{"id":74146,"date":"2025-10-26T21:03:23","date_gmt":"2025-10-26T19:03:23","guid":{"rendered":"https:\/\/digitrendz.blog\/?p=74146"},"modified":"2025-10-26T21:04:41","modified_gmt":"2025-10-26T19:04:41","slug":"microsoft-issues-critical-windows-update-amid-active-attacks","status":"publish","type":"post","link":"https:\/\/digitrendz.blog\/z\/newswire\/technology\/74146\/microsoft-issues-critical-windows-update-amid-active-attacks\/","title":{"rendered":"Microsoft Issues Critical Windows Update Amid Active Attacks"},"content":{"rendered":"<details class=\"wp-block-details ticss-586932b6 is-layout-flow wp-block-details-is-layout-flow\"><summary>\u25bc Summary<\/summary>\n<p class=\"ticss-0c48f427 has-small-font-size wp-block-paragraph\">&#8211; Microsoft has released an emergency security update for a critical vulnerability (CVE-2025-59287) in Windows Server Update Service that allows remote code execution.<br>&#8211; The Cybersecurity and Infrastructure Security Agency (CISA) warns that attacks exploiting this vulnerability are already underway and has given federal agencies two weeks to apply the fix.<br>&#8211; Only Windows servers with the WSUS server role enabled are vulnerable, as it is not enabled by default on Windows servers.<br>&#8211; CISA recommends identifying vulnerable servers, applying the October 23, 2025 security update, and rebooting WSUS servers after installation to complete mitigation.<br>&#8211; If immediate updating is not possible, CISA advises disabling the WSUS server role and blocking inbound traffic to ports 8530 and 8531 at the host firewall as a temporary workaround.<br><\/p>\n<\/details>\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n<p class=\"has-drop-cap wp-block-paragraph\"><strong><mark style=\"background-color:rgba(0, 0, 0, 0);color:#f34c3e\" class=\"has-inline-color\">M<\/mark>icrosoft has released an urgent security update for <a href=\"https:\/\/digitrendz.blog\/z\/entity\/windows-server\/\" class=\"acp-entity-link\" data-entity-id=\"54129\" data-entity-category=\"Technology\" title=\"Learn more about Windows Server\" target=\"_blank\" rel=\"noopener noreferrer\">Windows Server<\/a> to address a <a href=\"https:\/\/digitrendz.blog\/z\/tech-news\/226583\/jetbrains-patches-critical-unauthenticated-rce-flaw-in-teamcity\/\" class=\"acp-article-link\" data-article-id=\"226583\" title=\"JetBrains patches critical unauthenticated RCE flaw in TeamCity\" target=\"_blank\" rel=\"noopener noreferrer\">critical vulnerability<\/a>, designated <a href=\"https:\/\/digitrendz.blog\/z\/entity\/cve-2025-59287\/\" class=\"acp-entity-link\" data-entity-id=\"142394\" data-entity-category=\"WORK_OF_ART\" title=\"Learn more about CVE-2025-59287\" target=\"_blank\" rel=\"noopener noreferrer\">CVE-2025-59287<\/a>, which is already being actively exploited.<\/strong> The <a href=\"https:\/\/digitrendz.blog\/z\/tech-news\/235982\/cisa-orders-3-day-patch-for-ray-ai-flaw-under-active-attack\/\" class=\"acp-article-link\" data-article-id=\"235982\" title=\"CISA orders 3-day patch for Ray AI flaw under active attack\" target=\"_blank\" rel=\"noopener noreferrer\">Cybersecurity and Infrastructure Security Agency<\/a> (<a href=\"https:\/\/digitrendz.blog\/z\/entity\/cisa\/\" class=\"acp-entity-link\" data-entity-id=\"21358\" data-entity-category=\"Organization\" title=\"Learn more about CISA\" target=\"_blank\" rel=\"noopener noreferrer\">CISA<\/a>) has confirmed that attacks are in progress, making immediate action essential for all organizations using affected systems.<\/p>\n\n<p class=\"wp-block-paragraph\">This development follows closely on the heels of a recent emergency security update from <a href=\"https:\/\/digitrendz.blog\/z\/entity\/google\/\" class=\"acp-entity-link\" data-entity-id=\"50\" data-entity-category=\"Organization\" title=\"Learn more about Google\" target=\"_blank\" rel=\"noopener noreferrer\">Google<\/a> for Chrome, highlighting a period of heightened cybersecurity alerts. CISA had already warned federal agencies to update <a href=\"https:\/\/digitrendz.blog\/z\/trending-news\/221654\/windows-11-july-2026-update-fixes-570-flaws-as-ai-reshapes-patch-tuesday\/\" class=\"acp-article-link\" data-article-id=\"221654\" title=\"Windows 11 July 2026 update fixes 570 flaws as AI reshapes Patch Tuesday\" target=\"_blank\" rel=\"noopener noreferrer\">Windows<\/a> Server, <a href=\"https:\/\/digitrendz.blog\/z\/entity\/windows-10\/\" class=\"acp-entity-link\" data-entity-id=\"7150\" data-entity-category=\"Technology\" title=\"Learn more about Windows 10\" target=\"_blank\" rel=\"noopener noreferrer\">Windows 10<\/a>, and <a href=\"https:\/\/digitrendz.blog\/z\/entity\/windows-11\/\" class=\"acp-entity-link\" data-entity-id=\"7148\" data-entity-category=\"Technology\" title=\"Learn more about Windows 11\" target=\"_blank\" rel=\"noopener noreferrer\">Windows 11<\/a> systems less than a week ago due to ongoing server message block attacks. Now, the agency has verified that a new wave of attacks is exploiting a flaw in the <a href=\"https:\/\/digitrendz.blog\/z\/entity\/windows-server-update-service\/\" class=\"acp-entity-link\" data-entity-id=\"142392\" data-entity-category=\"product\" title=\"Learn more about Windows Server Update Service\" target=\"_blank\" rel=\"noopener noreferrer\">Windows Server Update Service<\/a> (WSUS). This vulnerability could allow an unauthenticated attacker to remotely execute malicious code with system-level privileges over the network.