26/10/2025
🚨 Critical WSUS Vulnerability Exploited in the Wild — Patch Now! 🚨
Microsoft has confirmed a critical remote code ex*****on (RCE) vulnerability in Windows Server Update Services (WSUS) — CVE-2025-59287 — that can be triggered by an unauthenticated attacker. This flaw affects WSUS on supported Windows Server releases and a public proof-of-concept has already been published, with active exploitation reported.
If you run WSUS:
• Install Microsoft’s out-of-band patch immediately (reboot required).
• Temporarily disable the WSUS Server Role or block inbound ports 8530/8531 if you can’t patch right away — but note this will stop client updates.
Don’t wait — unpatched WSUS servers can let attackers run code as SYSTEM and pivot across your network. Share with your IT/security team and check your patching schedule now. 🔒