24 Apr Critical vulnerabilities doubles, says report
- Critical vulnerabilities doubled year-over-year
- Elevation of Privilege vulnerabilities accounted for 40 per cent of all flaws
- Azure and Dynamics 365, saw a 9x increase in critical vulnerabilities
A new cybersecurity report has revealed a growing imbalance in the global threat landscape, with critical software vulnerabilities rising sharply even as overall volumes begin to stabilise.
The latest Microsoft Vulnerabilities Report, analysing publicly issued Microsoft security bulletins from 2025, points to a change in how cyber risk is evolving.
While the total number of reported vulnerabilities fell slightly year-on-year, the number of critical flaws has surged, suggesting that risk is becoming more concentrated and potentially more dangerous. According to the findings, Microsoft recorded 1,273 total vulnerabilities in 2025, down 6 per cent from 1,360 in 2024.
While the decline may indicate progress in managing an expanding attack surface, the report warns that traditional metrics may no longer fully capture emerging risks, particularly as artificial intelligence, non-human identities and complex cloud environments reshape the threat landscape.
In another statistic, critical vulnerabilities doubled over the same period, rising from 78 to 157 and reversing a multi-year downward trend. Elevation of Privilege (EoP) vulnerabilities continued to dominate, accounting for 40 per cent of all reported issues.
“Don’t be distracted by the dip in total vulnerabilities. Critical vulnerabilities doubled. This is a warning that risk is not decreasing, it is concentrating, and it is concentrating around privilege. Elevation of Privilege made up 40 per cent of all vulnerabilities again this year because that is exactly what attackers need to reach critical systems,” said James Maude, Field CTO at BeyondTrust.
The report also identifies a sharp rise in critical vulnerabilities across major cloud and enterprise platforms.
Microsoft Azure and Dynamics 365 saw a ninefold increase in critical flaws, rising from four to 37, while vulnerabilities in Microsoft Office more than tripled to 157.
“A ninefold increase in Azure and Dynamics 365 critical vulnerabilities shows where that concentration is happening. Combined with the rising tide of identity compromise attacks that exploit standing privilege, patching alone will not close this gap. The organisations that weather this are the ones treating every vulnerability and identity, human or machine, as a potential path to privilege in their most critical systems, and shrinking those paths before an attacker reaches them.”
Despite the broader trend, some areas showed improvement, as vulnerabilities affecting Microsoft Edge fell significantly to 50 in 2025, marking an 83 per cent decrease compared with the previous year.
The findings also reveal the growing role of artificial intelligence in both defence and attack. For example, while AI is accelerating vulnerability discovery for security teams, it is also enabling attackers to analyse patches, reverse engineer fixes and deploy exploits more rapidly.
The report further cautions that conventional vulnerability tracking methods, such as CVE counts, may no longer provide a complete picture.
Also, risks linked to over-privileged AI systems, long-lived machine credentials and identity misconfigurations have been found to fall outside traditional reporting frameworks, despite their potential impact.
In response, organisations are being urged to adapt their security strategies, such as accelerating patching cycles while assuming compromise remains possible, enforcing least-privilege access to limit the impact of breaches, adopting identity-first security models that secure both human and machine identities, and focusing on identifying and reducing potential paths to privilege rather than addressing vulnerabilities in isolation.
But is it enough?
Sorry, the comment form is closed at this time.