logo

Microsoft WSUS Remote Code Execution (CVE-2025-59287) Actively Exploited in the Wild (Updated November 3)

ID: 1dafdaae-bee6-5382-a44b-78f96719f26b

STIX ID: report--1dafdaae-bee6-5382-a44b-78f96719f26b

Feed Name: Palo Alto Networks Unit 42

Threat Score
90/100

Date Published: 2025-11-03

Date Updated: 2026-04-28

Author: Unit 42

...
...

Palo Alto Networks Unit 42 reports a critical unauthenticated RCE in Windows Server Update Services (CVE-2025-59287, CVSS 9.8) rooted in unsafe deserialization; Microsoft released an out-of-band patch after initial mitigation proved incomplete and researchers observed active exploitation targeting internet-exposed WSUS instances (ports 8530/8531), with attackers performing reconnaissance and exfiltration via PowerShell payloads. The brief provides technical attack paths, observed process chains and commands, ~5,500 exposed instances metric, interim mitigations (disable WSUS or block ports), XQL/XSOAR detection and response content, and a known IOC (webhook.site endpoint).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.