logo

CISA orders feds to patch actively exploited Windows Server WSUS flaw

ID: 87dbca39-1510-589a-af83-4fd5c97bd700

STIX ID: report--87dbca39-1510-589a-af83-4fd5c97bd700

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2025-10-27

Date Updated: 2026-07-18

Author: Sergiu Gatlan

...
...

**Executive summary:** CISA ordered U.S. federal agencies to urgently patch CVE-2025-59287, a critical, potentially wormable WSUS remote code execution vulnerability actively exploited in the wild (proof-of-concept released, scanning/exploitation observed), prompting Microsoft out-of-band updates and recommendations to disable the WSUS Server role if patches cannot be immediately applied.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.