SophiaX
🔍
LIVE
· New victim: cipher.systems — m3rx· New victim: International Chemical Co. — Barracuda· New victim: M****n — payoutsking· New victim: Applied Composites — Storm· New victim: Magna Legal Services — Storm· New KEV: CVE-2026-65660 · Microsoft· New KEV: CVE-2026-87902 · WordPress· New KEV: CVE-2026-67279 · MikroTik· New KEV: CVE-2026-71362 · Adobe· New KEV: CVE-2026-5430 · WSO2· New victim: 6,898 new IOCs ingested in last 24h cipher.systems — m3rx· New victim: International Chemical Co. — Barracuda· New victim: M****n — payoutsking· New victim: Applied Composites — Storm· New victim: Magna Legal Services — Storm· New KEV: CVE-2026-65660 · Microsoft· New KEV: CVE-2026-87902 · WordPress· New KEV: CVE-2026-67279 · MikroTik· New KEV: CVE-2026-71362 · Adobe· New KEV: CVE-2026-5430 · WSO2· 6,898 new IOCs ingested in last 24h

CVE-2025-59287

⚡ CISA KEV
Published: —Modified: —Vendor: MicrosoftProduct: Windows
—
CVSS v3
100.0%
EPSS
⚡ Added to KEV on 2025-10-24 · Federal agencies must remediate by 2025-11-14
Microsoft Windows Server Update Service (WSUS) contains a deserialization of untrusted data vulnerability that allows for remote code execution.
💣 Public Exploits0
From Exploit-DB
No public exploits in Exploit-DB.
🔍 Sigma Detection Rules2
Rules tagged with this CVE
highExploitation Activity of CVE-2025-59287 - WSUS Suspicious Child Processwindows—
highExploitation Activity of CVE-2025-59287 - WSUS Deserializationwindows—
🛠️ Patch Details11
Affected/fixed versions from threat intel reports
Microsoft Windows Serversource ↗
Microsoft Windows Server Update Services (WSUS)——source ↗
Microsoft Windows Server Update Services (WSUS)——source ↗
Microsoft Windows Server 2019source ↗
Microsoft Windows Server 2022source ↗
Microsoft Windows Server 2012source ↗
Microsoft Windows Server Update Services——source ↗
Microsoft Windows Server 2025source ↗
Microsoft Windows Server 2012 R2source ↗
Microsoft Windows Server 2016source ↗
Microsoft Windows Server Update Servicessource ↗
📎 References0
No reference URLs.