14 May BeyondTrust’s latest vulnerabilities report finds shocking AI risk
Posted at 04:16h
in
News,
Security
by BrittJones
- Critical vulnerabilities doubled year-over-year, signalling rising risk severity as AI-driven discovery and expanding attack surfaces reshape the Microsoft security landscape
- Elevation of Privilege vulnerabilities accounted for 40 per cent of all flaws, continuing to dominate threat actor pathways and reinforcing identity as the primary attack vector
- Azure and Dynamics 365 saw a 9x increase in critical vulnerabilities
BeyondTrust has released the 13th edition of its annual
Microsoft Vulnerabilities Report, revealing a critical shift in the vulnerability landscape.
While total vulnerability volume appears to be stabilising, critical vulnerabilities have surged, indicating severity and exploitability of vulnerabilities are rapidly increasing.
The report, which provides an in-depth analysis of data from publicly issued Microsoft security bulletins published throughout 2025, reveals a shifting risk profile driven by AI-accelerated vulnerability discovery, expanding cloud adoption, and increasingly sophisticated attacker strategies targeting identity and privilege.
“Don’t be distracted by the dip in total vulnerabilities. Critical vulnerabilities doubled. This is a warning that risk is not decreasing, it is concentrating, and it is concentrating around privilege. Elevation of Privilege made up 40% of all vulnerabilities again this year because that is exactly what attackers need to reach critical systems.” said James Maude, Field CTO at BeyondTrust.
“A ninefold increase in Azure and Dynamics 365 critical vulnerabilities shows where that concentration is happening. Combined with the rising tide of identity compromise attacks that exploit standing privilege, patching alone will not close this gap. The organisations that weather this are the ones treating every vulnerability and identity, human or machine, as a potential path to privilege in their most critical systems, and shrinking those paths before an attacker reaches them.”
Microsoft reported 1,273 total vulnerabilities, a 6 per cent decrease from 1,360 in 2024. At first glance, this decline suggests improvement, potentially reflecting Microsoft’s continued investment in security, which is maintaining control, despite a rapidly expanding attack surface.
However, it may also indicate that traditional vulnerability tracking is no longer capturing the full picture, particularly as AI-driven systems, non-human identities (NHIs), and complex cloud architectures introduce risks that don’t always map cleanly to CVEs.
At the same time, critical vulnerabilities doubled year-over-year, rising from 78 to 157, reversing a multi-year downward trend.
The report also found sharp increases in critical vulnerabilities across key Microsoft platforms that had previously seen declining vulnerability activity.
Sorry, the comment form is closed at this time.