2025-13120, CVE-2025-64435, CVE-2025-64436, CVE-2025-58436, CVE-2025-64713
Severity
Critical
Confidence
High
Status
Active

Full CVE Roster

All 150 CVEs from this release, ready to paste into a tracker, ticket, or SIEM search — 2 flagged as actively exploited (KEV).

CVE ID Title CVSS Severity KEV
CVE-2025-49752 Azure Bastion Elevation of Privilege Vulnerability 10.0 critical
CVE-2025-40165 media: nxp: imx8-isi: m2m: Fix streaming cleanup on release 9.8 critical
CVE-2025-40172 accel/qaic: Treat remaining == 0 as error in find_and_map_user_pages() 9.8 critical
CVE-2025-59245 Microsoft SharePoint Online Elevation of Privilege Vulnerability 9.8 critical
CVE-2025-64657 Azure Application Gateway Elevation of Privilege Vulnerability 9.8 critical
CVE-2025-64656 Azure Application Gateway Elevation of Privilege Vulnerability 9.4 critical
CVE-2025-64655 Dynamics OmniChannel SDK Storage Containers Elevation of Privilege Vulnerability 8.8 critical
CVE-2025-62207 Azure Monitor Elevation of Privilege Vulnerability 8.6 critical
CVE-2025-62459 Microsoft Defender Portal Spoofing Vulnerability 8.3 critical
CVE-2025-30398 Nuance PowerScribe 360 Information Disclosure Vulnerability 8.1 critical
CVE-2025-62199 Microsoft Office Remote Code Execution Vulnerability 7.8 critical
CVE-2025-60716 DirectX Graphics Kernel Elevation of Privilege Vulnerability 7.0 critical
CVE-2025-62214 Visual Studio Remote Code Execution Vulnerability 6.7 critical
CVE-2025-60724 GDI+ Remote Code Execution Vulnerability 9.8 high
CVE-2025-60876 BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). 9.4 high
CVE-2025-12970 CVE-2025-12970 8.8 high
CVE-2025-13226 Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) 8.8 high
CVE-2025-59499 Microsoft SQL Server Elevation of Privilege Vulnerability 8.8 high
CVE-2025-62220 Windows Subsystem for Linux GUI Remote Code Execution Vulnerability 8.8 high
CVE-2025-62222 Agentic AI and Visual Studio Code Remote Code Execution Vulnerability 8.8 high
CVE-2025-62210 Dynamics 365 Field Service (online) Spoofing Vulnerability 8.7 high
CVE-2025-62211 Dynamics 365 Field Service (online) Spoofing Vulnerability 8.7 high
CVE-2025-12816 CVE-2025-12816 8.6 high
CVE-2025-13227 Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) 8.6 high
CVE-2025-13230 Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) 8.6 high
CVE-2025-40135 ipv6: use RCU in ip6_xmit() 8.4 high
CVE-2025-40139 smc: Use __sk_dst_get() and dst_dev_rcu() in in smc_clc_prfx_set(). 8.4 high
CVE-2025-40176 tls: wait for pending async decryptions if tls_strp_msg_hold fails 8.4 high
CVE-2025-12977 CVE-2025-12977 8.3 high
CVE-2025-40170 net: use dst_dev_rcu() in sk_setup_caps() 8.1 high
CVE-2025-60715 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability 8.0 high
CVE-2025-62204 Microsoft SharePoint Remote Code Execution Vulnerability 8.0 high
CVE-2025-62452 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability 8.0 high
CVE-2025-64660 GitHub Copilot and Visual Studio Code Remote Code Execution Vulnerability 8.0 high
CVE-2025-40198 ext4: avoid potential buffer over-read in parse_apply_sb_mount_options() 7.8 high
CVE-2025-40205 btrfs: avoid potential out-of-bounds in btrfs_encode_fh() 7.8 high
CVE-2025-40211 ACPI: video: Fix use-after-free in acpi_video_switch_brightness() 7.8 high
CVE-2025-59505 Windows Smart Card Reader Elevation of Privilege Vulnerability 7.8 high
CVE-2025-59511 Windows WLAN Service Elevation of Privilege Vulnerability 7.8 high
CVE-2025-59512 Customer Experience Improvement Program (CEIP) Elevation of Privilege Vulnerability 7.8 high
