Bryan Longworth wears a headset microphone in front of a dark binary-code background beside bold text reading "Windows attacked," promoting A Faster PC's Patch Tuesday security update coverage.

Every second Tuesday of the month, Microsoft, Adobe, and other major software vendors release their scheduled security fixes — a ritual known in the IT world as Patch Tuesday. This month's release wasn't routine. It was the largest security update in Microsoft's history, and it landed alongside major announcements from Adobe, Fortinet, and Progress Software. If your business runs on Windows — which is nearly every business — here's what you need to know, and what to do about it this week.

A record-breaking Patch Tuesday: 570 vulnerabilities in one release

Last month, Microsoft's Patch Tuesday addressed 200 vulnerabilities, which was already considered a large release. This month, that number jumped to 570 security flaws fixed in a single update — nearly three times last month's total and more than double Microsoft's previous record. The fixes span Windows, Office, SharePoint, and dozens of other Microsoft products.

Most of these 570 fixes cover vulnerabilities that haven't been exploited yet. Three of them are different — and far more urgent.

Three zero-day vulnerabilities, two already under active attack

A zero-day vulnerability means attackers found and began exploiting the flaw before the vendor had a fix ready. This month, Microsoft disclosed three zero-days, and two are already being actively exploited.

SharePoint zero-days: complete server takeover

Two of the zero-days affect Microsoft SharePoint, the file-sharing and collaboration platform many offices rely on daily. These flaws don't just expose files or emails — they allow an attacker to take complete control of a SharePoint server. That means access to everything stored there, the ability to delete or ransomware-encrypt it, and a launch point to move deeper into the rest of the network, including client records, contacts, and financial data.

Businesses running SharePoint on their own on-premises servers (rather than the Microsoft-hosted cloud version) should treat this patch as an emergency and install it today, not later this week.

A login system flaw that lets attackers impersonate real users

The third zero-day affects the system that manages logins across an organization. It could allow an attacker to appear as a legitimate, authorized user — walking into the network without triggering suspicious login alerts. That kind of quiet access is especially dangerous because it doesn't look like an attack until the damage is already done.

BitLocker encryption bypass: a risk for every laptop that leaves the office

This month's update also includes a fix for a flaw in BitLocker, the built-in Windows tool that encrypts a hard drive so a lost or stolen device can't be read by whoever finds it. This vulnerability bypasses that protection. An attacker with physical access to a laptop — one stolen from a car, an unlocked office, or left behind at an airport — could unlock it and read every file, contract, client record, and saved password on it.

Any business with employees who travel with laptops should prioritize this patch immediately.

A recurring vulnerability with a ransomware history

Another critical fix addresses a Windows system that has previously been a favored entry point for ransomware groups. It's a useful reminder that patched vulnerabilities don't always disappear for good — related flaws in the same systems tend to resurface in new forms, which is exactly why ongoing patch management matters more than a one-time fix.

Adobe fixes seven maximum-severity flaws — and changes its release schedule

Adobe also released significant security patches this month, addressing seven vulnerabilities rated at the highest possible severity level. Two involve ColdFusion, software that powers many business websites and web applications behind the scenes — and these flaws are already being actively exploited to break into web servers. Another critical fix affects Campaign Classic, Adobe's marketing email platform, where a flaw could let an attacker run code remotely from anywhere in the world.

More significantly, Adobe announced it is moving from one security update per month to two, releasing patches on the second and fourth Tuesday of every month going forward. The reason: new threats are being discovered faster than a monthly cycle can keep up with. For any business using Adobe products to run a website or web application, this means patch management now needs to happen twice a month, not once. Explore our advanced cybersecurity managed services.

Fortinet firewall advisories: your first line of defense needs attention

Fortinet, one of the largest makers of business firewalls and routers, released multiple security advisories this month across several of its products. Firewalls are the digital wall between a business network and the open internet, and Fortinet vulnerabilities have a track record of being exploited quickly after disclosure. Any new Fortinet advisory should be acted on right away rather than scheduled for a future maintenance window.

