Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Ivanti: Adobe, Mozilla & Microsoft Security Updates Breakdown

Ivanti
06/29/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


We did talk a little bit about Adobe Acrobat and Reader, Chris touched on it. They did fix four vulnerabilities. Two of them were rated critical, two were rated moderate. Again, commonly used application, you want to make sure that you do get this distributed out into your environment. They did release it across all the versions they support, including DC Continuous, the Classic 2020, and the Classic 2024. Definitely a big update that you generally want to push out. As a general reader update. Chris also mentioned the Mozilla releases yesterday, Firefox 146, the latest version came out, addressed 13 vulnerabilities in there. They rated this update high. There were five high-rated CVEs and eight that were rated moderate in there. I can always include the link for you guys to read if you want to dig into some of these CVEs and see what's being fixed. But there were 13 this month addressed there in Firefox 146, which is the pointy tip of what they're releasing as far as Firefox goes. Under the extended service updates, we see that there was a 140.6 release as well. 10 vulnerabilities. This is basically a subset of what was in the 146 release. These are all covered here. There was also a ESR version 115.31 release. I didn't have ESR in the title in the last one, I apologize for that. But these are the extended service ones that Mozilla does support. Only four vulnerabilities fixed that needed to be fixed here. Three of those were rated high, one moderate. Again, if you're running some of these older ones, make sure you update them and include them in your list for this month. Talking about the Microsoft release, I left them in order. Usually, this is a critical release. As Chris said, it's very rare for us to see a major OS release that doesn't have a critical CVE addressed. But this month, they were all important. There were 37 of them addressed in Windows 11. Chris talked about the known exploited vulnerability 62221, which I did highlight in red down there, and also 54100, which was the publicly disclosed vulnerability. Include the KBs. There were also hot patches this month. I didn't include the hot patch KB in here, but Microsoft did release a hot patch for these updates this month as well. There was a reported vulnerability. This was an interesting one, and I've had some reports that quite a few people have seen this one. They found that the password icon that you use to log in off the lock screen has disappeared. If you scroll over and you know it's where it used to be, it actually does pop up and allow you if you click on that spot to log in properly. It's just really weird that the visual side of this has disappeared. Interestingly enough, if you dig into this KB, they do provide some directions if this is a big problem for you on how to roll this thing back, but it's pretty complicated. There are a lot of steps you have to go through. Again, take a look into the KB. I do have a hot link up there in the top of the slides if you want to look at this. Microsoft did say they, of course, are working on a resolution for this. It's also interesting as they say this primarily shows up in enterprise versions of the operating system, not in the professional or the home versions, which is really interesting as well. Definitely impacting a lot of us out there. Just be aware of this issue this month. I apologize, I did you guys a disservice last month with the drop of Windows 10 and going into ESU. I failed to mention that there is still obviously support for the server versions that are part of the Windows 10 operating system kernel. There's also some obviously long-term service branch versions of Windows 10 as well that are continuing to be supported. I did include this slide back in here. Apologize for those of you who were on last month. We obviously have Server 2016, 2019, and Server 2022, which are all based on the Windows 10 kernel. Two less vulnerabilities than we saw on the Windows 11 side. There are only 35 addressed here that applied to these particular operating systems. Of course, interestingly enough, the known exploited and publicly disclosed vulnerabilities are the same. There is a reported issue. We did talk about this last month in Windows 11. But this month, it's only apparently part of the Windows 10 issue. This has to do with WSUS updates not showing the proper errors in their reporting. Microsoft said this is just a reporting issue. It's not necessarily a problem per se, and they're again taking a look at can they fix this. This reporting problem was around the changes that they made with the fix for this remote code execution vulnerability. It says they're still taking a look at this. We'll see what happens. This is applicable to both versions of Server 2022, the 23H2 version as well as the stock version, which is just 2022. Exchange Server this month, also just an important update. Again, two vulnerabilities were addressed, one related to spoofing, one related to elevation of privilege. They did drop support, as you're probably aware, for the other versions of Exchange Server. There's a 2016-2019. Interestingly enough, if you look in the security updates guide, they did provide what they're calling ESU updates for those two versions. I haven't figured that one out yet, but apparently they are still providing some updates. If you're running those, you may find some patches that are applicable on some of those older versions. But right now, as far as mainstream support on Exchange Server, they're only supporting the subscription edition. Microsoft Office as well. You'll see I put a bunch of these in italics here with an asterisk on them. Although they have said they have dropped support for Office 2016 in the updates this month, you'll continue to see some. I've included them here. Access, Excel, Office Suite as a whole, and Word 2016 all received individual updates. Online server is still going to have continued support through 2026. That's not part of the end of support there. There were 13 vulnerabilities that were addressed. A bunch of KB articles, you can go dig into those if you're looking for one of your particular applications and what was fixed. Again, 13 vulnerabilities that were fixed. They were all remote code execution vulnerabilities. That was interesting that they were all of a single type. Definitely, if you are running some of these older apps still, the good news is that you can continue to get an update this month. On the online versions or what we refer to as the click-to-run versions often, we did see updates for 365 apps. Again, Office 2019, even though it's been officially end of life, it did get an update this month and the long-term service channel 2021 and 2024 releases also received updates. Eleven vulnerabilities that were addressed here. Again, 2019 is beyond end of life, but it did get an update, so we get a little reprieve on that one if you're still running it. SharePoint server, we did see updates for all supported versions of SharePoint server. Five KBs covering the various versions here. CVEs that were addressed here were of the type remote code execution and spoofing. I did list them here. None of these are known to be publicly disclosed or exploited, so that's good to know. But it was rated critical because there were some critical CVEs that were addressed in there. Chris did talk about between the patch Tuesdays.

