In 2025, the cybersecurity landscape was marked by an unprecedented surge in vulnerability disclosures, with nearly 49,209 CVEs published—representing a 43% increase over the previous year. Microsoft alone issued mitigations for 1,246 CVEs, including 158 rated as critical, and faced 41 zero-day vulnerabilities. Security experts noted that while the volume of vulnerabilities reached new highs, the real risk stemmed from a small subset that were actively exploited, particularly those affecting Microsoft platforms and edge devices. Attackers increasingly leveraged AI and new tactics to exploit vulnerabilities faster, often timing attacks around Patch Tuesday cycles to maximize impact before organizations could apply updates.
The overwhelming number of vulnerabilities forced security teams to rethink their prioritization strategies, as traditional severity ratings like CVSS proved insufficient for predicting exploitation. Instead, models such as the Exploit Prediction Scoring System (EPSS) and asset criticality became essential for identifying which vulnerabilities posed the greatest risk. State-sponsored actors and ransomware groups were responsible for a significant portion of exploitation activity, with remote code execution and privilege escalation flaws being the most targeted. Experts emphasized the need for rapid, risk-based patching and a shift away from patching solely based on severity scores, as attackers focused on speed, exposure, and critical assets rather than the sheer number of vulnerabilities disclosed.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
During 2025, several Microsoft vulnerabilities, including ToolShell (CVE-2025-53770), CVE-2025-24993, CVE-2025-24990, CVE-2025-62221, CVE-2025-53779, CVE-2025-26633, CVE-2025-33053, and CVE-2025-30377, were highlighted as actively exploited or especially dangerous. Experts noted that some lower-scored flaws still enabled serious outcomes such as privilege escalation, malware deployment, Preview Pane exploitation, and domain compromise.
Across 2025, Microsoft patched 1,246 CVEs, including 158 critical flaws and 41 zero-days. Elevation-of-privilege and remote-code-execution issues made up a significant share of the year's Microsoft vulnerability landscape.
By the end of 2025, experts recommended moving away from patch-count metrics toward remediation of exploitable risks on critical assets. EPSS, asset criticality, and governance-backed risk acceptance were presented as the basis for vulnerability management in 2026.
By late 2025, the CISA Known Exploited Vulnerabilities list was identified as the most reliable signal of active threat exposure and a trigger for incident-level remediation. Security guidance increasingly emphasized KEV-led prioritization over patching based only on volume or CVSS severity.
During 2025, state-sponsored actors were responsible for more than half of observed exploitation activity, while ransomware and zero-day attacks also rose sharply. The trend reflected a shift toward more targeted and operationally impactful exploitation.
Throughout 2025, most real-world breaches were driven by a relatively small set of vulnerabilities rather than the full volume of disclosed CVEs. Public proof-of-concept availability, likelihood of exploitation, and exposure on critical assets such as identity systems and edge devices were key factors.
In 2025, the number of published CVEs reached 49,209, representing a 43% increase over 2024. The increase was attributed to growing software complexity, expanding open-source dependencies, and more CVE Numbering Authorities.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.