CVE-2025-59514 Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability 7.8 high
CVE-2025-60703 Windows Remote Desktop Services Elevation of Privilege Vulnerability 7.8 high
CVE-2025-60705 Windows Client-Side Caching Elevation of Privilege Vulnerability 7.8 high
CVE-2025-60707 Multimedia Class Scheduler Service (MMCSS) Driver Elevation of Privilege Vulnerability 7.8 high
CVE-2025-60709 Windows Common Log File System Driver Elevation of Privilege Vulnerability 7.8 high
CVE-2025-60710 Host Process for Windows Tasks Elevation of Privilege Vulnerability 7.8 high Yes
CVE-2025-60713 Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability 7.8 high
CVE-2025-60714 Windows OLE Remote Code Execution Vulnerability 7.8 high
CVE-2025-60718 Windows Administrator Protection Elevation of Privilege Vulnerability 7.8 high
CVE-2025-60720 Windows Transport Driver Interface (TDI) Translation Driver Elevation of Privilege Vulnerability 7.8 high
CVE-2025-60721 Windows Administrator Protection Elevation of Privilege Vulnerability 7.8 high
CVE-2025-60727 Microsoft Excel Remote Code Execution Vulnerability 7.8 high
CVE-2025-62200 Microsoft Excel Remote Code Execution Vulnerability 7.8 high
CVE-2025-62201 Microsoft Excel Remote Code Execution Vulnerability 7.8 high
CVE-2025-62203 Microsoft Excel Remote Code Execution Vulnerability 7.8 high
CVE-2025-62205 Microsoft Office Remote Code Execution Vulnerability 7.8 high
CVE-2025-62216 Microsoft Office Remote Code Execution Vulnerability 7.8 high
CVE-2025-13601 Glib: integer overflow in in g_escape_uri_string() 7.7 high
CVE-2025-12638 Path Traversal Vulnerability in keras-team/keras via Tar Archive Extraction in keras.utils.get_file() 7.6 high
CVE-2024-47866 RGW DoS attack with empty HTTP header in S3 object copy 7.5 high
CVE-2025-12863 Libxml2: namespace use-after-free in xmlsettreedoc() function of libxml2 7.5 high
CVE-2025-47913 Potential denial of service in golang.org/x/crypto/ssh/agent 7.5 high
CVE-2025-59777 NULL pointer dereference vulnerability exists in GNU libmicrohttpd v1.0.2 and earlier. The vulnerability was fixed in commit ff13abc on the master branch of the libmicrohttpd Git repository, after the v1.0.2 tag. A specially crafted packet sent by an attacker could cause a denial-of-service (DoS) condition. 7.5 high
CVE-2025-62689 NULL pointer dereference vulnerability exists in GNU libmicrohttpd v1.0.2 and earlier. The vulnerability was fixed in commit ff13abc on the master branch of the libmicrohttpd Git repository, after the v1.0.2 tag. A specially crafted packet sent by an attacker could cause a denial-of-service (DoS) condition. 7.5 high
CVE-2025-60704 Windows Kerberos Elevation of Privilege Vulnerability 7.5 high
CVE-2024-25621 containerd affected by a local privilege escalation via wide permissions on CRI directory 7.3 high
CVE-2025-52881 runc: LSM labels can be bypassed with malicious config using dummy procfs files 7.3 high
CVE-2025-59504 Azure Monitor Agent Remote Code Execution Vulnerability 7.3 high
CVE-2025-40190 ext4: guard against EA inode refcount underflow in xattr update 7.1 high
CVE-2025-40201 kernel/sys.c: fix the racy usage of task_lock(tsk->group_leader) in sys_prlimit64() paths 7.1 high
CVE-2025-40204 sctp: Fix MAC comparison to be constant-time 7.1 high
CVE-2025-64720 LIBPNG is vulnerable to a buffer overflow in `png_image_read_composite` via incorrect palette premultiplication 7.1 high
CVE-2025-65018 LIBPNG is vulnerable to a heap buffer overflow in `png_combine_row` triggered via `png_image_finish_read` 7.1 high
CVE-2025-60726 Microsoft Excel Information Disclosure Vulnerability 7.1 high
CVE-2025-62202 Microsoft Excel Information Disclosure Vulnerability 7.1 high
CVE-2025-59506 DirectX Graphics Kernel Elevation of Privilege Vulnerability 7.0 high
CVE-2025-59507 Windows Speech Runtime Elevation of Privilege Vulnerability 7.0 high
CVE-2025-59508 Windows Speech Recognition Elevation of Privilege Vulnerability 7.0 high
CVE-2025-59515 Windows Broadcast DVR User Service Elevation of Privilege Vulnerability 7.0 high
CVE-2025-60717 Windows Broadcast DVR User Service Elevation of Privilege Vulnerability 7.0 high
CVE-2025-60719 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability 7.0 high
CVE-2025-62213 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability 7.0 high
CVE-2025-62215 Windows Kernel Elevation of Privilege Vulnerability 7.0 high Yes
CVE-2025-62217 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability 7.0 high
CVE-2025-62218 Microsoft Wireless Provisioning System Elevation of Privilege Vulnerability 7.0 high
CVE-2025-62219 Microsoft Wireless Provisioning System Elevation of Privilege Vulnerability 7.0 high
CVE-2025-62449 Microsoft Visual Studio Code CoPilot Chat Extension Security Feature Bypass Vulnerability 6.8 high
CVE-2025-47179 Configuration Manager Elevation of Privilege Vulnerability 6.7 high
CVE-2025-60708 Storvsp.sys Driver Denial of Service Vulnerability 6.5 high
CVE-2025-60722 Microsoft OneDrive for Android Elevation of Privilege Vulnerability 6.5 high
CVE-2025-62206 Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability 6.5 high
CVE-2025-60723 DirectX Graphics Kernel Denial of Service Vulnerability 6.3 high
CVE-2025-59240 Microsoft Excel Information Disclosure Vulnerability 5.5 high
CVE-2025-59509 Windows Speech Recognition Information Disclosure Vulnerability 5.5 high
CVE-2025-59510 Windows Routing and Remote Access Service (RRAS) Denial of Service Vulnerability 5.5 high
CVE-2025-59513 Windows Bluetooth RFCOM Protocol Driver Information Disclosure Vulnerability 5.5 high
CVE-2025-60706 Windows Hyper-V Information Disclosure Vulnerability 5.5 high
CVE-2025-62208 Windows License Manager Information Disclosure Vulnerability 5.5 high
CVE-2025-62209 Windows License Manager Information Disclosure Vulnerability 5.5 high
CVE-2025-62453 GitHub Copilot and Visual Studio Code Security Feature Bypass Vulnerability 5.0 high
CVE-2025-60728 Microsoft Excel Information Disclosure Vulnerability 4.3 high
CVE-2025-31133 runc container escape via "masked path" abuse due to mount race conditions — high
CVE-2025-52565 container escape due to /dev/console mount and related races — high
CVE-2025-64324 KubeVirt Vulnerable to Arbitrary Host File Read and Write — high
CVE-2025-66031 node-forge ASN.1 Unbounded Recursion — high
CVE-2025-11230 Denial of service vulnerability in HAProxy mjson library 7.5 medium
CVE-2025-11935 Forward Secrecy Violation in WolfSSL TLS 1.3 7.5 medium
CVE-2025-40158 ipv6: use RCU in ip6_output() 7.1 medium
CVE-2025-10966 missing SFTP host verification with wolfSSH 6.8 medium
CVE-2025-12969 CVE-2025-12969 6.5 medium
CVE-2025-64433 KubeVirt Arbitrary Container File Read 6.5 medium
CVE-2025-40173 net/ip6_tunnel: Prevent perpetual tunnel growth 6.2 medium
CVE-2025-40213 Bluetooth: MGMT: fix crash in set_mesh_sync and set_mesh_complete 6.1 medium
CVE-2025-64505 LIBPNG is vulnerable to a heap buffer overflow in `png_do_quantize` via malformed palette index 6.1 medium
CVE-2025-64506 LIBPNG is vulnerable to a heap buffer over-read in `png_write_image_8bit` with grayscale+alpha or RGB/RGBA images 6.1 medium
CVE-2025-61915 OpenPrinting CUPS vulnerable to stack based out-of-bound write 6.0 medium
CVE-2025-12818 PostgreSQL libpq undersizes allocations, via integer wraparound 5.9 medium
CVE-2025-12748 Libvirt: denial of service in xml parsing 5.5 medium
CVE-2025-13193 Libvirt: information disclosure via world-readable vm snapshots 5.5 medium
CVE-2025-40107 can: hi311x: fix null pointer dereference when resuming from sleep before interface was enabled 5.5 medium
CVE-2025-40136 crypto: hisilicon/qm - request reserved interrupt for virtual function 5.5 medium
CVE-2025-40146 blk-mq: fix potential deadlock while nr_requests grown 5.5 medium
CVE-2025-40149 tls: Use __sk_dst_get() and dst_dev_rcu() in get_netdev_for_sock(). 5.5 medium
CVE-2025-40164 usbnet: Fix using smp_processor_id() in preemptible code warnings 5.5 medium
CVE-2025-40167 ext4: detect invalid INLINE_DATA + EXTENTS flag combination 5.5 medium
CVE-2025-40168 smc: Use __sk_dst_get() and dst_dev_rcu() in smc_clc_prfx_match(). 5.5 medium
CVE-2025-40178 pid: Add a judgment for ns null in pid_nr_ns 5.5 medium
CVE-2025-40179 ext4: verify orphan file size is not too big 5.5 medium
CVE-2025-40180 mailbox: zynqmp-ipi: Fix out-of-bounds access in mailbox cleanup loop 5.5 medium
CVE-2025-40187 net/sctp: fix a null dereference in sctp_disposition sctp_sf_do_5_1D_ce() 5.5 medium
CVE-2025-40188 pwm: berlin: Fix wrong register in suspend/resume 5.5 medium
CVE-2025-40192 Revert "ipmi: fix msg stack when IPMI is disconnected" 5.5 medium
CVE-2025-40193 xtensa: simdisk: add input size check in proc_write_simdisk 5.5 medium
CVE-2025-40194 cpufreq: intel_pstate: Fix object lifecycle issue in update_qos_request() 5.5 medium
CVE-2025-40195 mount: handle NULL values in mnt_ns_release() 5.5 medium
CVE-2025-40197 media: mc: Clear minor number before put device 5.5 medium
CVE-2025-40200 Squashfs: reject negative file sizes in squashfs_read_inode() 5.5 medium
CVE-2025-40202 ipmi: Rework user message limit handling 5.5 medium
CVE-2025-40206 netfilter: nft_objref: validate objref and objrefmap expressions 5.5 medium
CVE-2025-40207 media: v4l2-subdev: Fix alloc failure check in v4l2_subdev_call_state_try() 5.5 medium
CVE-2025-40210 Revert "NFSD: Remove the cap on number of operations per NFSv4 COMPOUND" 5.5 medium
CVE-2025-60753 An issue was discovered in libarchive bsdtar before version 3.8.1 in function apply_substitution in file tar/subst.c when processing crafted -s substitution rules. This can cause unbounded memory allocation and lead to denial of service (Out-of-Memory crash). 5.5 medium
CVE-2025-10158 Rsync: Out of bounds array access via negative index 5.4 medium
CVE-2025-11936 Potential DoS Vulnerability through Multiple KeyShareEntry with Same Group in TLS 1.3 ClientHello 5.3 medium
CVE-2025-12875 mruby array.c ary_fill_exec out-of-bounds write 5.3 medium
CVE-2025-13120 mruby array.c sort_cmp use after free 5.3 medium
CVE-2025-64435 KubeVirt VMI Denial-of-Service (DoS) Using Pod Impersonation 5.3 medium
CVE-2025-64436 KubeVirt Excessive Role Permissions Could Enable Unauthorized VMI Migrations Between Nodes 5.3 medium
CVE-2025-58436 OpenPrinting CUPS slow client can halt cupsd, leading to a possible DoS attack 5.1 medium
CVE-2025-64713 WebAssembly Micro Runtime frame_offset_bottom array bounds overflow in fast Interpreter mode when handling GET_GLOBAL(I32) followed by if opcode 5.1 medium

