Critical WSUS flaw in Windows Server now exploited in attacks
ID: df96192c-52c2-5f7b-a57a-5f30a66bb8a1
STIX ID: report--df96192c-52c2-5f7b-a57a-5f30a66bb8a1
Feed Name: Bleeping Computer
Threat Score
Attackers are exploiting CVE-2025-59287, a critical RCE in Windows Server Update Services (WSUS) that can run code as SYSTEM and may be wormable; public proof-of-concept code is available and security firms (Eye Security, Huntress) plus the Netherlands NCSC have observed scanning and active exploitation, prompting Microsoft to issue emergency patches and recommend disabling the WSUS Server role where immediate patching is not possible.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
