Microsoft Patch Tuesday Reveals Record-Breaking 394 Vulnerabilities
A record-breaking Microsoft Patch Tuesday revealed 394 vulnerabilities across various products, including three zero-days that were actively exploited by threat actors. The most severe flaws include a Windows AFD.sys zero-day exploited by North Korea's Lazarus group and a Palo Alto Networks vulnerability that allowed attackers to bypass authentication.
The Gunra ransomware group was also exposed in a joint advisory from the FBI, CISA, NSA, and South Korean authorities. This group emerged in April 2025 and has been exploiting known Fortinet authentication-bypass flaws (CVE-2024-55591 and CVE-2025-24472) to gain initial access.
Cisco confirmed active exploitation of a zero-day vulnerability in its Secure Firewall ASA and FTD software, while Microsoft fixed a critical remote code execution flaw in Outlook. Multiple TP-Link vulnerabilities were also disclosed, allowing attackers to bypass authentication on ISP-managed Aginet mesh systems, routers, PON devices, and other products.