Skip to content
Noroxi

Patch Tuesday

December 2025

On the second Tuesday of each month Microsoft, Adobe, SAP, Siemens and Schneider Electric publish in bulk; Oracle on the third Tuesday of January, April, July and October. Records published that day, from our own database, sorted by action score: KEV and mature exploits first.

How it is computed: CNA stamp + publication date (two-day window, UTC). No claim of a one-to-one match with the vendor bulletin; out-of-band updates land on other days.

224 records · 1 KEV

Affecting your stack

This month's records that match the products and versions in your stack.

Sign in to see the ones matching your stack; records and notifications are free. →

Microsoft · December 9

56 · 1 KEV · 1 critical

+44 moreAll records of the vendor

Adobe · December 9

135 · 0 KEV · 6 critical
  • ColdFusion | Unrestricted Upload of File with Dangerous Type (CWE-434)

    CriticalCVSS 9.1No exploitEPSS 11%

    adobe · coldfusionDec 9, 2025

  • Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)

    CriticalCVSS 9.3No exploitEPSS 1%

    adobe · experience managerDec 10, 2025

  • Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)

    CriticalCVSS 9.3No exploitEPSS 1%

    adobe · experience managerDec 10, 2025

  • Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)

    CriticalCVSS 9.3No exploitEPSS 0%

    adobe · experience managerDec 10, 2025

  • ColdFusion | Improper Input Validation (CWE-20)

    CriticalCVSS 9.1No exploitEPSS 1%

    adobe · coldfusionDec 9, 2025

  • ColdFusion | Deserialization of Untrusted Data (CWE-502)

    HighCVSS 8.4No exploitEPSS 10%

    adobe · coldfusionDec 9, 2025

  • ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)

    CriticalCVSS 9.1No exploitEPSS 1%

    adobe · coldfusionDec 9, 2025

  • ColdFusion | Improper Input Validation (CWE-20)

    HighCVSS 8.4No exploitEPSS 5%

    adobe · coldfusionDec 9, 2025

  • DNG SDK | Integer Overflow or Wraparound (CWE-190)

    HighCVSS 7.8No exploitEPSS 0%

    adobe · dng software development kitDec 9, 2025

  • Acrobat Reader | Untrusted Search Path (CWE-426)

    HighCVSS 7.8No exploitEPSS 0%

    adobe · acrobatDec 9, 2025

  • Acrobat Reader | Out-of-bounds Read (CWE-125)

    HighCVSS 7.8No exploitEPSS 0%

    adobe · acrobatDec 9, 2025

  • ColdFusion | Improper Restriction of XML External Entity Reference ('XXE') (CWE-611)

    HighCVSS 7.4No exploitEPSS 1%

    adobe · coldfusionDec 9, 2025

+123 moreAll records of the vendor

SAP · December 9

12 · 0 KEV · 2 critical
  • Code Injection vulnerability in SAP Solution Manager

    CriticalCVSS 9.9No exploitEPSS 5%

    sap_se · sap solution managerDec 9, 2025

  • Deserialization Vulnerability in SAP jConnect - SDK for ASE

    CriticalCVSS 9.1No exploitEPSS 9%

    sap_se · sap jconnect - sdk for aseDec 9, 2025

  • Sensitive Data Exposure in SAP Web Dispatcher and Internet Communication Manager (ICM)

    HighCVSS 8.2No exploitEPSS 0%

    sap_se · sap web dispatcher and internet communication manager (icm)Dec 9, 2025

  • Denial of service (DOS) in SAP NetWeaver (remote service for Xcelsius)

    HighCVSS 7.9No exploitEPSS 0%

    sap_se · sap netweaver (remote service for xcelsius)Dec 9, 2025

  • Memory Corruption vulnerability in SAP Web Dispatcher, Internet Communication Manager and SAP Content Server

    HighCVSS 7.5No exploitEPSS 1%

    sap_se · sap web dispatcher, internet communication manager and sap content serverDec 9, 2025

  • Missing Authorization Check in SAP S/4 HANA Private Cloud (Financials General Ledger)

