← All CVEs NewScan detects
criticalKEV

CVE-2025-59287

Windows Server Update Services unauthenticated deserialization -> RCE as SYSTEM (CVSS 9.8)

Severity
critical
Affected product
Microsoft WSUS
Affected versions
Microsoft WSUS all versions before the fix
CISA KEV
Listed as a known exploited vulnerability
EPSS
94% chance of exploitation in the next 30 days
Added to NewScan
2026-08-06
Detected by
NewScan — free, self-hosted

How NewScan reports it

APPLIANCE FINGERPRINT

NewScan fingerprints the Microsoft WSUS appliance and reports this CVE when the detected version falls inside the affected range below.

Out-of-band patch 2025-10-24, exploitation observed ~23:34 UTC 2025-10-23 against internet-exposed instances on the default ports. Advisory only - no anonymous version source.

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →