Find notable cyber news and cases, enriched with sources, timelines, and signals.

Microsoft October 2025 Patch Tuesday security updates

Security Patch Release
First reported
Last updated
Happening score
H score 59
3 unique sources, 3 articles

Summary

Hide ▲

Microsoft's October 2025 Patch Tuesday delivers security updates for 172 flaws, including six zero-days, creating immediate patching priority for Windows and related Microsoft products. The bundle includes eight Critical vulnerabilities, with both remote code execution and elevation of privilege issues in scope. Microsoft also says Windows 10 reaches end of support today, which makes this the last free security-update cycle for the operating system. One fix removes the ltmdm64.sys Agere Modem driver, which can stop related Fax modem hardware from functioning.

Related Happenings

Microsoft security patch release for CVE-2026-41091 and CVE-2026-45498

Security Patch Release
First: 21.05.2026 10:49 Last: 21.05.2026 10:49 Sources 1

About this happening: Microsoft rolled out security updates for Defender and related malware protection components to address two zero-days: CVE-2026-41091 and CVE-2026-45498. The fixes cover affected...

Latest development: 21.05.2026 12:52

Microsoft released patches for Microsoft Defender Antimalware Platform version 4.18.26040.7 to address CVE-2026-41091, a link-following privilege-escalation flaw that can let an authorized attacker elevate privileges locally to System, and CVE-2026-45498, a denial-of-service flaw. Microsoft said both vulnerabilities were publicly disclosed and exploited in the wild as zero-days. CISA added both flaws to its Known Exploited Vulnerabilities (KEV) list and urged federal agencies to patch them by June 3.

Microsoft May 2026 Patch Tuesday release

Security Patch Release
First: 13.05.2026 13:36 Last: 13.05.2026 13:36 Sources 1

About this happening: Microsoft's **May 13, 2026 Patch Tuesday** release fixed **138 vulnerabilities** across its product portfolio, including **Windows**, **Azure**, and **Edge**. None of the flaws we...

Microsoft security patch release for CVE-2026-41089

Security Patch Release
First: 13.05.2026 00:46 Last: 13.05.2026 00:46 Sources 1

About this happening: **Microsoft** and other major software vendors shipped a heavy **May 2026** patch cycle, with fixes spanning **Windows**, **iOS**, **Firefox**, **Oracle** products, and **Chrome**...

Windows 10 KB5087544 extended security update

Security Patch Release
First: 12.05.2026 21:58 Last: 12.05.2026 21:58 Sources 1

About this happening: **Microsoft** released **Windows 10 KB5087544** for **Windows 10 ESU/LTSC systems**, addressing **May 2026 Patch Tuesday vulnerabilities** and a **Remote Desktop warnings** issue....

Microsoft Windows 11 mandatory Patch Tuesday updates (KB5089549, KB5087420)

Security Patch Release
First: 12.05.2026 21:09 Last: 12.05.2026 21:09 Sources 1

About this happening: Microsoft released **mandatory Windows 11 cumulative updates** for **KB5089549** and **KB5087420**, delivering the **May 2026 Patch Tuesday** fixes for **120 vulnerabilities** acr...

Timeline

  1. 14.10.2025 21:02 3 articles · 7mo ago

    Microsoft releases October 2025 Patch Tuesday updates

    Initial Disclosure

    Microsoft releases October 2025 security updates covering 172 flaws and six zero-days, including eight Critical vulnerabilities across Windows SMB Server, Microsoft SQL Server, Windows Remote Access Connection Manager, IGEL OS before 11, AMD EPYC SEV-SNP, and TCG TPM 2.0.

    Show sources
  2. 14.10.2025 21:02 1 articles · 7mo ago

    Microsoft removes the vulnerable Agere Modem driver

    Mitigation Patch Update

    Microsoft removes the vulnerable ltmdm64.sys Agere Modem driver in the October cumulative update after it was abused for local privilege escalation, and related Fax modem hardware ceases functioning.

    Show sources
  3. 14.10.2025 21:02 1 articles · 7mo ago

    Windows 10 reaches end of support

    Legal Policy Action Update

    Windows 10 reaches end of support today, ending free security updates for the operating system; consumers can enroll in one year of Extended Security Updates (ESU), and enterprises can enroll for up to three years.

    Show sources