Summary
September's Patch Tuesday brought another full slate of vulnerabilities, and Automox security manager Ryan Braunstein, senior security engineer Henry Smith, and senior security engineer Seth Hoyt walk through the three worth acting on first. Henry flags CVE-2025-54098, a Hyper-V elevation of privilege rated exploitation more likely, and notes the role on Pro and Enterprise workstations widens the blast radius. Ryan covers the Windows UI XAML use-after-free flaws tied to the DatePickerFlyout and the newer Phone Link iOS support. Seth explains CVE-2025-54916, a stack-based buffer overflow in NTFS that hands a low-privilege account remote code execution.
)
)
)
)
)
)
)