TL;DR

  • Adobe Acrobat and Reader received critical security updates addressing four vulnerabilities across all supported versions, requiring immediate deployment in enterprise environments.
  • Mozilla released Firefox 146 with 13 vulnerability fixes and updated multiple ESR versions, with organizations running older Firefox branches needing to apply ESR-specific patches.
  • Microsoft's January Patch Tuesday addressed 37 Windows 11 vulnerabilities (all important-rated, no critical) including one known exploited CVE and one publicly disclosed issue.
  • Windows 11 enterprise users are experiencing a cosmetic bug where the password icon disappears from the lock screen, though login functionality remains intact with Microsoft working on a resolution.

Adobe and Mozilla Security Releases

Adobe released critical updates for Acrobat and Reader, addressing four vulnerabilities across all supported versions including DC Continuous, Classic 2020, and Classic 2024. Two vulnerabilities were rated critical and two moderate, making this a priority deployment for organizations using these commonly deployed applications. Mozilla simultaneously released Firefox 146 with 13 vulnerabilities fixed (five high-rated, eight moderate), along with extended service release updates for ESR 140.6 (10 vulnerabilities) and ESR 115.31 (four vulnerabilities, three high-rated). Organizations running older Firefox ESR versions should prioritize these updates as part of their monthly patching cycle.

Microsoft Windows and Server Updates

Microsoft's January release marked a rare occurrence with no critical-rated vulnerabilities for Windows 11, addressing 37 important-rated CVEs instead. The update included one known exploited vulnerability (CVE-2025-62221) and one publicly disclosed issue (CVE-2025-54100). A notable reported issue affects enterprise versions of Windows 11 where the password icon disappears from the lock screen, though the login functionality remains operational if users click the expected location. Windows 10-based server versions (Server 2016, 2019, and 2022) received 35 vulnerability fixes with the same exploited and publicly disclosed CVEs. Server 2022 users are experiencing WSUS reporting errors related to a previous remote code execution fix, though Microsoft indicates this is a reporting issue rather than a functional problem. Hot patches were also released this month for supported configurations.

Chapters

0:00 - Adobe Security Updates
0:31 - Mozilla Firefox Releases
1:36 - Microsoft Windows 11 Updates
3:17 - Windows 10 Server Updates
4:43 - Exchange Server Patches
5:22 - Microsoft Office Updates
6:41 - SharePoint Server Fixes

Key Quotes

0:43 "It's very rare for us to see a major OS release that doesn't have a critical CVE addressed. But this month, they were all important."
2:38 "It's just really weird that the visual side of this has disappeared. Interestingly enough, if you dig into this KB, they do provide some directions if this is a big problem for you on how to roll this thing back, but it's pretty complicated."
3:03 "It's also interesting as they say this primarily shows up in enterprise versions of the operating system, not in the professional or the home versions, which is really interesting as well."
5:03 "Interestingly enough, if you look in the security updates guide, they did provide what they're calling ESU updates for those two versions. I haven't figured that one out yet, but apparently they are still providing some updates."

FAQ

What should I do about the missing password icon on Windows 11 lock screens?

The password icon has disappeared visually but the login functionality still works if you click where the icon used to be. Microsoft is working on a fix and has provided rollback instructions in the KB article, though the rollback process is complex with multiple steps. This issue primarily affects enterprise versions of Windows 11, not professional or home editions.

Are Exchange Server 2016 and 2019 still receiving security updates?

While mainstream support has ended for Exchange Server 2016 and 2019, Microsoft is providing what they're calling ESU (Extended Security Update) patches for these versions. If you're running these older versions, you may find applicable patches in the security updates guide, though only the subscription edition has full mainstream support.


