← CVE catalog

CVE-2025-59287

Critical CVSS 9.8 Known exploited

Published 2025-10-14 · last changed 2026-06-17 · added to CISA KEV 2025-10-24

This one is being exploited in the wild.

CISA added CVE-2025-59287 to the Known Exploited Vulnerabilities catalog on 2025-10-24. Federal agencies are required to remediate it on a deadline. If you have affected machines, this is the class of finding that moves ahead of the rest of the queue.

The fix

Microsoft fixes this in updatesKB5070887, KB5070886, KB5070882, KB5070883, KB5070884, KB5070892, KB5070879, KB5070881, KB5070893. The fixed build differs per Windows version, so the row that matters is the one matching the machine you are looking at.

Windows version Fixed in build Update Released
Windows Server 2012 6.2.9200.25728 KB5070887 2026-09-19
Windows Server 2012 R2 6.3.9600.22826 KB5070886 2026-09-19
Windows Server 2012 R2 (Server Core installation) 6.3.9600.22826 KB5070886 2026-09-19
Windows Server 2012 (Server Core installation) 6.2.9200.25728 KB5070887 2026-09-19
Windows Server 2016 10.0.14393.8524 KB5070882 2026-09-19
Windows Server 2016 (Server Core installation) 10.0.14393.8524 KB5070882 2026-09-19
Windows Server 2019 10.0.17763.7922 KB5070883 2026-09-19
Windows Server 2019 (Server Core installation) 10.0.17763.7922 KB5070883 2026-09-19
Windows Server 2022 10.0.20348.4297 KB5070884, KB5070892 2026-09-19
Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.1916 KB5070879 2026-09-19
Windows Server 2022 (Server Core installation) 10.0.20348.4297 KB5070884, KB5070892 2026-09-19
Windows Server 2025 10.0.26100.6905 KB5070881, KB5070893 2026-09-19
Windows Server 2025 (Server Core installation) 10.0.26100.6905 KB5070881, KB5070893 2026-09-19

Having the KB is not the same as knowing whether a machine has it. Windows updates supersede each other, so the update you installed often covers a fix that shipped in an earlier one. Paste your build into the patch checker and it walks that chain for you.

What it is

Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over a network.

Sources

CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H