Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Microsoft’s 2025 Patch Tuesday releases addressed 1,130 CVEs, and Tenable Research Special Operations says 24 of 41 zero-days in its review were exploited in the wild. Those figures make exploitation and exposure better guides to urgency than a vulnerability count alone. The examples below cover the 2025 calendar year; a separate update notes documented activity through July 2026, not a complete 2026 roundup.

What the 2025 numbers do—and don’t—show

Tenable Research Special Operations counted 1,130 CVEs addressed in Microsoft Patch Tuesday releases during 2025, 12% more than its 1,009 count for 2024. This is a count of Patch Tuesday CVEs, not a verified total of every Microsoft vulnerability disclosed through every channel.

In that same analysis, Tenable identified 41 zero-days—defined there as vulnerabilities disclosed before a vendor patch—and reported that 24 were exploited in the wild. Elevation-of-privilege flaws made up 38.3% of the Patch Tuesday vulnerabilities Tenable counted, compared with 30.8% for remote-code-execution flaws. Among the 24 exploited zero-days, 62.5% were elevation-of-privilege vulnerabilities.

These figures do not establish which flaw was the single most dangerous for every organization. Microsoft advises triaging by exposure and impact, and considering signals such as exploitability, public exploit code and observed exploitation. A flaw in an internet-exposed server or an actively exploited path can demand attention ahead of a higher raw severity score on a system that is not exposed.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Which Microsoft vulnerabilities were actively exploited?

Tenable’s 2025 retrospective documents these notable examples; it does not present them as a definitive top-five ranking. The affected deployment and whether compromise may already have occurred matter as much as the vulnerability category.

Vulnerability What Tenable reported Why it matters to response
CVE-2025-24983, Windows Win32 Kernel Subsystem elevation of privilege Used with the PipeMagic backdoor to spread ransomware. Privilege escalation can help an attacker who already has a foothold extend control; investigate for related activity as well as applying the fix.
CVE-2025-29824, Windows Common Log File System Driver elevation of privilege Exploited by Storm-2460, also known as RansomEXX; PipeMagic was also used to spread ransomware. Observed ransomware activity makes this more than a theoretical patching issue.
CVE-2025-26633, Microsoft Management Console security feature bypass Water Gamayu, also known as EncryptHub and Larva-208, exploited it to deploy the MSC EvilTwin trojan loader. A security-feature bypass can enable a malicious delivery path; review detections and endpoint activity alongside patch status.
CVE-2025-33053, Internet Shortcut Files remote code execution Stealth Falcon, also known as FruityArmor, exploited it to deploy Horus Agent malware. Check for malicious shortcut-file activity and investigate suspected execution, not just whether the update is present.
CVE-2025-49704 and CVE-2025-49706, SharePoint remote code execution and spoofing Tenable reported exploitation by multiple named groups in activity described as the ToolShell chain. For exposed on-premises SharePoint, response may need to include compromise assessment and hardening, not only update installation.

What changed in the 2026 update?

This is a dated update, not a full-year count. In a July 14, 2026 alert, CISA said CVE-2026-32201, CVE-2026-45659 and CVE-2026-56164 were being actively exploited against supported on-premises SharePoint Server Subscription Edition, 2019 and 2016. CISA described post-exploitation activity that included theft of IIS machine keys, deserialization techniques, persistence and malware deployment.

Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

In a July 14, 2026 KEV notice, CISA also named Microsoft AD FS CVE-2026-56155 and SharePoint Server CVE-2026-56164 among four additions based on evidence of active exploitation. The notice establishes exploitation as a prioritization signal; it should not be read as evidence that every affected installation was compromised.

Why patching SharePoint may not be enough

Installing an update closes a vulnerability; it does not establish that an attacker did not exploit the server beforehand. CISA’s July 14, 2026 SharePoint guidance therefore pairs patching and successful installation verification with investigation, monitoring and hardening.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
  1. Apply the update and verify it: install the applicable Microsoft security update, confirm that installation completed successfully, and shorten patch cycles where possible.
  2. Check for compromise: review relevant detections and logs, investigate suspicious activity, and hunt for intrusion artifacts before assuming the server is clean.
  3. Handle IIS machine keys carefully: remediate intrusion artifacts before rotating keys. CISA warns that key harvesters could steal replacement keys if they remain on the server.
  4. Strengthen SharePoint protections: enable AMSI integration for each SharePoint web application and use Full Mode where feasible.
  5. Reduce exposure: avoid direct internet exposure unless necessary. Where public access is required, place the server behind an authenticated Layer 7 reverse proxy or equivalent; block external access to Central Administration and restrict farm and database communications to necessary systems.

This sequence addresses both the vulnerable software and the possibility of an existing intrusion. A successful patch installation is necessary, but it is not a substitute for investigating signs of prior exploitation.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Which Microsoft bugs should you patch first?

Use a risk-based queue rather than sorting by severity or CVE count alone. Microsoft’s Security Update Guide signals include exploitability, public exploit code and observed exploitation; CISA’s risk framework also considers exposure, KEV status, whether exploitation can be automated and technical impact.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
  1. Start with confirmed exploitation and exposed systems. Prioritize applicable flaws known to be exploited, especially on internet-facing services such as on-premises SharePoint.
  2. Check the deployment and support status. Confirm the product, edition and version are affected and supported. Unsupported technology remains an exposure that a patch-priority list cannot solve by itself.
  3. Assess impact and attack path. Remote code execution, privilege escalation and security-feature bypass describe different consequences; consider how an attacker could reach the vulnerable system and what access the flaw could provide.
  4. Verify remediation, then investigate when warranted. Track successful update installation. For exploited flaws or suspicious activity, add log review and compromise assessment rather than treating patch compliance as proof of safety.

Update cadence differs by deployment model. Microsoft describes Patch Tuesday as the predictable rhythm for on-premises software, while PaaS and SaaS services update continuously, often without customer action. Out-of-band updates remain possible when circumstances warrant them, so administrators should be prepared to act outside the monthly cycle.

What tends to be overlooked?

The evidence supports treating overlooked risk as an operational pattern, not attaching that label to one specific CVE. A vulnerability can be missed when teams focus on monthly totals or severity labels but fail to account for internet exposure, confirmed exploitation, the possibility of an existing intrusion or software that has passed end of support.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

CISA’s FY2024–FY2025 Vulnerability Review summary says attackers often scan for and exploit simple, known flaws. It highlights poor patching and continued use of end-of-support technology as contributors to compromise, alongside commonly targeted issues such as improper input validation and memory-safety flaws. The practical lesson is to maintain an accurate inventory, identify exposed and unsupported systems, and verify remediation—not merely to watch for unusually complex bugs.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.