Trending Topics

Prioritise, don’t panic: the Patch Tuesday advice your business really needs
Patch Tuesday, which those in the cybersecurity industry like to say is followed by Exploit Wednesday, has been and gone. It’s now, I would like to suggest, Thoughtful Thursday. So, take a deep breath and prepare yourself for some non-panicky advice.
Yes, July’s Patch Tuesday listed 130 Common Vulnerabilities and Exposures (CVEs) impacting Microsoft products and services. With 130 fixes also published, it would be easy to slip into full-on attack anxiety mode.
However, none of these have been exploited in the wild as far as anyone is aware, so take a deep breath.
Now, while you are calm, also note that Microsoft itself has determined that more than 85% fall under the category of unlikely or less likely to be exploited. Which isn’t to say that no urgent mitigation work is required, but priorities rather than panic should be the order of the day. And of the weeks ahead.
Don’t panic on Patch Tuesday
“The very simple, but often impractical advice for security updates is just to install them all as soon as possible,” said Brian Donohue, Principal Security Researcher at Red Canary.
In an ideal world, that would be perfect. However, we live in the real world; one that brings time considerations and the impact that updates can have on systems and processes in terms of adverse downstream, consequence.
Who hasn’t read about Microsoft updates that go belly up in one disastrous way or another, after all? Which is why organisations must, says Donohue, “pay close attention to Microsoft’s exploitability rankings and the CVSS scores assigned to vulnerabilities”.
By doing so, you can prioritise those vulnerabilities that impact your business, that have an “exploitation more likely” flag or that have the highest Common Vulnerability Scoring System (CVSS) criticality ratings.
“Anything that enables remote code execution is especially important to patch immediately,” Donohue warned,
Your mileage will vary compared to the next organisation. You may not use a particular product, or the impact could be greater or smaller depending upon any number of factors. All that said, the following vulnerabilities stand out as worthy of speedy assessment this month.
CVE-2025-47981
“The highest-rated vulnerability this month is CVE-2025-47981,” said Satnam Narang, Senior Staff Research Engineer of Tenable’s Special Operations Team. This is “a remote code execution flaw in SPNEGO Extended Negotiation (NEGOEX), an extension of the SPNEGO negotiation mechanism used to allow for negotiating what security mechanism is used before authenticating”.
Although only affecting Windows 10 version 1607 and above, Microsoft flagged CVE-2025-47981 as being more likely to be exploited.
CVE-2025-49719
“It has been a quiet few months on the SQL Server front,” said Adam Barnett, Lead Software Engineer at Rapid7, “but today Microsoft has published CVE-2025-49719, a publicly disclosed information disclosure vulnerability, with all versions as far back as SQL Server 2016 receiving patches.”
Although Microsoft ranks this vulnerability as important rather than critical, it has been publicly disclosed.
CVE-2025-47987
CVE-2025-47987 is Credential Security Support Provider Protocol (CredSSP) elevation of privilege vulnerability. “CredSSP is a key component in secure authentication flows, particularly in Remote Desktop Protocol (RDP) and other network authentication scenarios,” said Ben McCarthy, Lead Cyber Security Engineer at Immersive. He added that this makes any vulnerability in it “highly sensitive”.
Even though local access is required for exploitation, the vulnerability represents a serious threat as “no user interaction is needed, and the exploitation complexity is low,” and it can result in full system access, McCarthy said.
