Microsoft Windows Server Update Services (WSUS) is affected by CVE-2025-59287, a critical unauthenticated remote code execution flaw with a CVSS 9.8 score that is being actively exploited in the wild. The vulnerability stems from insecure deserialization of AuthorizationCookie objects handled by the GetCookie() endpoint, allowing a remote attacker to send crafted POST requests to WSUS servers exposed on ports 8530 and 8531 and execute arbitrary code as SYSTEM.
Observed exploitation has involved WSUS-related processes such as w3wp.exe and wsusservice.exe spawning cmd.exe and powershell.exe, indicating full server compromise through the update management service. Microsoft has issued an emergency security update for affected WSUS deployments, while defenders have been urged to patch immediately, restart servers after applying fixes, and restrict inbound access to ports 8530 and 8531 or disable WSUS temporarily if patching cannot be completed at once.

See which actors are running it and whether you're in range.
4 events from the most recent confirmed update back to the earliest known activity.
CSIRT.SK published an alert describing CVE-2025-59287 as a critical actively exploited WSUS vulnerability with CVSS 9.8, caused by insecure deserialization in AuthorizationCookie objects handled by the GetCookie() endpoint. The advisory also recommended restricting inbound traffic to ports 8530 and 8531 or disabling WSUS if patching was not possible.
Attackers were observed actively exploiting exposed Windows Server Update Services servers by sending crafted POST requests to ports 8530 and 8531. Observed abuse included w3wp.exe and wsusservice.exe launching cmd.exe and powershell.exe, indicating code execution as SYSTEM.
Microsoft released an emergency update for the critical WSUS remote code execution vulnerability CVE-2025-59287 and advised administrators to patch affected servers and restart them.
The Dutch NCSC reported that a trusted partner observed exploitation of CVE-2025-59287 and raised its assessment to High/High, citing high likelihood of exploitation and high potential impact. It urged organizations to apply the emergency update and avoid exposing WSUS directly to the public internet.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
6 references tracked. Mallory keeps watching after this page renders.
ncsc.gov.pg
Open sourcecsirt.sk
Open sourcencsc.nl
Open sourcehawktrace.com
Open sourcehuntress.com
Open sourcemsrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.