Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
widely-deployed-product-advisoryactively-exploited-vulnerabilityproof-of-concept-releaseinternet-facing-service-vulnerability

Critical Vulnerabilities and Security Updates in November–December 2025

Updated 3mo agoFirst seen Dec 9, 20252 sources

Security researchers identified a significant drop in the number of critical vulnerabilities in November 2025, with only 10 high-impact CVEs requiring immediate attention, compared to 32 in October. Notable threats included two actively exploited FortiWeb vulnerabilities (CVE-2025-64446 and CVE-2025-58034), a Samsung image processing flaw (CVE-2025-21042) weaponized for zero-click Android attacks, and several vulnerabilities with public proof-of-concept code available. The vulnerabilities spanned products from Microsoft, Google, Oracle, WatchGuard, and others, with exploitation campaigns favoring quality over quantity.

In December 2025, Adobe and Microsoft released their final security updates of the year, addressing a large number of vulnerabilities across products such as Adobe Reader, ColdFusion, Experience Manager, and Creative Cloud Desktop. While Adobe patched 139 CVEs, most were cross-site scripting issues, and none were known to be under active attack at the time of release. Microsoft’s updates were also part of the regular Patch Tuesday cycle, emphasizing the ongoing need for organizations to remain vigilant and promptly apply security patches to mitigate risk from both newly disclosed and actively exploited vulnerabilities.

Share:
Critical Vulnerabilities and Security Updates in November–December 2025
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
Dec 9, 20257mo ago

Microsoft discloses active exploitation of CVE-2025-62221

As part of the December 9, 2025 security update, Microsoft identified CVE-2025-62221 in the Windows Cloud Files Mini Filter Driver as under active attack. The vulnerability affects all supported Windows versions.

Microsoft releases December 2025 Patch Tuesday updates

On December 9, 2025, Microsoft released patches for 56 new CVEs, or 70 including Chromium-related issues, affecting Windows, Office, Edge, Exchange, Azure, Copilot, and PowerShell. Three were rated Critical in the release.

Adobe releases December 2025 security updates for 139 CVEs

On December 9, 2025, Adobe published security updates covering 139 unique CVEs across Reader, ColdFusion, Experience Manager, Creative Cloud Desktop, and the DNG SDK. The release included several critical code-execution issues, though none were reported as under active attack.

Nov 1, 20258mo ago

Microsoft Windows kernel privilege-escalation flaw is actively exploited

In November 2025, Microsoft faced active exploitation of CVE-2025-62215, a kernel-level race condition that allowed privilege escalation. The flaw was listed among the month's critical vulnerabilities under real-world attack.

Fortinet FortiWeb vulnerabilities come under active exploitation

In November 2025, two critical Fortinet FortiWeb flaws, CVE-2025-64446 and CVE-2025-58034, were reported as actively exploited. They were among a small set of high-impact November vulnerabilities that were all observed under exploitation.

LANDFALL spyware weaponizes Samsung DNG flaw for zero-click Android attacks

In November 2025, the LANDFALL spyware campaign exploited Samsung image processing vulnerability CVE-2025-21042 to deliver zero-click Android attacks via WhatsApp-delivered DNG files. The activity targeted high-value individuals in Middle Eastern countries and demonstrated advanced capabilities including SELinux bypass and anti-forensics.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.