Progress Software patches a ShareFile zero-day

Progress Software confirmed and patched a zero-day vulnerability in ShareFile, its file-sharing and document management platform — the same flaw that previously led some businesses to take their ShareFile servers offline entirely. The official patch is now available, and ShareFile customers should bring servers back online only after the patch is installed.

U-Boot firmware flaws: a deeper, harder-to-detect threat

Perhaps the most concerning disclosure this month involves U-Boot, open-source firmware that powers a wide range of routers, network devices, and embedded systems. Firmware runs beneath the operating system, before Windows or any other software even starts. Vulnerabilities at this level could let an attacker plant malicious code that traditional antivirus software wouldn't detect and that a factory reset wouldn't remove — a genuinely persistent threat.

This isn't a reason for most businesses to panic today, but it is a clear signal of where the attack landscape is heading: deeper into devices, harder to detect, and harder to remove.

Your action plan for this month's Patch Tuesday

  1. Confirm automatic updates are on. If you're on Windows with automatic updates enabled, you're likely already covered for Microsoft's patches — but if you manage your own servers, verify this week.
  2. Treat SharePoint zero-days as an emergency if you run SharePoint on your own hardware.
  3. Prioritize the BitLocker patch for any laptops that leave the office.
  4. Build a twice-monthly patch schedule if you rely on Adobe products for your website.
  5. Update firewalls, routers, and network equipment regularly — they're not "set it and forget it" devices.

The bottom line

The pace of attacks is accelerating, and vendors are pushing patches faster than ever to keep up. The businesses that get hurt usually aren't the ones being specifically targeted — they're the ones that didn't patch in time.

If you'd rather have someone handle all of this for you, that's exactly what A Faster PC does. We manage security updates, monitor active threats, and keep systems protected for businesses across Florida's Treasure Coast, Space Coast, and South Florida — as well as clients in other states and countries. Contact A Faster PC today or download our free cybersecurity report to see the most common ways businesses get hacked and how to stop it. View our advanced cybersecurity managed services which can protect you, your data, and your reputation from ransomware, breaches, and cyber attacks.

Frequently Asked Questions

Q: What is Patch Tuesday and why does it matter for my business?
A: Patch Tuesday is the second Tuesday of every month, when Microsoft, Adobe, and other major vendors release their scheduled security fixes. This month's release was the largest in Microsoft's history, fixing 570 vulnerabilities in a single update — which is why it matters more than usual for any business running Windows.

Q: What is a zero-day vulnerability?
A: A zero-day vulnerability is a security flaw that attackers discovered and began exploiting before the software vendor had a patch ready. This month, Microsoft disclosed three zero-days, and two of them are already being actively exploited, which makes patching them urgent rather than routine.

Q: Is my business at risk if I use Microsoft SharePoint?
A: Yes, if you run SharePoint on your own on-premises server rather than the Microsoft-hosted cloud version. Two of this month's zero-day flaws allow an attacker to take complete control of a SharePoint server, including client records, contacts, and financial data, so that patch should be installed as an emergency, today.

Q: Does the BitLocker vulnerability affect all Windows computers?
A: The BitLocker flaw specifically matters for devices that could be physically lost or stolen, like laptops employees take out of the office. It bypasses BitLocker's encryption protection, meaning an attacker with physical access to the device could read every file on it, so this patch is a priority for any mobile workforce.

Q: Why is Adobe changing to two security updates a month?
A: Adobe fixed seven maximum-severity vulnerabilities this month, including flaws already being exploited in ColdFusion. Because new threats are being discovered faster than a monthly cycle allows, Adobe is now releasing patches twice a month, on the second and fourth Tuesday, and businesses using Adobe products should adjust their patching schedule accordingly.

