Microsoft issues emergency security patch for Windows server – update now or risk attack


  • Microsoft issues an emergency patch for a critical WSUS bug that allows remote code execution
  • CVE-2025-59287 allows unauthorized attackers to gain SYSTEM privileges without user interaction
  • An out-of-band update was released after public exploit code surfaced online

Microsoft has issued an emergency security patch for Windows Server to fix a Critical Severity bug that appears to have been exploited in the wild.

As part of its latest Patch Tuesday cumulative update (October 14, 2025), Microsoft addressed CVE-2025-59287, a “deserialization of untrusted data” flaw found in the Windows Server Update Service (WSUS).

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top