<\/p>\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/digitrendz.blog\/z\/entity\/microsoft\/\" class=\"acp-entity-link\" data-entity-id=\"251\" data-entity-category=\"Organization\" title=\"Learn more about Microsoft\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft<\/a> clarified that the <strong><a href=\"https:\/\/digitrendz.blog\/z\/entity\/wsus-server-role\/\" class=\"acp-entity-link\" data-entity-id=\"142904\" data-entity-category=\"product\" title=\"Learn more about WSUS Server Role\" target=\"_blank\" rel=\"noopener noreferrer\">WSUS Server Role<\/a> is not enabled by default on <a href=\"https:\/\/digitrendz.blog\/z\/entity\/windows-servers\/\" class=\"acp-entity-link\" data-entity-id=\"143027\" data-entity-category=\"product\" title=\"Learn more about Windows servers\" target=\"_blank\" rel=\"noopener noreferrer\">Windows servers<\/a><\/strong>. Only servers with this specific role activated are vulnerable if the patch is not installed. The company stated, \u201cWindows servers that do not have the WSUS server role enabled are not vulnerable to this vulnerability. If the WSUS server role is enabled, the server will become vulnerable if the fix is not installed before the WSUS server role is enabled.\u201d<\/p>\n\n<p class=\"wp-block-paragraph\">In response, CISA issued a binding operational directive, giving certain <a href=\"https:\/\/digitrendz.blog\/z\/topic\/federal-agencies\/\" class=\"acp-topic-link\" data-topic-id=\"85541\" title=\"Explore: federal agencies\" target=\"_blank\" rel=\"noopener noreferrer\">federal agencies<\/a> a strict two-week deadline to apply the fix. The agency strongly urges all organizations to follow Microsoft\u2019s updated guidance for the WSUS <a href=\"https:\/\/digitrendz.blog\/z\/trending-news\/238086\/cisa-orders-federal-patch-for-exploited-trueconf-server-bugs\/\" class=\"acp-article-link\" data-article-id=\"238086\" title=\"CISA orders federal patch for exploited TrueConf Server bugs\" target=\"_blank\" rel=\"noopener noreferrer\">Remote Code Execution<\/a> Vulnerability to prevent potential system compromise.<\/p>\n\n<p class=\"wp-block-paragraph\">CISA recommends a specific course of action for system administrators:<\/p>\n\n<p class=\"wp-block-paragraph\">First, identify any servers currently configured in a way that makes them vulnerable to exploitation.<\/p>\n\n<p class=\"wp-block-paragraph\">Next, apply the out-of-band security update that Microsoft released on October 23, 2025, to all identified servers.<\/p>\n\n<p class=\"wp-block-paragraph\">After installing the update, a reboot of the WSUS servers is required to complete the mitigation process.<\/p>\n\n<p class=\"wp-block-paragraph\">For organizations unable to apply the update immediately, it is advised to disable the WSUS server role entirely. Additionally, blocking inbound traffic to ports 8530 and 8531 at the host firewall can serve as a temporary protective measure.<\/p>\n\n<p class=\"wp-block-paragraph\">Microsoft emphasized that administrators should not reverse these workarounds until after the official update has been successfully installed. While addressing this issue may require immediate attention, even outside of normal business hours, taking these steps is crucial for maintaining network security.<\/p>\n\n<p class=\"wp-block-paragraph\"><em>(Source: <a href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/10\/25\/act-now---microsoft-issues-emergency-windows-update-as-attacks-begin\/\" target=\"_blank\" rel=\"noreferrer noopener\">Forbes<\/a>)<\/em><\/p>","protected":false},"excerpt":{"rendered":"<p>Microsoft has issued an urgent security update for Windows Server to patch a critical vulnerability (CVE-2025-59287) that is actively being exploited, allowing remote code execution with system privileges. Only servers with the WSUS Server Role enabled are vulnerable, and CISA has mandated federa&#8230;<\/p>\n","protected":false},"author":1,"featured_media":74145,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_themeisle_gutenberg_block_has_review":false,"cybocfi_hide_featured_image":"","footnotes":""},"categories":[6579,3297,3327,3254],"tags":[107045,58149,13998,44369,107046],"entities":[14622,107049,107589,1110,817,904,7305,4555,4554,37157,107047,107588,107473],"class_list":["post-74146","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-bigtech-companies","category-cybersecurity","category-newswire","category-technology","tag-cve-2025-59287","tag-cybersecurity-alert","tag-remote-code-execution","tag-windows-server-update","tag-wsus-vulnerability","entity-cisa","entity-cve-2025-59287","entity-cybersecurtity-and-infrastructure-security-agency","entity-forbes","entity-google","entity-microsoft","entity-paypal","entity-windows-10","entity-windows-11","entity-windows-server","entity-windows-server-update-service","entity-windows-servers","entity-wsus-server-role"],"_links":{"self":[{"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/posts\/74146","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/comments?post=74146"}],"version-history":[{"count":0,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/posts\/74146\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/media\/74145"}],"wp:attachment":[{"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/media?parent=74146"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/categories?post=74146"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/tags?post=74146"},{"taxonomy":"entity","embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/entities?post=74146"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}