Find notable cyber news and cases, enriched with sources, timelines, and signals.
Vulnerability Exploitation Wave Security Patch Release

ShadowPad staging through WSUS RCE

Updated 24.11.2025 09:18
Case score 62
Case score 62 Members 3 Latest activity 24.11.2025 09:18
Active exploitation Patch available CVSS: 9.9 Critical
Members 3 First seen 15.10.2025 00:53 Last seen 24.10.2025 19:28 Updated 24.11.2025 09:18

Overview

Attackers are exploiting **CVE-2025-59287** in **Windows Server Update Services (WSUS)** to gain SYSTEM-level execution on exposed Windows Server systems and stage **ShadowPad**. One observed chain used **PowerCat**, `certutil.exe`, and `curl.exe` to reach an external host and install the payload through DLL side-loading. Microsoft said it fixed the flaw in **October 2025**, and available evidence now shows live scanning and exploitation attempts against public WSUS instances. **Eye Security** and **NCSC-NL** reported that the abuse is active, and Microsoft later issued emergency updates and temporary workarounds for systems that could not be patched immediately.

Signals

9 derived
Exploitation
CVSS Exploitation Active exploitation
CVEs/products
CVE
Victims/regions
Victim region Germany Victim region Netherlands
Remediation
Urgency Immediate Remediation Patch available
Threat context
Malware Tooling

Malware context

2 families · 2 tools
Tools
PowerCat Velociraptor

Member happenings

3 related
Vulnerability Windows Server Update Service RCE bug (CVE-2025-59287)
Updated 15.10.2025 00:53 Lead Contribution 59
CVSS 9.9 Critical Patch Patch Available

**CVE-2025-59287** is a **critical WSUS RCE flaw** in **Windows Server Update Services** that can put update infrastructure at risk. Microsoft patched the bug in **October 2025**, and recent reporting says **threat actors** are exploiting it on **WSUS-enabled Windows Servers** for **initial access**. In the observed activity, attackers used **PowerCat**, **certutil.exe**, and **curl.exe** to reach an external server and deploy **ShadowPad** via **DLL side-loading**. The exploit can enable **remote code execution with system privileges**, making exposed WSUS instances a high-priority target.

Exploitation Wave WSUS servers CVE-2025-59287 exploitation wave
Updated 24.10.2025 19:28 Scoring Support Contribution 3
Exploitation Active Exploitation CVSS 9.8 Critical Patch Patch Available

**CVE-2025-59287** is being actively exploited against **WSUS-enabled Windows Server** systems, creating **SYSTEM-level remote code execution** risk on exposed servers. The wave matters because **public proof-of-concept code** accelerated abuse, and defenders have already observed **scanning and exploitation attempts** on **2025-10-24**. **Microsoft** issued out-of-band fixes for affected Windows Server versions, while **Eye Security** and **NCSC-NL** warned that publicly reachable WSUS instances remain at elevated risk.

Security Patch Release Microsoft security patch release for CVE-2025-59287
Updated 24.10.2025 10:27 Context
Exploitation Active Exploitation CVSS 9.8 Critical Urgency Immediate Patch Patch Available

**Microsoft** released **out-of-band** security updates for **CVE-2025-59287**, a critical **WSUS** remote code execution flaw affecting **Windows Server** systems with the **WSUS Server Role** enabled. The emergency patches address a bug with **publicly available proof-of-concept exploit code**, raising the urgency for administrators running exposed update servers. Microsoft also advised immediate installation or temporary workarounds such as disabling WSUS or blocking **Ports 8530 and 8531**.