Microsoft’s July 2025 Patch Tuesday Addresses 130 Vulnerabilities

Red | Vulnerability Report
Download PDF

Microsoft’s July 2025 Patch Tuesday rolls out fixes for 130 vulnerabilities, including several issues that demand immediate attention. Among them is CVE-2025-49719, an information disclosure flaw in Microsoft SQL Server that could allow an unauthorized attacker to access uninitialized memory over the network, potentially leaking sensitive data. This vulnerability has been publicly disclosed, increasing its risk of exploitation in the wild. Another serious concern is CVE-2025-6554, a type confusion bug in the V8 JavaScript engine used by Google Chrome, which was actively exploited before a patch was released. Given the severity and exposure of these flaws, users are urged to apply patches immediately to mitigate active threats and enhance system security.

What’s new on HivePro

Get through updates and upcoming events, and more directly in your inbox