Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
actively-exploited-vulnerabilitywidely-deployed-product-advisoryrapid-weaponizationstate-sponsored-espionage

Record Surge in CVE Disclosures and Microsoft Vulnerabilities in 2025

Updated 3mo agoFirst seen Dec 30, 20252 sources

In 2025, the cybersecurity landscape was marked by an unprecedented surge in vulnerability disclosures, with nearly 49,209 CVEs published—representing a 43% increase over the previous year. Microsoft alone issued mitigations for 1,246 CVEs, including 158 rated as critical, and faced 41 zero-day vulnerabilities. Security experts noted that while the volume of vulnerabilities reached new highs, the real risk stemmed from a small subset that were actively exploited, particularly those affecting Microsoft platforms and edge devices. Attackers increasingly leveraged AI and new tactics to exploit vulnerabilities faster, often timing attacks around Patch Tuesday cycles to maximize impact before organizations could apply updates.

The overwhelming number of vulnerabilities forced security teams to rethink their prioritization strategies, as traditional severity ratings like CVSS proved insufficient for predicting exploitation. Instead, models such as the Exploit Prediction Scoring System (EPSS) and asset criticality became essential for identifying which vulnerabilities posed the greatest risk. State-sponsored actors and ransomware groups were responsible for a significant portion of exploitation activity, with remote code execution and privilege escalation flaws being the most targeted. Experts emphasized the need for rapid, risk-based patching and a shift away from patching solely based on severity scores, as attackers focused on speed, exposure, and critical assets rather than the sheer number of vulnerabilities disclosed.

Share:
Record Surge in CVE Disclosures and Microsoft Vulnerabilities in 2025
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

7 events from the most recent confirmed update back to the earliest known activity.

7 EVENTS
Dec 30, 20256mo ago

Multiple Microsoft zero-days and lower-scored flaws see active exploitation in 2025

During 2025, several Microsoft vulnerabilities, including ToolShell (CVE-2025-53770), CVE-2025-24993, CVE-2025-24990, CVE-2025-62221, CVE-2025-53779, CVE-2025-26633, CVE-2025-33053, and CVE-2025-30377, were highlighted as actively exploited or especially dangerous. Experts noted that some lower-scored flaws still enabled serious outcomes such as privilege escalation, malware deployment, Preview Pane exploitation, and domain compromise.

Microsoft addresses 1,246 CVEs during 2025

Across 2025, Microsoft patched 1,246 CVEs, including 158 critical flaws and 41 zero-days. Elevation-of-privilege and remote-code-execution issues made up a significant share of the year's Microsoft vulnerability landscape.

Dec 29, 20256mo ago

Security guidance shifts toward EPSS- and asset-aware prioritization for 2026

By the end of 2025, experts recommended moving away from patch-count metrics toward remediation of exploitable risks on critical assets. EPSS, asset criticality, and governance-backed risk acceptance were presented as the basis for vulnerability management in 2026.

CISA KEV list emerges as key indicator for active vulnerability risk

By late 2025, the CISA Known Exploited Vulnerabilities list was identified as the most reliable signal of active threat exposure and a trigger for incident-level remediation. Security guidance increasingly emphasized KEV-led prioritization over patching based only on volume or CVSS severity.

State-backed and ransomware exploitation intensifies in 2025

During 2025, state-sponsored actors were responsible for more than half of observed exploitation activity, while ransomware and zero-day attacks also rose sharply. The trend reflected a shift toward more targeted and operationally impactful exploitation.

Attackers increasingly exploit a small subset of high-risk flaws in 2025

Throughout 2025, most real-world breaches were driven by a relatively small set of vulnerabilities rather than the full volume of disclosed CVEs. Public proof-of-concept availability, likelihood of exploitation, and exposure on critical assets such as identity systems and edge devices were key factors.

Published CVE count rises to 49,209 in 2025

In 2025, the number of published CVEs reached 49,209, representing a 43% increase over 2024. The increase was attributed to growing software complexity, expanding open-source dependencies, and more CVE Numbering Authorities.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.