Patch data provided by:
|
 |
Identifier
|
Vendor/
Product
|
Affected Versions
|
Date Released
by Vendor
|
Vulnerability Info
|
Vender Severity / Our Recommedation
|
Multiple CVE's
|
Adobe Acrobat Reader
|
Reader/DC Continuous
Win - 25.001.20672 and earlier
Mac - 25.001.20668 and earlier
Classic 2024
24.001.30254 and earlier
Classic 2020
20.005.30774 and earlier
|
9/9/2025
|
Arbitrary Code Execution,
Security Feature Bypass |
Critical Priority 3: Update at admins discretion
|
Multiple CVE's
|
Adobe After Effects
|
24.6.7 and earlier
25.3 and earlier
|
9/9/2025
|
Memory Exposure |
Important Priority 3: Update at admins discretion
|
CVE-2025-54242
|
Adobe Premiere Pro
|
25.3 and earlier
24.6.5 and earlier
|
9/9/2025
|
Arbitrary Code Execution |
Critical Priority 3: Update at admins discretion
|
CVE-2025-54236
|
Adobe Commerce
|
Commerce/Magento Open Source 2.4.9-alpha2 and earlier
2.4.8-p2 and earlier
2.4.7-p7 and earlier
2.4.6-p12 and earlier
2.4.5-p14 and earlier
2.4.4-p15 and earlier (not Magento)
Commerce B2B
1.5.3-alpha2 and earlier
1.5.2-p2 and earlier
1.4.2-p7 and earlier
1.3.4-p14 and earlier
1.3.3-p15 and earlier
|
9/9/2025
|
Security Feature Bypass |
Critical Priority 2: Update within 30 days
|
Multiple CVE's
|
Adobe Substance 3D Viewer
|
0.25.1 and earlier
|
9/9/2025
|
Arbitrary Code Execution |
Critical Priority 3: Update at admin's discretion
|
Multiple CVE's
|
Adobe Substance 3D Modeler
|
1.22.2 and earlier
|
9/9/2025
|
Arbitrary Code Execution |
Critical Priority 3: Update at admin's discretion
|
Multiple CVE's
|
Adobe Experience Manager
|
6.5 LTS SP1 and earlier
6.5.23 and earlier
AEM Cloud Service
|
9/9/2025
|
Security Feature Bypass |
Critical Priority 3: Update at admins discretion
|
CVE-2025-54256
|
Adobe Dreamweaver
|
21.5 and earlier
|
9/9/2025
|
Arbitrary Code Execution |
Critical Priority 3: Update at admins discretion
|
CVE-2025-54261
|
Adobe ColdFusion
|
2025 Update 3 and earlier
2023 Update 15 and earlier
2021 Update 21 and earlier
|
9/9/2025
|
Arbitrary File System Write |
Critical Priority 1: Update within 72 hours
|
Multiple CVE's
|
Apple iPadOS
|
Before 26
|
9/15/2025
|
Application Termination,
Data Leak,
DoS,
Keylogging,
Logic Issue,
Memory Corruption,
Out of Bounds,
Sandbox Breakout,
Security Feature Bypass,
System Termination,
Type Confusion,
Unexpected URL Redirect,
Use After Free |
Zero Day - Update ASAP - See above for more information about which devices are affected
|
Multiple CVE's
|
Apple watchOS
|
Before 26
|
9/15/2025
|
Application Termination,
Data Leak,
DoS,
Logic Issue,
Memory Corruption,
Out of Bounds,
Sandbox Breakout,
Security Feature Bypass |
Update when possible
|
Multiple CVE's
|
Apple macOS Sequoia
|
Before 15.7
|
9/15/2025
|
Application Termination,
Buffer Overflow,
Data Leak,
DoS,
Logic Issue,
Memory Corruption,
Out of Bounds,
Privilege Escalation,
Sandbox Breakout,
Security Feature Bypass,
System Termination,
User Confusion |
Update after testing
|
Multiple CVE's
|
Apple macOS
Sonoma
|
Before 14.8
|
9/15/2025
|
Application Termination,
Data Leak,
DoS,
Logic Issue,
Memory Corruption,
Out of Bounds,
Privilege Escalation,
Race Condition,
Sandbox Breakout,
Security Feature Bypass,
System Termination,
User Confusion |
Update after testing
|
Multiple CVE's
|
Apple macOS Tahoe
|
Before 26
|
9/15/2025
|
Application Termination,
Data Leak,
DoS,
Logic Issue,
Memory Corruption,
Out of Bounds,
Privilege Escalation,
Race Condition,
Sandbox Breakout,
Security Feature Bypass,
Spoofing,
System Termination,
User Confusion |
Update after testing
|
Multiple CVE's
