Cisco updated its advisory regarding critical vulnerabilities in Identity Services Engine, acknowledging active exploitation. Some vulnerabilities were attempted to be exploited in the wild as of July 2025.
For the first time this year, Microsoft has released a Patch Tuesday bundle with no exploited security problems, although one has been made public. July's software flaw fix package includes 130 patches with one earning a CVSS score of over nine - CVE-2025-47981, which breaks SPNEGO security protocols with a heap-based buffer overflow that allows remote code execution. The other nine critical issues include four in Office, where four flaws allow for remote code execution.