Microsoft released its September 2025 Patch Tuesday updates to address 81 vulnerabilities across its product portfolio, including 8 critical flaws, 72 important issues, and one vulnerability without a severity rating. The release included fixes for two vulnerabilities that were already being actively exploited in the wild, prompting calls for immediate patching.
One of the exploited flaws, CVE-2025-55234, affects the SMB Server component and enables privilege escalation through relay attack techniques that can capture authentication data for unauthorized access. The second, CVE-2024-21907, affects versions earlier than 13.0.1 of the third-party Newtonsoft.Json library bundled with Microsoft SQL Server and can be exploited remotely without authentication to trigger a denial of service via a StackOverflow exception in JsonConvert.DeserializeObject. Microsoft also advised defenders to enable SMB Server Signing and SMB Server Extended Protection for Authentication as mitigations for the SMB issue, while warning that older devices may face compatibility problems.

See which actors are running it and whether you're in range.
1 event from the most recent confirmed update back to the earliest known activity.
Microsoft issued its September 2025 security updates, fixing 81 vulnerabilities across its product portfolio, including 8 critical flaws, 72 important flaws, and one without a severity rating. The release included fixes for two zero-day vulnerabilities that were being actively exploited in the wild.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.