The Cybersecurity and Infrastructure Security Agency (CISA) ordered U.S. government agencies to patch a critical-severity Windows Server Update Services (WSUS) vulnerability after adding it to its catalog of security flaws exploited in attacks. Tracked as CVE-2025-59287, this actively exploited, potentially wormable remote code execution (RCE) vulnerability affects Windows servers with the WSUS Server role (a feature that isn't enabled by default) that act as update sources for other WSUS servers within the organization. Attackers can abuse it remotely in low-complexity attacks that don't require user interaction or privileges, allowing them to gain SYSTEM privileges and run malicious code. On Thursday, after cybersecurity firm HawkTrace Security released proof-of-concept exploit code, Microsoft released out-of-band security updates to "comprehensively address CVE-2025-59287" on all impacted Windows Server versions and advised IT administrators to install them as soon as possible. IT admins who can't immediately deploy the emergency patches are advised to disable the WSUS Server role on vulnerable systems to remove the attack vector. The day CVE-2025-59287 patches were released, American cybersecurity company Huntress found evidence of CVE-2025-59287 attacks targeting WSUS instances with their default ports (8530/TCP and 8531/TCP) exposed online. Dutch cybersecurity firm Eye Security also observed scanning and exploitation attempts on Friday morning, with at least one of its...
CISA orders feds to patch Windows Server WSUS flaw used in attacks
Affected Software
Frequently Asked Questions
What is the main topic of this article?
The article discusses a critical vulnerability in Windows Server Update Services (WSUS) that has been exploited in attacks and the subsequent CISA directive for federal agencies to apply patches.
What security implications are discussed in the article?
The article highlights that the WSUS vulnerability poses serious risks as it can be exploited by attackers, potentially allowing unauthorized access or disruptions.
What products or software are affected by the vulnerability?
The primary affected software mentioned is Microsoft Windows Server Update Services (WSUS) along with Adobe Commerce.
Who issued the directive to patch the vulnerability?
The directive to patch the WSUS vulnerability was issued by the Cybersecurity and Infrastructure Security Agency (CISA).
Why is it important for federal agencies to patch this vulnerability?
It is crucial for federal agencies to patch this vulnerability to protect sensitive information and maintain the integrity of their systems against active exploitation.