Researchers at the Sophos Counter Threat Unit (CTU) have uncovered how attackers are exploiting a vulnerability in Windows Server Update Services (WSUS) to steal sensitive data from companies. The experts are investigating the exploitation of a remote code execution vulnerability (CVE-2025-59287) in Microsoft’s Windows Server Update Service (WSUS), a native IT management tool for Windows system administrators. On October 14, 2025, Microsoft released patches for the affected Windows Server versions. After publishing a technical analysis of CVE-2025-59287 and deploying a proof of concept (PoC) code on GitHub, Microsoft released an unscheduled security update on October 23rd.
On October 24, Sophos discovered abuse of a critical vulnerability in several customer environments. The wave of attacks, which spanned several hours and targeted publicly accessible WSUS servers, affected customers across a wide range of industries and did not appear to be a targeted attack. It is unclear whether the attackers used the publicly available proof of concept or developed their own exploit.
“This activity shows that attackers acted quickly to exploit this critical vulnerability in WSUS and collect valuable data from vulnerable organizations. We have clearly identified six incidents through Sophos telemetry so far, but this is likely just the tip of the iceberg. Further investigation identified at least 50 victims, primarily in the US, including universities, technology, manufacturing and healthcare organizations. This may have been an initial testing or reconnaissance phase and the attackers are now analyzing the collected data to identify new attack opportunities We are not currently seeing any further mass attacks, but it is still early and security leaders should consider this as an early warning. Organizations should ensure their systems are fully patched and WSUS servers are securely configured to minimize the risk of an attack.” – Rafe Pilling, Director of Threat Intelligence at Sophos Counter Threat Unit
The CTU researchers recommend that companies heed the manufacturer’s warning and immediately apply the patches and instructions for fixing the vulnerability. More information is available in English blog post with details of the findings.