|
Apple Safari
|
Before 26
|
9/15/2025
|
Application Termination,
Spoofing,
Unauthorized Access,
URL Redirection |
Update when possible
|
Multiple CVE's
|
Apple Xcode
|
Before 26
|
9/15/2025
|
Process Crash,
Remote Code Execution,
Sandbox Breakout |
Update when possible
|
Multiple CVE's
|
Apple visionOS
|
Before 26
|
9/15/2025
|
Application Termination,
Data Leak,
DoS,
Logic Issue,
Memory Corruption,
Out of Bounds,
Privilege Escalation |
Update when possible
|
Multiple CVE's
|
Google
Chrome
|
Before 140.0.7339.185 (Linux)
Before 140.0.7339.185/.186 (Windows/Mac)
|
9/17/2025
|
Heap Buffer Overflow,
Inappropriate Implementation,
Type Confusion,
Use After Free |
Zero Day - Update ASAP |
Multiple CVE's
|
Mozilla Thunderbird
|
Before 143
|
9/16/2025
|
Arbitrary Code Execution,
Information Disclosure,
Integer Overflow,
Memory Corruption,
Sandbox Breakout,
Security Feature Bypass,
Use After Free |
Update after testing
|
Multiple CVE's
|
Mozilla Firefox
|
Before 143
|
9/16/2025
|
Arbitrary Code Execution,
Information Disclosure,
Integer Overflow,
Memory Corruption,
Sandbox Breakout,
Security Feature Bypass,
Spoofing,
Use After Free |
Update after testing
|
Multiple CVE's
|
Mozilla Firefox ESR
|
Before 140.3
|
9/16/2025
|
Arbitrary Code Execution,
Information Disclosure,
Integer Overflow,
Memory Corruption,
Sandbox Breakout,
Security Feature Bypass,
Use After Free |
Update after testing
|
CVE-2025-10290
|
Mozilla Focus for iOS
|
Before 143
|
9/16/2025
|
Spoofing |
Update after testing
|
CVE-2025-49458
|
Zoom Workplace Clients
|
Workplace for Windows, macOS, Linux before 6.5
Workplace VDI Client for Windows before 6.3.14/6.4.12
Rooms for Windows, macOS, iOS before 6.5
Rooms Controller for Windows, macOS, Linux before 6.5
Meeting SDK for Windows, macOS, Linux before 6.5
|
9/9/2025
|
Buffer Overflow,
Denial of Service |
Medium - Update after testing
|
CVE-2025-49459
|
Zoom Workplace for Windows ARM
|
Before 6.5
|
9/9/2025
|
Privilege Escalation via Local Access |
High - Update after testing
|
CVE-2025-49461
|
Zoom Workplace Clients
|
Workplace Desktop for Windows, macOS, Linux before 6.5
Workplace App for iOS before 6.5
Workplace VDI Client for Windows before 6.3.14/6.4.12
Rooms Controller and Meeting SDK for Windows, macOS, Linux, Android before 6.5
Rooms Client for Windows, macOS, Android, iPad before 6.5
|
9/9/2025
|
Cross Site Scripting,
Denial of Service |
Medium - Update after testing
|
CVE-2025-58134
|
Zoom Workplace Clients
|
Workplace Desktop, Rooms Controller, Rooms Client and Meeting SDK for Windows before 6.5
Workplace VDI Client for Windows before 6.3.14/6.4.12
|
9/9/2025
|
Incorrect Authorization |
Medium - Update after testing
|
CVE-2025-58131
|
Zoom Workplace VDI Plugin
|
macOS Universal Installer for VMware Horizon before 6.4.10/6.2.15/6.3.12
|
9/9/2025
|
Race Condition,
Information Disclosure |
Medium - Update after testing
|
CVE-2025-49460
|
Zoom Workplace Clients
|
Workplace Desktop for Windows, macOS, Linux before 6.5
Workplace App for iOS before 6.5
Workplace VDI Client for Windows before 6.3.14/6.4.12
Rooms Controller and Meeting SDK for Windows, macOS, Linux, Android before 6.5
Rooms Client for Windows, macOS, Android, iPad before 6.5
|
9/9/2025
|
Uncontrolled Resource Consumption,
Denial of Service |
Medium - Update after testing
|
CVE-2025-58135
|
Zoom Workplace Clients
|
Workplace Desktop, Rooms Controller, Rooms Client and Meeting SDK for Windows before 6.5
Workplace VDI Client for Windows before 6.3.14/6.4.12
|
9/9/2025
|
Information Disclosure |
Medium - Update after testing
|