The Cybersecurity and Infrastructure Security Agency (CISA) has ordered US government agencies to fix a critical vulnerability in Windows Server Update Services (WSUS) after adding it to its list of security vulnerabilities exploited by attacks.
See also: CISA added five new vulnerabilities to the KEV List

The vulnerability, tracked as CVE-2025-59287, is an actively exploited, potentially communicable remote code execution (RCE) vulnerability affecting Windows servers with the WSUS Server role, which act as update sources for other servers within an organization. Attackers can exploit it remotely in low-sophistication attacks that do not require user interaction or privileges, allowing them to gain SYSTEM privileges and execute malicious code.
On Thursday, following the release of exploit code by cybersecurity firm HawkTrace Security, Microsoft released unscheduled security updates to “fully address CVE-2025-59287” on all affected versions of Windows Server and advised IT administrators to install them as soon as possible. IT administrators who cannot immediately apply the hotfixes are advised to disable the WSUS Server role on vulnerable systems to remove the attack surface.
On the day the fixes for CVE-2025-59287 were released, US cybersecurity firm Huntress found evidence of attacks targeting instances of wsυs with their default ports (8530/TCP and 8531/TCP) exposed to the internet. Dutch cybersecurity firm Eye Security also observed scanning and exploitation attempts, with at least one of its clients' systems compromised using a different exploit than the one reported by HawkTrace.
See also: CISA added Adobe AEM vulnerability to the KEV List

While Microsoft has classified CVE-2025-59287 as “Most Likely Exploitable,” it has yet to update its security advisory to confirm the active exploit. Internet monitoring group Shadowserver is tracking over 2,800 WSUS instances with default ports exposed to the internet, though it did not specify how many have already been patched.
On Friday, CISA added a second vulnerability affecting Adobe Commerce (formerly Magento) stores, which was also identified as being exploited in attacks last week. CISA added both vulnerabilities to the Known Exploitable Vulnerabilities list, which includes security weaknesses that are actively being exploited. As mandated by Binding Operating Directive (BOD) 22-01 of November 2021, U.S. Federal agencies of the Executive Branch must patch their systems within three weeks, by November 14, to secure them from potential breaches.
While this only applies to U.S. government agencies, all IT administrators and defenders are urged to prioritize fixing these security weaknesses as soon as possible. CISA said that these types of vulnerabilities are common attack points for malicious cybercriminals and pose significant risks to federal business. CISA strongly urges organizations to implement Microsoft’s updated guidance for the remote code execution vulnerability in Windows Server Update Service (WSUS) or risk an unauthenticated attacker achieving remote code execution with system privileges.
See also: CISA added Zimbra vulnerability to KEV Catalog

CISA recommends that network defenders identify all vulnerable servers and apply the out-of-program security updates for CVE-2025-59287. After installation, restart the WSUS servers to complete the remediation and secure the remaining Windows servers.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