Microsoft’s November 11, 2025 Patch Tuesday release covers 184 CVEs: 13 rated critical, 92 rated important, and 62 rated moderate. Of these, none are currently listed as actively exploited.

Severity Breakdown

Severity Count
Critical 13
Important 92
Moderate 62
Actively exploited (CISA KEV) 0

Highest-Severity Vulnerabilities

Top 20 of 184 total, by CVSS/severity:

CVE Title CVSS
CVE-2025-49752 Azure Bastion Elevation of Privilege Vulnerability 10.0
CVE-2025-40165 media: nxp: imx8-isi: m2m: Fix streaming cleanup on release 9.8
CVE-2025-40172 accel/qaic: Treat remaining == 0 as error in find_and_map_user_pages() 9.8
CVE-2025-59245 Microsoft SharePoint Online Elevation of Privilege Vulnerability 9.8
CVE-2025-64657 Azure Application Gateway Elevation of Privilege Vulnerability 9.8
CVE-2025-60724 GDI+ Remote Code Execution Vulnerability 9.8
CVE-2025-64656 Azure Application Gateway Elevation of Privilege Vulnerability 9.4
CVE-2025-60876 BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). 9.4
CVE-2025-64655 Dynamics OmniChannel SDK Storage Containers Elevation of Privilege Vulnerability 8.8
CVE-2025-12970 CVE-2025-12970 8.8
CVE-2025-13226 Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) 8.8
CVE-2025-59499 Microsoft SQL Server Elevation of Privilege Vulnerability 8.8
CVE-2025-62220 Windows Subsystem for Linux GUI Remote Code Execution Vulnerability 8.8
CVE-2025-62222 Agentic AI and Visual Studio Code Remote Code Execution Vulnerability 8.8
CVE-2025-62210 Dynamics 365 Field Service (online) Spoofing Vulnerability 8.7
CVE-2025-62211 Dynamics 365 Field Service (online) Spoofing Vulnerability 8.7
CVE-2025-62207 Azure Monitor Elevation of Privilege Vulnerability 8.6
CVE-2025-12816 CVE-2025-12816 8.6
CVE-2025-13227 Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) 8.6
CVE-2025-13230 Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) 8.6

CVSS scores are sourced directly from Microsoft’s CVRF data as of November 11, 2025; exploitation status is cross-checked against CISA’s KEV catalog. Later re-scoring by NVD can shift a CVE’s score after this report was generated.

Why This Matters

No vulnerabilities in this release are yet listed in CISA’s Known Exploited Vulnerabilities catalog, but that can change quickly once a patch is public and attackers reverse-engineer it. Organizations should prioritize the critical- and important-rated CVEs above, especially any with public proof-of-concept exploits.

Frequently Asked Questions

How many vulnerabilities did Microsoft patch in November 2025? 184 CVEs, per Microsoft’s November 11, 2025 Patch Tuesday release.

Were any November 2025 Patch Tuesday vulnerabilities actively exploited? Not as of November 11, 2025, per CISA’s Known Exploited Vulnerabilities (KEV) catalog — this can change as exploitation is discovered after release.


Data sourced from Microsoft Security Response Center (MSRC) CVRF v3.0 and CISA’s Known Exploited Vulnerabilities (KEV) catalog, aggregated November 11, 2025. See more vulnerability research.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 Microsoft Security Response Center (MSRC)
02 CISA Known Exploited Vulnerabilities (KEV) Catalog

Related intelligence


Analyst tools