CISA orders feds to patch actively exploited Windows Server WSUS flaw
ID: 87dbca39-1510-589a-af83-4fd5c97bd700
STIX ID: report--87dbca39-1510-589a-af83-4fd5c97bd700
Feed Name: Bleeping Computer
Threat Score
**Executive summary:** CISA ordered U.S. federal agencies to urgently patch CVE-2025-59287, a critical, potentially wormable WSUS remote code execution vulnerability actively exploited in the wild (proof-of-concept released, scanning/exploitation observed), prompting Microsoft out-of-band updates and recommendations to disable the WSUS Server role if patches cannot be immediately applied.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
