Find notable cyber news and cases, enriched with sources, timelines, and signals.
Vulnerability Exploitation Wave Security Patch Release

ShadowPad staging through WSUS RCE

Updated 24.11.2025 09:18
Case score 62
Members 3 First seen 15.10.2025 00:53 Latest activity 24.11.2025 09:18

Overview

Attackers are exploiting **CVE-2025-59287** in **Windows Server Update Services (WSUS)** to gain SYSTEM-level execution on exposed Windows Server systems and stage **ShadowPad**. One observed chain used **PowerCat**, `certutil.exe`, and `curl.exe` to reach an external host and install the payload through DLL side-loading. Microsoft said it fixed the flaw in **October 2025**, and available evidence now shows live scanning and exploitation attempts against public WSUS instances. **Eye Security** and **NCSC-NL** reported that the abuse is active, and Microsoft later issued emergency updates and temporary workarounds for systems that could not be patched immediately.
Latest development Open development history 2 earlier developments Microsoft discloses WSUS RCE bug Microsoft disclosed CVE-2025-59287, a CVSS 9.8 remote code execution flaw in Windows Server Update Service (WSUS), and tagged it as a vulnerability attackers are more likely to exploit. WSUS is used to centrally distribute and manage updates and patches, so organizations running the service should prioritize remediation to reduce the risk of compromise of the update infrastructure.
  1. Earlier development

    Public WSUS exposure and PoC risk are confirmed

    Eye Security estimated roughly 2,500 WSUS instances worldwide, including 250 in Germany and about 100 in the Netherlands, while the Netherlands National Cyber Security Centre (NCSC-NL) confirmed exploitation of CVE-2025-59287 and warned that publicly available proof-of-concept code increases the risk of abuse.

  2. Earlier development

    Eye Security observes exploitation attempts

    Eye Security observed scanning and exploitation attempts against CVE-2025-59287 on 2025-10-24, and at least one customer system was compromised using a different exploit than the HawkTrace proof-of-concept code.

Signals

Impact signals
Exploitation
CVEs/products
Remediation
Threat context

Malware & tooling context

2 families · 2 tools
Tools

Technical intelligence

Existing Case data

Member happenings

Vulnerability Windows Server Update Service RCE bug (CVE-2025-59287)
Updated 15.10.2025 00:53 Lead Contribution 59
CVSS 9.9 Critical Patch Patch Available

**CVE-2025-59287** is a **critical WSUS RCE flaw** in **Windows Server Update Services** that can put update infrastructure at risk. Microsoft patched the bug in **October 2025**, and recent reporting says **threat actors** are exploiting it on **WSUS-enabled Windows Servers** for **initial access**. In the observed activity, attackers used **PowerCat**, **certutil.exe**, and **curl.exe** to reach an external server and deploy **ShadowPad** via **DLL side-loading**. The exploit can enable **remote code execution with system privileges**, making exposed WSUS instances a high-priority target.

Exploitation Wave WSUS servers CVE-2025-59287 exploitation wave
Updated 24.10.2025 19:28 Scoring Support Contribution 3
Exploitation Active Exploitation CVSS 9.8 Critical Patch Patch Available

**CVE-2025-59287** is being actively exploited against **WSUS-enabled Windows Server** systems, creating **SYSTEM-level remote code execution** risk on exposed servers. The wave matters because **public proof-of-concept code** accelerated abuse, and defenders have already observed **scanning and exploitation attempts** on **2025-10-24**. **Microsoft** issued out-of-band fixes for affected Windows Server versions, while **Eye Security** and **NCSC-NL** warned that publicly reachable WSUS instances remain at elevated risk.

Security Patch Release Microsoft security patch release for CVE-2025-59287
Updated 24.10.2025 10:27 Context
Exploitation Active Exploitation CVSS 9.8 Critical Urgency Immediate Patch Patch Available

**Microsoft** released **out-of-band** security updates for **CVE-2025-59287**, a critical **WSUS** remote code execution flaw affecting **Windows Server** systems with the **WSUS Server Role** enabled. The emergency patches address a bug with **publicly available proof-of-concept exploit code**, raising the urgency for administrators running exposed update servers. Microsoft also advised immediate installation or temporary workarounds such as disabling WSUS or blocking **Ports 8530 and 8531**.