KEV · Actively exploited
CVE-2025-59287
CRITICAL 9.8
KEV
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
EPSS
72.70%
exploit likely
percentile 98.8%
CISA Known Exploited Vulnerability
- Added to KEV
- 2025-10-24
- Remediation deadline
- 2025-11-14
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Ransomware
- No
OS versions that fix this CVE
This CVE is resolved by the following OS security releases. Update the OS to at least the listed version.
- Windows Fixed in Windows Server 2025 (Server Core installation) 10.0.26100.6905 Windows Server 2025 10.0.26100.6905 Windows Server 2022 (Server Core installation) 10.0.20348.4297 Windows Server 2022 10.0.25398.1916 Windows Server 2019 (Server Core installation) 10.0.17763.7922 Windows Server 2019 10.0.17763.7922 Windows Server 2016 (Server Core installation) 10.0.14393.8524 Windows Server 2016 10.0.14393.8524