Saturday , June 20 2026

(CVE-2025-59287)
CIRT Alert RCE Vulnerability in Microsoft WSUS in Bangladesh

Bangladesh cyber security watchdog BGD e-GOV CIRT published an advisory (27.10.2025) regarding critical romote code execution vulnarability in Microsoft WSUS CVSS score 9.8 as per NVD, NIST.

CIRT has detected a serious security flaw in Microsoft’s WSUS that could let an attacker fully control a WSUS server. This vulnerability not only impacts the server but could also enable the attacker to send harmful updates, compromise devices, and gain significant access to our network. It considers this a high-priority incident and urge immediate patching or mitigation for all WSUS servers. Inaction could result in regulatory, operational, and reputational harm.

CISA: Splunk flaw under active exploit, patch by Sunday

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has asked federal agencies to protect their systems by Sunday from a...
Read More
CISA: Splunk flaw under active exploit, patch by Sunday

Texas data breach exposes 3 million driver’s licenses

The Texas Parks and Wildlife Department (TPWD) revealed a data leak at its license system provider. This leak exposed private...
Read More
Texas data breach exposes 3 million driver’s licenses

Critical Cisco ISE Vulnerability Enables Remote Code Execution

Cisco has revealed critical security flaws in its Identity Services Engine (ISE). These flaws could let attackers run harmful code...
Read More
Critical Cisco ISE Vulnerability Enables Remote Code Execution

F5 Patches NGINX Flaw for Code Execution and DoS Attacks

F5 has shared a security warning about serious flaws in NGINX. These issues could let attackers run any code and...
Read More
F5 Patches NGINX Flaw for Code Execution and DoS Attacks

FortiBleed: 70,000 Fortinet Firewalls Compromised Globally

A vast cyber spying operation called “FortiBleed” has quietly compromised more than 73,932 different Fortinet firewall URLs in 194 countries....
Read More
FortiBleed: 70,000 Fortinet Firewalls Compromised Globally

New Rokarolla Android malware hits 217 banking and crypto apps

A new Android banking trojan called Rokarolla is hitting 217 banking and cryptocurrency apps with a wide range of 137...
Read More
New Rokarolla Android malware hits 217 banking and crypto apps

Phishing Campaign Exploits Legitimate Microsoft Login Flow

Attackers are using Microsoft’s OAuth 2.0 Device Authorization Grant (device code) flow in a campaign to take control of Microsoft...
Read More
Phishing Campaign Exploits Legitimate Microsoft Login Flow

ALERT
Cisco SD-WAN Zero-Day, FortiSandbox and cPanel flaws exploited in attacks

Cisco on Monday told customers about a new SD-WAN product flaw used in attacks. The flaw, called CVE-2026-20262, is a...
Read More
ALERT  Cisco SD-WAN Zero-Day, FortiSandbox and cPanel flaws exploited in attacks

“Panthalassa” builds floating AI data centers powered by ocean waves

Every American data center story these days follows almost the same pattern. Someone has the chips, someone has the cash,...
Read More
“Panthalassa” builds floating AI data centers powered by ocean waves

Critical Wazuh Vuln Enables Alert Tampering and Evidence Deletion

A critical security flaw has affected the open-source security community. Recently, complete details and working exploit code were shared online....
Read More
Critical Wazuh Vuln Enables Alert Tampering and Evidence Deletion

Vulnerability Summary:

The critical remote code execution (RCE) vulnerability has been identified in Microsoft WSUS. The flaw stems from deserialization of untrusted data in WSUS reporting web services and allows an unauthenticated attacker to send specially crafted requests to a WSUS server (with the WSUS Server Role enabled) and execute arbitrary code as NT AUTHORITY\SYSTEM. The issue has been assigned a CVSS 3.x score of 9.8 (per NVD/NIST) and is listed in CISA’s Known Exploited Vulnerabilities catalog.

Affected Systems & Scope:

Only Windows servers with the WSUS role enabled are affected. Servers without WSUS aren’t vulnerable. Commonly exposed ports for WSUS are TCP 8530 (HTTP) and TCP 8531 (HTTPS); servers on these ports may be at higher risk.

All Windows Server versions with WSUS enabled are vulnerable unless patched. Vendors provide specific KBs for each OS version. Although WSUS usually operates internally, the risk remains high if a WSUS server is accessible.

Impact:

• Successful exploitation grants the attacker remote code execution with SYSTEM privileges on the WSUS server. This means full compromise of that server.

If compromised, the attacker could use the WSUS server to move laterally, distribute harmful updates, gain higher privileges, or deploy additional payloads.

As WSUS is a patch-distribution infrastructure, compromise may undermine trust in the update process or allow poisoning of updates.

IOCs:

Source: BGD e-GOV CIRT

Recomendations:

The Cyber Incident Response Team (CIRT) has advised immediate actions to address the critical WSUS vulnerability. Within 24–72 hours, inventory all WSUS servers to assess their exposure, checking if they are accessible internally or externally and if TCP ports 8530 and 8531 are open. Administrators should install the out-of-band security update from Microsoft dated 23 October 2025 and reboot the servers to apply it. If patching cannot be done right away, temporarily disable the WSUS Server Role or block traffic to ports 8530 and 8531 at the host and network firewall to avoid exploitation.

 

Check Also

Rokarolla

New Rokarolla Android malware hits 217 banking and crypto apps

A new Android banking trojan called Rokarolla is hitting 217 banking and cryptocurrency apps with …