criticalKEV
CVE-2025-59287
Windows Server Update Services unauthenticated deserialization -> RCE as SYSTEM (CVSS 9.8)
- Severity
- critical
- Affected product
- Microsoft WSUS
- Affected versions
- Microsoft WSUS all versions before the fix
- CISA KEV
- Listed as a known exploited vulnerability
- EPSS
- 94% chance of exploitation in the next 30 days
- Added to NewScan
- 2026-08-06
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
APPLIANCE FINGERPRINT
NewScan fingerprints the Microsoft WSUS appliance and reports this CVE when the detected version falls inside the affected range below.
Out-of-band patch 2025-10-24, exploitation observed ~23:34 UTC 2025-10-23 against internet-exposed instances on the default ports. Advisory only - no anonymous version source.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →