Story perspectives
Urgent WSUS Vulnerability: Federal Agencies Must Patch By November
10/27/2025
1 of 1
Story summary
- The Windows Server Update Service (WSUS) vulnerability CVE-2025-59287 is being exploited, enabling unauthenticated attackers to execute malicious code.
- The Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to apply the emergency patch by November 14, 2025.
- Organizations unable to update immediately should disable the WSUS role or block traffic to ports 8530 and 8531.
- Security experts urge immediate action to prevent breaches.
