CVE-2025-59287Active Exploitation(microsoft / windows_server_2012)

HIGHCVSS 9.8 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Patch microsoft windows_server_2012 systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over a network.

6.3/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-11-14. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-502

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_server_2012
  • windows_server_2016
  • windows_server_2019
  • windows_server_2022

Threat summary

  • Active exploitation appears in 4 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 10 mentions across 9 observed days

What's happening

  • Active exploitation reported across 4 signals
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 4 signals
  • General: 3 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-07-28)
  • 10 total mentions across 9 days

Affected systems

Vendors
Products
windows_server_2012windows_server_2016windows_server_2019windows_server_2022windows_server_2022_23h2windows_server_2025

2 versions affected across 6 products

Deep dive

Activity timeline10 mentions / 9d
01122Mentions · 2026-02-05: 1Mentions · 2026-02-10: 1Mentions · 2026-02-14: 1Mentions · 2026-03-08: 1Mentions · 2026-03-16: 1Mentions · 2026-03-19: 1Mentions · 2026-03-28: 1Mentions · 2026-07-17: 1Mentions · 2026-07-28: 2PoC Mentioned / Linked · 2026-03-16: 1Active Exploitation · 2026-03-16: 1Active Exploitation · 2026-03-19: 1Active Exploitation · 2026-03-28: 1Active Exploitation · 2026-07-28: 1Patch / Workaround · 2026-02-10: 1Patch / Workaround · 2026-03-19: 1Patch / Workaround · 2026-07-17: 1Patch / Workaround · 2026-07-28: 2Technical Details · 2026-02-05: 1Technical Details · 2026-02-10: 1Technical Details · 2026-03-16: 1Technical Details · 2026-07-28: 102-0502-1002-1403-0803-1603-1903-2807-1707-28
Signal classification4 categories
Active Exploitation
440.0%
General
330.0%
Patch
220.0%
Disclosure
110.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-051
General1
2026-02-101
Patch1
2026-02-141
General1
2026-03-081
General1
2026-03-161
Active Exploitation1
2026-03-191
Active Exploitation1
2026-03-281
Active Exploitation1
2026-07-171
Patch1
2026-07-282
Active Exploitation1Disclosure1
Full discourse10 posts
  • A.Mugh33ra🇵🇰❤️🇵🇸@mugh33ra
    General

    Found CVE-2025-59287 kinda hard to exploit target: BBP open to collab 50/50 #BugBounty #hackerone #idor #sqlinjection #bugbountytip #xss #injection https://t.co/oAe9yB9lZw

    Post summary

    The tweet reports discovering CVE-2025-59287 and notes it’s hard to exploit, but offers no PoC, exploit code, or detailed technical information.

    1080144689.1K
    2.1K followersView on X
  • Crowdfense@crowdfense
    General

    The following vulnerabilities have been added to our feed: CVE-2025-53136: NT OS KASLR Bypass CVE-2025-30397: Internet Explorer/Edge Chakra Engine RCE CVE-2025-59287: Windows Server Update RCE CVE-2025-24893: XWiki Groovy Injection RCE https://www.crowdfense.com/n-day-feed/

    Post summary

    The feed lists several new CVEs with brief technical descriptors but contains no evidence of PoCs, exploits, active attacks, patches, or debunking claims.

    05033212.5K
    2.9K followersView on X
  • Günter Born@etguenni
    Patch

    Nach den kumulative Updates vom 14. Juli 2026 können Windows-Clients nicht mehr an #WSUS reporten. Hängt mit #CVE-2025-59287 zusammen, weshalb eine Funktion im WSUS temporär deaktiviert wurde. https://borncity.com/blog/2026/07/17/windows-clients-wsus-reporting-probleme-nach-updates-vom-14-juli-2026/

    Post summary

    The July 14, 2026 updates caused Windows clients to stop reporting to WSUS due to CVE-2025-59287, leading to a temporary disabling of a WSUS function as a workaround.

