More threat intel teams are sounding the alarm about a critical Windows Server Update Services (WSUS) remote code execution vulnerability, tracked as CVE-2025-59287 and now under active exploitation, just days after Microsoft pushed an emergency patch and the US Cybersecurity and Infrastructure Security Agency added the bug to its Known Exploited Vulnerabilities catalog. Microsoft hasn’t updated its advice about the flaw to reveal to note the active in-the-wild exploitation detected by multiple credible sources. Redmond instead lists CVE-2025-59287 as not having been publicly disclosed, or exploited. The software giant does rate the bug as "exploitation more likely," which may be the understatement of the month. "We are actively investigating the exploitation of CVE-2025-59287 by a newly identified threat actor we are tracking as UNC6512, across multiple victim organizations," Google Threat Intelligence Group (GTIG) said in an email, in response to The Register's questions. "Following initial access, the actor has been observed executing a series of commands to conduct reconnaissance on the compromised host and the associated environment," GTIG continued. "We have also observed exfiltration from impacted hosts." Microsoft declined to answer The Register's questions about reported attacks but pointed out it does not typically update security advisories post-release unless its initial post was inaccurate. CVE-2025-59287, which affects Windows Server versions 2012 through 2025, ...
WSUS attacks hit 'multiple' orgs as Google and other infosec sleuths ring Redmond’s alarm bell
The Register
·Jessica Lyons
·Published Oct 27, 2025
·Updated
Affected Software
1 affected component
Microsoft Windows Server Update Services
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the recent active exploitation of a critical vulnerability in Microsoft Windows Server Update Services (WSUS), tracked as CVE-2025-59287.
2
What security implications are discussed in the article?
The article highlights the risks associated with the remote code execution vulnerability in WSUS, which poses a significant threat to multiple organizations.
3
What is CVE-2025-59287?
CVE-2025-59287 is a critical vulnerability in Windows Server Update Services that allows for remote code execution.
4
Which organizations are affected by these WSUS attacks?
The article notes that multiple organizations have been impacted by attacks exploiting the WSUS vulnerability.
5
What actions are being recommended in response to the WSUS vulnerability?
The article implies that organizations should urgently address the vulnerability by applying relevant patches and updates.