Q: What makes the U-Boot firmware vulnerability different from a typical software bug?
A: U-Boot is firmware that runs underneath the operating system, before Windows even starts. A flaw at this level could let an attacker plant code that traditional antivirus software can't detect and that a factory reset won't remove, making it a persistent threat rather than a one-time infection.

Q: How can businesses on Florida's Treasure Coast, Space Coast, and South Florida get help managing all these patches?
A: A Faster PC provides managed IT and cybersecurity services to businesses across Florida's Treasure Coast, Space Coast, and South Florida, as well as clients in other states and countries. We handle security updates and monitor active threats so systems are protected before most business owners even hear about a new vulnerability.

Q: What should I do first if I haven't kept up with patches this month?
A: Start by confirming whether automatic updates are turned on for your Windows systems, then prioritize the SharePoint zero-day patch if you run it on your own server, and the BitLocker patch for any laptops that travel outside the office. If that feels like too much to track, schedule a discovery call today with A Faster PC. We can take it off your plate entirely.

Watch the full video here: Your Windows System Is Being Targeted Right Now | What You Need to Know.

About A Faster PC

A Faster PC is a leading managed services provider (MSP) serving Florida's Treasure Coast, Space Coast, and South Florida. A Faster PC provides responsive IT support, advanced cybersecurity solutions, cloud backup, disaster recovery, breach remediation, patch management, computer repair, and technical support for accounting offices, attorneys' offices, medical offices, dental offices, professional offices, small- to medium-sized businesses, non-profits, churches, home office users, and individuals throughout the regions. We help our clients cut costs in their Internet, TV, and telephone bills and in business operations.

Every week at 10:07 AM EST, A Faster PC hosts A Faster PC Live Technical Support, which is a live Radio Show that is livestreamed to YouTube and Facebook and is available as a podcast. For various ways to listen to and watch A Faster PC Live Technical support, visit https://www.afasterpc.com/live-technical-support/.

A Faster PC services the following counties and cities: St. Lucie County including: Port St. Lucie, Fort Pierce, St. Lucie West, Tradition, St. Lucie Village; Martin County including: Stuart, Jensen Beach, Jupiter Island, Ocean Breeze Park, and Sewall's Point; Indian River County: including Vero Beach, Sebastian, Fellsmere, Indian River Shores; Palm Beach County including: Jupiter, Jupiter Inlet Colony, Juno Beach, Tequesta, Palm Beach Gardens, North Palm Beach, Palm Beach Shores, Riviera Beach, West Palm Beach, Wellington, Royal Palm Beach, Greenacres, Lake Worth Beach, Lantana, Boynton Beach, Ocean Ridge, Briny Breezes, Gulf Stream, Delray Beach, Highland Beach, and Boca Raton; Broward County including: Fort Lauderdale, Hollywood, Pompano Beach, Coral Springs, Pembroke Pines, Miramar, Davie, Plantation, Sunrise, Deerfield Beach, Lauderhill, Weston, Tamarac, Coconut Creek, Margate, Lauderdale Lakes, Oakland Park, Hallandale Beach, Cooper City, Wilton Manors, Lighthouse Point, Parkland, Lauderdale-by-the-Sea, Sea Ranch Lakes, Lazy Lake, Hillsboro Beach, Southwest Ranches, North Lauderdale, Dania Beach; Miami-Dade County including: Miami, Miami Beach, Hialeah, Miami Gardens, Coral Gables, Homestead, Doral, North Miami, Aventura, Kendall, Cutler Bay, Sunny Isles Beach, Key Biscayne, Pinecrest, Surfside, Bal Harbour, North Miami Beach, Palmetto Bay, Miami Springs, Opa-locka, Miami Lakes, Florida City, South Miami, Sweetwater, West Miami, Bay Harbor Islands, Biscayne Park, El Portal, Golden Beach, Hialeah Gardens, Indian Creek, Medley, North Bay Village, and Virginia Gardens; and Okeechobee County including: Okeechobee, Taylor Creek, Cypress Quarters, Fort Drum, and Basinger.