Microsoft Issues Emergency Patch for Critical WSUS Vulnerability

Microsoft Issues Emergency Patch for Critical WSUS Vulnerability

Microsoft has released an emergency security patch for a critical vulnerability in Windows Server Update Services (WSUS) that is being actively exploited. The vulnerability, tracked as CVE-2025-59287, allows remote code execution and carries a severity score of 9.8 out of 10.
Oct 24, 2025 CVE: CVE-2025-59287
Critical Vulnerability CVE-2025-59287 in Windows Server Update Services

Critical Vulnerability CVE-2025-59287 in Windows Server Update Services

Microsoft has released an out-of-band security update for a critical vulnerability in Windows Server Update Services (WSUS), tracked as CVE-2025-59287. This flaw allows remote code execution by unauthenticated threat actors, and a new patch is necessary to fully mitigate the issue as the initial patch was incomplete.
Oct 24, 2025 CVE: CVE-2025-59287
Critical WordPress Flaw Allows Admin Control via Service Finder Plugin

Critical WordPress Flaw Allows Admin Control via Service Finder Plugin

A critical vulnerability (CVE-2025-5947) in the Service Finder Bookings plugin for WordPress enables unauthenticated attackers to gain administrative access to affected sites. This flaw underscores the urgent need for prompt patching and highlights ongoing risks associated with insecure plugin design.
Oct 12, 2025 CVE: CVE-2025-5947