CVE-2025-59287
Exploited in the Wild
✓ Confirmed 0-Day
Triaged: March 5, 2026
7 articles
EPSS Score
Source: FIRST.org · 2026-05-24
69.07%
probability
This CVE has a 69.07% probability
of being exploited in the next 30 days.
0%
Top 98.7th percentile of all CVEs
100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE.
View on VulnerabilityLookup ↗
Attack Intelligence
Exploits & PoC
M507/CVE-2025-59287-PoC
Unauthenticated RCE PoC in Microsoft Windows Server Update Service (WSUS) - CVE-2025-59287 & CVE-2023-35317
10
LuemmelSec/CVE-2025-59287---WSUS-SCCM-RCE
PoC CVE-2025-59287 — LuemmelSec/CVE-2025-59287---WSUS-SCCM-RCE
2
Adel-kaka-dz/cve-2025-59287
PoC CVE-2025-59287 — Adel-kaka-dz/cve-2025-59287
1
ross-ns/WSUS-CVE-2025-59287
PoC CVE-2025-59287 — ross-ns/WSUS-CVE-2025-59287
0
swoon69/CVE-2025-59287-Exercise-Use
PoC CVE-2025-59287 — swoon69/CVE-2025-59287-Exercise-Use
0
salman5230/CVE-2025-59287
🔍 Analyze WSUS deserialization behavior to enhance security, generate reports, and identify configuration weaknesses in your infrastructure.
0
6 repos — triés par ⭐
Rechercher sur GitHub ↗
Two New Windows Zero-Days Exploited in the Wild — One Affects Every Version Ever Shipped
TheHackerNews
Newly Patched Critical Microsoft WSUS Flaw Comes Under Active Exploitation
TheHackerNews
Oct 24, 2025
Microsoft October 2025 Patch Tuesday fixes 6 zero-days, 172 flaws
BleepingComputer
Oct 14, 2025
ShadowPad Malware Actively Exploits WSUS Vulnerability for Full System Access
TheHackerNews
Nov 24, 2025
Microsoft and Adobe Patch Tuesday, October 2025 Security Update Review
Qualys
Oct 14, 2025
CISA and NSA Issue Urgent Guidance to Secure WSUS and Microsoft Exchange Servers
TheHackerNews
Oct 31, 2025
Security Advisory 2025-040
CERT-EU
Oct 24, 2025
Signal Intelligence
Confidence
92%
EPSS
69.07%
Mentions
7
Last Seen
Nov 24, 2025
CNA Information
Analyst Note
CVE-2025-59287 shows clear zero-day indicators: Microsoft released an out-of-band patch on 2025-10-14, and multiple authoritative sources (TheHackerNews, BleepingComputer) explicitly document active exploitation in the wild occurring concurrently with patch availability. ShadowPad malware exploitation and CISA/NSA guidance further corroborate active attacks. The timing aligns with zero-day criteria (exploitation simultaneous with patch).
Threat Actors 34
Mustang Panda
apt_group
Information theft and espionage
🇨🇳 CN
APT27
apt_group
Information theft and espionage
🇨🇳 CN
Cobalt
apt_group
Financial crime
🇷🇺 RU
APT 28
apt_group
Information theft and espionage
🇷🇺 RU
EMISSARY PANDA
apt_group
Information theft and espionage
🇨🇳 CN
Hacking Team
apt_group
🇮🇹 IT
Watchdog
apt_group
🇨🇳 CN
Operation C-Major
apt_group
Information theft and espionage
🇵🇰 PK
HAZY TIGER
apt_group
Information theft and espionage
🇮🇳 IN
Infy
apt_group
Information theft and espionage
🇮🇷 IR
Group 27
apt_group
Information theft and espionage
🇨🇳 CN
TA428
apt_group
Information theft and espionage
🇨🇳 CN
Earth Lamia
apt_group
Information theft and espionage
🇨🇳 CN
UNC5174
apt_group
🇨🇳 CN
APT-C-27
apt_group
Information theft and espionage
🇸🇾 SY
APT 22
apt_group
Information theft and espionage
🇨🇳 CN
RTM
apt_group
Financial crime
🇷🇺 RU
GOBLIN PANDA
apt_group
Information theft and espionage
🇨🇳 CN
Operation Cobalt Whisper
apt_group
Financial crime
🇨🇳 CN
APT 6
apt_group
Information theft and espionage
🇨🇳 CN
UNC215
apt_group
Information theft and espionage
🇨🇳 CN
Bitwise Spider
apt_group
Financial gain
🇷🇺 RU
Red October
apt_group
🇷🇺 RU
The White Company
apt_group
Information theft and espionage
🇨🇳 CN
Pat Bear
apt_group
🇸🇾 SY
Unnamed Actor
apt_group
🇨🇳 CN
Shadow Network
apt_group
Information theft and espionage
🇨🇳 CN
Mana Team
apt_group
🇨🇳 CN
Iron Group
apt_group
Information theft and espionage
🇨🇳 CN
BRONZE SPRING
apt_group
Information theft and espionage
🇨🇳 CN
SharpPanda
apt_group
Information theft and espionage
🇨🇳 CN
APT 5
apt_group
Information theft and espionage
🇨🇳 CN
Cyber Alliance
apt_group
🇺🇦 UA
Dark Partners
apt_group
Triage Info
Decided atMar 05, 2026