logo

Patch Tuesday: November 2025 (Expel’s version)

ID: 8ab6f191-4559-5f96-9d9d-090d2a4c88f0

STIX ID: report--8ab6f191-4559-5f96-9d9d-090d2a4c88f0

Feed Name: Expel Blog

Threat Score
85/100

Date Published: 2025-11-12

Date Updated: 2026-04-27

Author: Ben Nahorney; Matt Jastram

...
...

This Patch Tuesday bulletin highlights 63 new Microsoft CVEs—notably a WSUS unsafe-deserialization RCE (CVE-2025-59287) that has been actively exploited with public exploit code, a Windows kernel zero-day added to CISA's KEV, and other high-severity RCE/elevation issues; the report details observed attacker activity (PowerShell data collection and exfiltration), recommends applying out-of-band patches, blocking WSUS ports 8530/8531, and removing or hardening WSUS where unused.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.