Microsoft August 2025 Patch Tuesday fixes 111 flaws
Security Patch Release
Summary
Hide ▲
Show ▼
Microsoft rolled out August 2025 Patch Tuesday fixes for 111 security flaws across its software portfolio, including a publicly disclosed Windows Kerberos zero-day. The release spans Edge, Exchange Server hybrid deployments, and cloud services, and 16 vulnerabilities were rated Critical. Microsoft said some cloud-service issues in Azure OpenAI, Azure Portal, and Microsoft 365 Copilot BizChat had already been remediated and required no customer action.
Related Happenings
Microsoft Teams defaults on messaging safety protections for uncustomized tenants in January 2026
Security Tool/Service
First: 23.12.2025 15:23
Last: 23.12.2025 15:23
Sources 1
About this happening:
**Microsoft Teams** will turn on **messaging safety features by default** starting **January 12, 2026**, expanding protection against **malicious content** for tenants on default...
Microsoft Teams defaults on messaging safety protections for uncustomized tenants in January 2026
Security Tool/ServiceAbout this happening: **Microsoft Teams** will turn on **messaging safety features by default** starting **January 12, 2026**, expanding protection against **malicious content** for tenants on default...
Exchange Online Exchange ActiveSync 16.1 cutoff
Advisory/Mitigation
First: 16.12.2025 14:53
Last: 16.12.2025 14:53
Sources 1
About this happening:
**Microsoft** will block **Exchange Online** access for **Exchange ActiveSync** devices below **16.1**, forcing administrators to update legacy mobile email clients before **March...
Exchange Online Exchange ActiveSync 16.1 cutoff
Advisory/MitigationAbout this happening: **Microsoft** will block **Exchange Online** access for **Exchange ActiveSync** devices below **16.1**, forcing administrators to update legacy mobile email clients before **March...
Microsoft bug bounty expands to critical flaws across online services
Security Tool/Service
First: 11.12.2025 18:00
Last: 11.12.2025 18:00
Sources 1
About this happening:
**Microsoft** expanded its **bug bounty program** to pay for **critical vulnerabilities** that directly affect **any of its online services**, increasing incentives to surface fla...
Microsoft bug bounty expands to critical flaws across online services
Security Tool/ServiceAbout this happening: **Microsoft** expanded its **bug bounty program** to pay for **critical vulnerabilities** that directly affect **any of its online services**, increasing incentives to surface fla...
Microsoft security patch release for CVE-2025-62221
Security Patch Release
First: 09.12.2025 20:38
Last: 09.12.2025 20:38
Sources 1
About this happening:
**Microsoft**'s **December 2025 Patch Tuesday** fixes **57 flaws**, including **CVE-2025-62221** and two publicly disclosed zero-days, reducing exposure to local privilege escalat...
Microsoft security patch release for CVE-2025-62221
Security Patch ReleaseAbout this happening: **Microsoft**'s **December 2025 Patch Tuesday** fixes **57 flaws**, including **CVE-2025-62221** and two publicly disclosed zero-days, reducing exposure to local privilege escalat...
Microsoft 365 desktop app download disruption
Service Disruption
First: 04.12.2025 15:18
Last: 04.12.2025 15:18
Sources 1
About this happening:
Microsoft is resolving a **service disruption** that is blocking **Microsoft 365 desktop app** downloads from the **Microsoft 365 homepage**, leaving affected users unable to inst...
Microsoft 365 desktop app download disruption
Service DisruptionAbout this happening: Microsoft is resolving a **service disruption** that is blocking **Microsoft 365 desktop app** downloads from the **Microsoft 365 homepage**, leaving affected users unable to inst...
Timeline
-
13.08.2025 11:47 1 articles · 9mo ago
Microsoft releases August 2025 Patch Tuesday fixes for 111 flaws
Mitigation Patch UpdateMicrosoft released fixes for 111 security flaws across its software portfolio, including CVE-2025-53779, a publicly disclosed Windows Kerberos privilege-escalation zero-day tied to relative path traversal and the BadSuccessor dMSA technique, and CVE-2025-53786 affecting Microsoft Exchange Server hybrid deployments. Microsoft also addressed 16 vulnerabilities in Microsoft Edge since the previous Patch Tuesday update.
Show sources
- Microsoft August 2025 Patch Tuesday Fixes Kerberos Zero-Day Among 111 Total New Flaws — thehackernews.com — 13.08.2025 11:47