Story perspectives
Critical WSUS Vulnerability Prompts Urgent Microsoft Patch
10/29/2025
1 of 1
Story summary
- The Windows Server Update Services (WSUS) vulnerability CVE-2025-59287 enables remote code execution on unpatched servers (CVSS 9.8).
- Exploitation has been active since October 23, 2025, after a proof-of-concept exploit was released.
- Microsoft issued an out-of-band patch the same day.
- Organizations should apply the patch or use mitigations, such as disabling WSUS Server Role.
- The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added it to its Known Exploited Vulnerabilities catalog.
