• News/
  • https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-windows-server-wsus-flaw-exploited-in-attacks/

CISA orders feds to patch Windows Server WSUS flaw used in attacks

BleepingComputer
·
Sergiu Gatlan
·
Published Oct 27, 2025
·
Updated

The Cybersecurity and Infrastructure Security Agency (CISA) ordered U.S. government agencies to patch a critical-severity Windows Server Update Services (WSUS) vulnerability after adding it to its catalog of security flaws exploited in attacks. Tracked as CVE-2025-59287, this actively exploited, potentially wormable remote code execution (RCE) vulnerability affects Windows servers with the WSUS Server role (a feature that isn't enabled by default) that act as update sources for other WSUS servers within the organization. Attackers can abuse it remotely in low-complexity attacks that don't require user interaction or privileges, allowing them to gain SYSTEM privileges and run malicious code. On Thursday, after cybersecurity firm HawkTrace Security released proof-of-concept exploit code, Microsoft released out-of-band security updates to "comprehensively address CVE-2025-59287" on all impacted Windows Server versions and advised IT administrators to install them as soon as possible. IT admins who can't immediately deploy the emergency patches are advised to disable the WSUS Server role on vulnerable systems to remove the attack vector. The day CVE-2025-59287 patches were released, American cybersecurity company Huntress found evidence of CVE-2025-59287 attacks targeting WSUS instances with their default ports (8530/TCP and 8531/TCP) exposed online. Dutch cybersecurity firm Eye Security also observed scanning and exploitation attempts on Friday morning, with at least one of its...

Read full article

Affected Software

2 affected components
Microsoft Windows Server Update Services (WSUS) Server role
Adobe Commerce
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a critical vulnerability in Windows Server Update Services (WSUS) that CISA has mandated U.S. government agencies to patch.

2

What security implications are discussed?

The article highlights that the WSUS vulnerability has been actively exploited in cyberattacks, posing significant risks to affected systems.

3

What products or software are affected?

The affected software includes Microsoft Windows Server Update Services and Microsoft Windows Server.

4

Why is it important for government agencies to respond to this vulnerability?

It is crucial for government agencies to patch this vulnerability to mitigate risks and protect sensitive data from exploitation.

5

What action did CISA take regarding this issue?

CISA ordered U.S. government agencies to implement the necessary patches to address the identified WSUS vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203