Categories:
  • » Webinar Library » Ivanti
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Vulnerability Management
  • Best Practices
  • Webinar
  • Compliance & Governance
  • Patch Tuesday
  • Security Updates
  • Adobe Acrobat
  • Mozilla Firefox
  • Windows 11
  • Exchange Server
  • Microsoft Office
  • SharePoint Server
  • Enterprise Patching
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Ivanti: Adobe, Mozilla & Microsoft Security Updates Breakdown

              Upcoming Webinar Calendar

              • 06/30/2026
                01:00 PM
                06/30/2026
                Master Active Directory Certificate Services and Maintain Your Edge
                https://www.truthinit.com/index.php/channel/2018/master-active-directory-certificate-services-and-maintain-your-edge/
              • 07/01/2026
                04:00 AM
                07/01/2026
                Integrating Security in AI: Automated Red Teaming Strategies for Private Models
                https://www.truthinit.com/index.php/channel/1969/integrating-security-in-ai-automated-red-teaming-strategies-for-private-models/
              • 07/01/2026
                04:00 AM
                07/01/2026
                Schutz von KI in Anwendungen, Agenten und APIs.
                https://www.truthinit.com/index.php/channel/2008/schutz-von-ki-in-anwendungen-agenten-und-apis/
              • 07/01/2026
                01:00 PM
                07/01/2026
                How to Prevent Your AI from Outsmarting You
                https://www.truthinit.com/index.php/channel/2021/how-to-prevent-your-ai-from-outsmarting-you/
              • 07/02/2026
                10:00 AM
                07/02/2026
                Building Resilience Against Hybrid Threats in a Dark Cloud Environment
                https://www.truthinit.com/index.php/channel/2011/building-resilience-against-hybrid-threats-in-a-dark-cloud-environment/
              • 07/08/2026
                02:00 PM
                07/08/2026
                Understanding the Crucial Role of Context in AI Data
                https://www.truthinit.com/index.php/channel/2037/understanding-the-crucial-role-of-context-in-ai-data/
              • 07/09/2026
                01:00 PM
                07/09/2026
                The HUMAN Experience: Empowering Agentic Trust in Practice
                https://www.truthinit.com/index.php/channel/2026/the-human-experience-empowering-agentic-trust-in-practice/
              • 07/14/2026
                01:00 PM
                07/14/2026
                Crafting a Championship-Worthy Security Team for Maximum Defense Effectiveness
                https://www.truthinit.com/index.php/channel/2025/crafting-a-championship-worthy-security-team-for-maximum-defense-effectiveness/
              • 07/21/2026
                04:00 AM
                07/21/2026
                Strategies for Managing AI Governance and Securing App-to-LLM API Traffic
                https://www.truthinit.com/index.php/channel/1967/strategies-for-managing-ai-governance-and-securing-app-to-llm-api-traffic/
              • 07/21/2026
                01:00 PM
                07/21/2026
                HUMAN Dialogue: Insights from Attackers During the FIFA World Cup
                https://www.truthinit.com/index.php/channel/2029/human-dialogue-insights-from-attackers-during-the-fifa-world-cup/
              • 07/22/2026
                06:30 AM
                07/22/2026
                Insights and Strategies from the DPDP Webinar
                https://www.truthinit.com/index.php/channel/2000/insights-and-strategies-from-the-dpdp-webinar/
              • 07/28/2026
                01:00 PM
                07/28/2026
                Illumio + Netskope: Zero Trust in the Age of AI Autonomy
                https://www.truthinit.com/index.php/channel/2031/illumio-netskope-zero-trust-in-the-age-of-ai-autonomy/
              • 07/29/2026
                04:00 AM
                07/29/2026
                Real-Time Strategies for Safeguarding Against Prompt Injections
                https://www.truthinit.com/index.php/channel/1968/real-time-strategies-for-safeguarding-against-prompt-injections/
              • 08/19/2026
                12:00 PM
                08/19/2026
                Master Agent-Ready Skills in 30 Days with Cyera Agent Security
                https://www.truthinit.com/index.php/channel/2036/master-agent-ready-skills-in-30-days-with-cyera-agent-security/
              • 09/30/2026
                04:00 AM
                09/30/2026
                AI Command Center: Optimizing Visibility and Control in Your Operations
                https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/

              Upcoming Events

              • Jun
                30

                Master Active Directory Certificate Services and Maintain Your Edge

                06/30/202601:00 PM ET
                • Jul
                  01

                  Schutz von KI in Anwendungen, Agenten und APIs.

                  07/01/202604:00 AM ET
                  • Jul
                    01

                    Integrating Security in AI: Automated Red Teaming Strategies for Private Models

                    07/01/202604:00 AM ET
                    • Jul
                      01

                      How to Prevent Your AI from Outsmarting You

                      07/01/202601:00 PM ET
                      • Jul
                        02

                        Building Resilience Against Hybrid Threats in a Dark Cloud Environment

                        07/02/202610:00 AM ET
                        More events
                        Truth in IT
                        • Sponsor
                        • About Us
                        • Terms of Service
                        • Privacy Policy
                        • Contact Us
                        • Preference Management
                        Desktop version
                        Standard version