Microsoft’s High-Severity Flaws Nearly Doubled in 2025, BeyondTrust Finds

Microsoft disclosed 1,273 software vulnerabilities in 2025, fewer than the year before, but the number of high-severity flaws nearly doubled, according to a report published Tuesday by the cybersecurity firm BeyondTrust. The company’s 2026 Microsoft Vulnerability Report found that high-severity issues rose to 157 from 78 a year earlier, an increase of 101.28%, even as the overall vulnerability count fell 6.4% from the 1,360 disclosed in 2024.

The pattern, BeyondTrust argues, means companies are measuring the wrong thing. Total counts have become a poor guide to risk, the report says, and organizations should focus on what it calls impact intensity, the severity of individual flaws and where they sit in the network. A decline in volume alongside a jump in severity, the firm says, is not a sign that the software is getting safer.

Office was the most striking example. Vulnerabilities in Microsoft’s productivity suite grew 234% year over year, and the company’s cloud platforms followed the same trajectory. Azure and Dynamics 365 saw their overall flaw counts dip slightly, but their high-severity vulnerabilities jumped from 4 to 37, a ninefold increase on a small base. For organizations that run their operations on Microsoft’s stack, the report’s authors wrote, the risk has shifted from the desktop to the services that run the business.

The types of flaws also changed. Privilege escalation vulnerabilities, the kind that let an attacker move from a limited account to a powerful one, accounted for 40% of all Microsoft CVEs in 2025. Information-disclosure vulnerabilities rose 73%. Together, the report says, the numbers describe attackers who are spending less time on loud, easily detected intrusions and more on quiet reconnaissance, credential theft, and lateral movement inside networks.

Security researchers said the shift reflects a mature threat environment. “The noisy ransomware attacks still happen, but the professionals have moved on,” one researcher said. “They find a way in, they look around, they elevate privileges, and they take their time.” That style of attack is far harder for conventional defenses to catch, and it explains why the software industry’s traditional fix, patching fast, is no longer sufficient on its own.

The cloud dimension is what most concerns the report’s authors. Azure is not just a place to run virtual machines; it is where companies manage identities, automate business processes, and define the policies that govern access to everything else. A high-severity flaw in that control plane, the report warns, can take down an entire business chain rather than a single application. “The cloud has stopped being infrastructure and become the enterprise’s nervous system,” the report states. “A vulnerability there is not a data leak; it is a way to control the company.”

BeyondTrust’s interest in the numbers is not purely academic. The firm, which makes privileged-access-management software, sells the tools that organizations use to limit what accounts can do, the exact controls that defeat the privilege-escalation attacks its report tracks. The company’s annual studies of Microsoft’s security posture have become a fixture for security teams, who use them to set priorities for the coming year’s patching and hardening work.

The findings land as Microsoft’s security teams face their own scrutiny. The company has made security its stated top priority since 2024, and it has restructured engineering incentives around shipping fewer, safer updates. The 2025 data suggests the effort is producing results at the margins, fewer total flaws, while the severity mix deteriorates, a combination the company attributed in part to changes in how it classifies issues. Microsoft did not immediately respond to a request for comment on the report.

The report’s framing of attacker behavior draws on years of incident data. High-profile breaches of recent years, from sprawling supply-chain compromises to intrusions at cloud service providers, have consistently followed the same shape: an initial foothold obtained through a small flaw, followed by weeks of quiet privilege escalation and lateral movement before the destructive payload is delivered. The vulnerability types that BeyondTrust says grew most in 2025, privilege escalation and information disclosure, are precisely the categories that such attacks exploit. The implication for defenders is uncomfortable: the flaws that matter are the ones attackers can turn into standing, the report says, not the ones that make headlines.

Microsoft’s patch cadence complicates the picture further. The company ships security updates monthly, and its rapid-response patches for exploited flaws have become more frequent as its security teams race to contain active attacks. For enterprise security teams, the result is a workload that keeps growing even as the total number of fixes shrinks, and the report urges organizations to automate the parts of patching they can, and to reserve human attention for the high-severity issues in the systems that matter most.

The practical advice for enterprises is neither new nor easy to follow. Patch the cloud control planes first, protect privileged accounts, and assume that attackers are already inside. The report’s more subtle message is that vulnerability counts, the metric that security teams have tracked for two decades, have stopped telling the story that matters. In a year when Microsoft’s total disclosures fell but its most dangerous flaws grew by double digits, the number of issues is no longer the point. Where they are, and what they can reach, is.

  • Related Posts

    • September 6, 2026
    • 8 views
    Tesla Shares Fall 6% as Cybercab Update Disappoints

    Tesla published an update on its Cybercab program on Friday, and investors answered with a sale. By the close, the company’s shares were down about 6 percent, one of the…

    • September 6, 2026
    • 10 views
    Apple Studies New Ways to Raise App Store Revenue

    Last week, Apple lost the executive who had defended its App Store rules through the industry’s longest-running fights, and the company let him go with little public explanation. This week,…