logo

Critical WSUS flaw in Windows Server now exploited in attacks

ID: df96192c-52c2-5f7b-a57a-5f30a66bb8a1

STIX ID: report--df96192c-52c2-5f7b-a57a-5f30a66bb8a1

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2025-10-24

Date Updated: 2026-07-18

Author: Sergiu Gatlan

...
...

Attackers are exploiting CVE-2025-59287, a critical RCE in Windows Server Update Services (WSUS) that can run code as SYSTEM and may be wormable; public proof-of-concept code is available and security firms (Eye Security, Huntress) plus the Netherlands NCSC have observed scanning and active exploitation, prompting Microsoft to issue emergency patches and recommend disabling the WSUS Server role where immediate patching is not possible.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.