Newly Patched Critical Microsoft WSUS Flaw Comes Under Active Exploitation
Microsoft patched a critical-severity Windows Server Update Service (WSUS) vulnerability with out-of-band security upgrades on Thursday. The exploit's proof-of-concept (PoC) is publicly available and is already being actively exploited in the field.
The issue is CVE-2025-59287 (CVSS score: 9.8), a remote code execution vulnerability in Windows Server that was initially resolved by the tech giant last week as part of its Patch Tuesday update.
The flaw was found and reported by three security researchers: Markus Wulftange at CODE WHITE GmbH, MEOW, and f7d8c52bec79e42795cf15888b85cbad.
The flaw pertains to a situation where an unauthorized attacker can run code over a network due to the deserialization of untrusted data in WSUS. It is important to note that Windows servers without t...