    030471.2K
    2.8K followersView on X
  • CVE Brief@DailyCVEBrief
    Active Exploitation

    LOOK BACK — Microsoft shipped a WSUS deserialization RCE fix on Oct 14, 2025. A later binary diff found the October build was the first to contain the vulnerable sink. CVE-2025-59287 was exploited in the wild the same day the out-of-band re-fix landed. https://t.co/egGv6zmqPG

    Post summary

    Microsoft issued a WSUS deserialization RCE fix (CVE‑2025‑59287) after the flaw was actively exploited on the same day, confirming its impact and the urgency of patching.

    1000036
    22 followersView on X
  • transilienceai@transilienceai
    General

    @VulmonFeeds 🔍 No detailed technical description, CVSS score, affected versions, or exploit specifics appear in available sources. It does not match other listed CVEs like CVE-2025-59287 (WSUS RCE). #CyberSecurity

    Post summary

    The post indicates a lack of technical detail about the CVE and does not mention PoC, exploit, patch, or active exploitation.

    1000047
    315 followersView on X
  • CVE Brief@DailyCVEBrief
    Disclosure

    Full Look Back: the .NET Framework deprecation gap, why the real fix was deleting the call rather than guarding it, and how a CVE-number typo filed a 2023 bug under a 2025 ID across most coverage. https://cvebrief.com/cve/CVE-2025-59287/ https://t.co/LhrgPMjkrk

    Post summary

    The tweet explains the .NET Framework deprecation gap bug, highlights a CVE-number typo, and notes that the fix involved deleting the call, but does not mention any exploit, active attacks, or detailed vulnerability characteristics.

    0000022
    22 followersView on X
  • John Christly@christly
    Active Exploitation

    https://cybersec.xmcyber.com/s/windows-server-update-service-wsus-critical-vulnerability-cve-2025-59287-under-active-exploitation-26228/1

    Post summary

    The article title signals that CVE‑2025‑59287 in WSUS is being actively exploited, yet no concrete exploit code, a patch, or detailed technical description is provided.

    00000191
    437 followersView on X
  • Security Aid@SecurityAid
    Active Exploitation

    Actively Exploited WSUS Bug Added to CISA KEV List Sysadmins are urged to patch WSUS vulnerability CVE-2025-59287 as soon as possible, with federal agencies required to update by November 14Sysadmins are urged to patch WSUS vulnerability CVE-2025-59287 as soon as possible, wi... https://t.co/fIvIYMK95R

    Post summary

    The tweet announces that CVE-2025-59287 is actively exploited, has been added to the CISA KEV list, and urges immediate patching with a deadline for federal agencies.

    00000120
    126 followersView on X
  • Security Aid@SecurityAid
    Active Exploitation

    Critical Windows Server WSUS Vulnerability Exploited in the Wild  CVE-2025-59287 allows a remote, unauthenticated attacker to execute arbitrary code and a PoC exploit is available. The post Critical Windows Server WSUS Vulnerability Exploited in the Wild  appeared first on Se... https://t.co/vZ34Ds4iqi

    Post summary

    The post reports that CVE-2025-59287 is actively exploited in the wild, provides a PoC reference, and outlines the remote code execution nature of the flaw without mentioning patches or mitigations.

    00000123
    126 followersView on X
  • Engr.Abdulmajeed AlQarni@MjodQ95
    Patch

    🚨 CVE-2025-59287 — ثغرة WSUS ثغرة حرجة في Windows Server Update Services تُمكّن مهاجم من تنفيذ كود عن بُعد بصلاحية SYSTEM. ** إجراء فوري: ثبّت تحديث مايكروسوفت الخاص بالـ WSUS فوراً، واعزل خوادم WSUS عن الإنترنت أو احظر المنافذ 8530/8531، وراجع سجلات النشاط https://t.co/R0wv60IDY9

    Post summary

    The tweet alerts to a critical remote‑code‑execution flaw in Windows Server Update Services, urging immediate patching and isolation of WSUS servers to mitigate the risk.

    00000142
    3 followersView on X
CPE platform detail7 entries

7 of 7 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_server_2012---
OSmicrosoftwindows_server_2012r2--
OSmicrosoftwindows_server_2016---
OSmicrosoftwindows_server_2019---
OSmicrosoftwindows_server_2022---
OSmicrosoftwindows_server_2022_23h2---
OSmicrosoftwindows_server_2025---

Explore more