Drooid Logo
Back to today’s briefing

Story perspectives

Critical WSUS Vulnerability Prompts Urgent Microsoft Patch

10/29/2025

50 7 Full Breakdown

1 of 1

Story summary
  • The Windows Server Update Services (WSUS) vulnerability CVE-2025-59287 enables remote code execution on unpatched servers (CVSS 9.8).
  • Exploitation has been active since October 23, 2025, after a proof-of-concept exploit was released.
  • Microsoft issued an out-of-band patch the same day.
  • Organizations should apply the patch or use mitigations, such as disabling WSUS Server Role.
  • The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added it to its Known Exploited Vulnerabilities catalog.