Application Management and Patching

August 2025 Third-Party Patches 

Topics: Application Management and Patching

August was slightly quieter by the numbers. All three indicators fell compared with June or July. Versions dropped from 137 to 76, unique vulnerabilities from 111 to 92, and vulnerable applications from 92 to 51. That should give admins and endpoint security teams a bit of breathing room. 

August 2025 Third-Party Patches - Metrics

Notable Vulnerabilities in August 2025 Third-Party Patches 

Surprisingly, vulnerabilities in August weren’t that severe either. The highest Exploit Prediction Scoring System (EPSS) score we observed was 0.008—low on the 0–1 scale. Average CVSS stayed in line with prior months. 

Starting this month, I’m also cross-checking against CISA’s Known Exploited Vulnerabilities Catalog. According to CISA KEV and Microsoft sources, only one August vulnerability is confirmed exploited in the wild. 

CVE-2025-5419 is an out-of-bounds read/write flaw in Chromium’s V8 JavaScript engine. It could let a remote attacker trigger heap corruption via a crafted HTML page. This flaw could impact multiple Chromium-based browsers, including Google Chrome, Microsoft Edge, and Opera. See the Chrome releases blog and MSRC for details. 

CVE-2025-53766 affects Microsoft 365 Apps. A heap-based buffer overflow in Windows GDI+ could enable remote code execution, potentially compromising systems running Microsoft 365 Apps. Details: MSRC

August 2025 Third-Party Patches - Vulnerabilities Chart

Browser Security Updates in August 2025 

Major browsers including Google Chrome, Microsoft Edge, Brave, Mozilla Firefox (including ESR versions), Opera One, Vivaldi, and Waterfox received numerous security updates addressing various vulnerabilities. 

Browser Vulnerabilities Updates 
Google Chrome 15 
Microsoft Edge 15 
Brave Browser 13 
Pale Moon 
Mozilla Firefox 
Mozilla Firefox ESR 115 
Mozilla Firefox ESR 128 
Opera One 
Waterfox 

Microsoft Product Updates Included in August 2025 Third-Party Patches 

In addition to Edge, Microsoft issued security updates for several other products. 

  • Microsoft Visual Studio 2022 Community 
  • Microsoft Visual Studio Team Explorer 2022 
  • Microsoft Edge for Business 
  • Microsoft Visual Studio 2022 Enterprise 
  • Microsoft Visual Studio 2022 Professional 
  • Microsoft 365 Apps 
  • Microsoft Visio 
  • Microsoft Project 
  • Microsoft Edge Beta 
  • Microsoft Azure CLI 
  • Windows Subsystem for Linux 

Detailed List of August 2025 Third-Party Patches 

For a complete list of applications, versions, and the number of remediated vulnerabilities, see the table below generated using Application Workspace data.  

ProductName VersionName Vulnerabilities remediated 
Apache Tomcat 10 10.1.44 
Apache Tomcat 11 11.0.10 
Apache Tomcat 9 9.0.108 
Autodesk Revit 2023 2023.1.8 
Autodesk Revit 2025 2025.4.3 
Brave Browser 1.81.131 
Brave Browser 1.81.135 
Bruno 2.10.0 
Burp Suite Community Edition 2025.8 
Burp Suite Professional Edition 2025.8 
Coder 2.25.1 
Coder 2.24.3 
Coder 2.23.5 
Datadog Agent 7.69.3 
Docker Desktop 4.44.3 
Docker Desktop 4.44.3.202357 
Docker Desktop 4.44.0 
Docker Desktop 4.44.0.201307 
EnterpriseDB Corporation PostgreSQL 13 13.22.1 
EnterpriseDB Corporation PostgreSQL 14 14.19.1 
EnterpriseDB Corporation PostgreSQL 15 15.14.1 
EnterpriseDB Corporation PostgreSQL 16 16.10.1 
EnterpriseDB Corporation PostgreSQL 17 17.6 
EnterpriseDB Corporation PostgreSQL 17 17.6.1 
Foxit PDF Editor 14 14.0.0.33046 16 
Foxit PDF Editor 2025 2025.2.0.33046 17 
Foxit PDF Editor Pro 14 14.0.0.33046 16 
Google Chrome 139.0.7258.155 
Google Chrome 139.0.7258.154 
Google Chrome 139.0.7258.139 
Google Chrome 139.0.7258.138 
Google Chrome 139.0.7258.127 
Google Chrome 139.0.7258.128 
Google Chrome 139.0.7258.67 
Google Chrome for Business 139.0.7258.139 
Google Chrome for Business 139.0.7258.155 
Google Chrome for Business 139.0.7258.128 
Google Chrome for Business 139.0.7258.67 
Google Chrome for Education 139.0.7258.139 
Google Chrome for Education 139.0.7258.155 
Google Chrome for Education 139.0.7258.128 
Google Chrome for Education 139.0.7258.67 
Google Go Programming Language 1.24.6 
Google Go Programming Language 1.23 1.23.12 
Helm 3.18.5 
IntelliJ IDEA Community 2025.2 
IntelliJ IDEA Ultimate 2025.2 
Microsoft 365 Apps 2507 (Build 16.0.19029.20184) 16 
Microsoft 365 Apps 2502 (Build 16.0.18526.20546) 16 
Microsoft 365 Apps 2506 (Build 16.0.18925.20216) 16 
Microsoft Azure CLI 2.76.0 
Microsoft Edge Beta 139.0.3405.86 
Microsoft Edge for Business 139.0.3405.125 
Microsoft Edge for Business 139.0.3405.111 
Microsoft Edge for Business 139.0.3405.86 
Microsoft Edge for Business 139.0.3405.102 
Microsoft Project 2507 (Build 16.0.19029.20184) 16 
Microsoft Visio 2507 (Build 16.0.19029.20184) 16 
Microsoft Visual Studio 2022 Community 17.14.36414.22 
Microsoft Visual Studio 2022 Enterprise 17.14.36414.22 
Microsoft Visual Studio 2022 Professional 17.14.36414.22 
Microsoft Visual Studio Team Explorer 2022 17.14.36414.22 
Mozilla Firefox 142.0 
Mozilla Firefox ESR 115 115.27.0 
Mozilla Firefox ESR 128 128.14.0 
Mozilla Thunderbird 142.0 
Mozilla Thunderbird 140.2.0 
Mozilla Thunderbird ESR 128 128.14.0 
Mozilla Thunderbird ESR 140 140.2.0 
Opera One 121.0.5600.38 
Pale Moon 33.8.2 
TeamCity 2025.07.1 
Waterfox 6.5.11 
Windows Subsystem for Linux 2.5.10 
Wireshark 4.4 4.4.9 

Conclusion 

Fast third-party patching protects your environment. August updates closed critical gaps across browsers and apps—tightening security and boosting uptime. Check back next month for fresh insights. 

Want to cut patch MTTR and shrink your attack surface? Explore our eBook Reduce Your Attack Footprint or follow our App Management and Patching series

Back to Top