    HighCVSS 7.1No exploitEPSS 0%

    sap_se · sap s/4 hana private cloud (financials general ledger)Dec 9, 2025

  • Missing Authentication check in SAP NetWeaver Internet Communication Framework

    MediumCVSS 6.6No exploitEPSS 0%

    sap_se · sap netweaver internet communication frameworkDec 9, 2025

  • Information Disclosure vulnerability in Application Server ABAP

    MediumCVSS 6.5No exploitEPSS 0%

    sap_se · application server abapDec 9, 2025

  • Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal

    MediumCVSS 6.1No exploitEPSS 0%

    sap_se · sap netweaver enterprise portalDec 9, 2025

  • Denial of Service (DoS) in SAPUI5 framework (Markdown-it component)

    MediumCVSS 5.9No exploitEPSS 0%

    sap_se · sapui5 framework (markdown-it component)Dec 9, 2025

  • Missing Authorization check in SAP Enterprise Search for ABAP

    MediumCVSS 5.5No exploitEPSS 0%

    sap_se · sap enterprise search for abapDec 9, 2025

  • Server-Side Request Forgery (SSRF) in SAP BusinessObjects Business Intelligence Platform

    MediumCVSS 5.4No exploitEPSS 0%

    sap_se · sap businessobjects business intelligence platformDec 9, 2025

All records of the vendor

Siemens · December 9

21 · 0 KEV · 3 critical
  • A vulnerability has been identified in COMOS V10.6 (All versions < V10.6.1), COMOS V10.6 (All versions < V10.6.1), NX V2412 (All versions <

    CriticalCVSS 9.1No exploitEPSS 0%

    siemens · comos v10.6Dec 9, 2025

  • A vulnerability has been identified in COMOS V10.6 (All versions < V10.6.1), COMOS V10.6 (All versions < V10.6.1), JT Bi-Directional Transla

    CriticalCVSS 9.2No exploitEPSS 0%

    siemens · comos v10.6Dec 9, 2025

  • A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1).

    CriticalCVSS 9.2No exploitEPSS 0%

    siemens · simatic cn 4100 firmwareDec 9, 2025

  • A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.0), RUGGEDCOM ROX MX5000RE (All versions < V2.17.0), RUGGE

    HighCVSS 8.7No exploitEPSS 1%

    siemens · ruggedcom rox ii firmwareDec 9, 2025

  • A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.0), RUGGEDCOM ROX MX5000RE (All versions < V2.17.0), RUGGE

    HighCVSS 8.6No exploitEPSS 1%

    siemens · ruggedcom rox ii firmwareDec 9, 2025

  • A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.0), RUGGEDCOM ROX MX5000RE (All versions < V2.17.0), RUGGE

    HighCVSS 8.6No exploitEPSS 0%

    siemens · ruggedcom rox ii firmwareDec 9, 2025

  • A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.0), RUGGEDCOM ROX MX5000RE (All versions < V2.17.0), RUGGE

    HighCVSS 8.6No exploitEPSS 1%

    siemens · ruggedcom rox ii firmwareDec 9, 2025

  • Affected products do not properly enforce TCP sequence number validation in specific scenarios but accept values within a broad range.

    HighCVSS 8.7No exploitEPSS 0%

    siemens · sidoor atd430wDec 9, 2025

  • A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1).

    HighCVSS 8.7No exploitEPSS 1%

    siemens · simatic cn 4100 firmwareDec 9, 2025

  • A vulnerability has been identified in SINEC Security Monitor (All versions < V4.10.0).

    HighCVSS 8.4No exploitEPSS 0%

    siemens · sinec security monitorDec 9, 2025

  • A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.0), RUGGEDCOM ROX MX5000RE (All versions < V2.17.0), RUGGE

    HighCVSS 7.7No exploitEPSS 0%

    siemens · ruggedcom rox ii firmwareDec 9, 2025

  • A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.0), RUGGEDCOM ROX MX5000RE (All versions < V2.17.0), RUGGE

    HighCVSS 7.5No exploitEPSS 1%

    siemens · ruggedcom rox ii firmwareDec 9, 2025

+9 moreAll records of the vendor

Schneider Electric · December 9

0 · 0 KEV · 0 critical

No records in this window.