WSUS — Cyber Threats, Attacks & Incidents

Threat entity extracted from intelligence sources

Frequency
20
occurrences
First Seen
October 27, 2025
Last Seen
July 30, 2026

WSUS (Windows Server Update Services) is Microsoft's centralized platform for managing and distributing updates within an enterprise.

Overview

WSUS (Windows Server Update Services) is Microsoft's centralized platform for managing and distributing updates within an enterprise. In late 2025, it became a notable attack surface as threat actors leveraged a remote code execution vulnerability to deliver ShadowPad malware, enabling broad system access. Its central role in patch management makes WSUS a high-value target for widespread compromise across networks.

Related Threat Clusters

Recent Intelligence Reports

  • The July 2026 Security Update Review — www.zerodayinitiative.com · July 30, 2026
  • The July 2026 Security Update Review — Thezdi · July 14, 2026
  • CISA Adds CVE-2021 — Webpronews · November 30, 2025
  • SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 73 — Securityaffairs.Co · November 30, 2025
  • Attackers deliver ShadowPad via newly patched WSUS RCE bug — Securityaffairs.Co · November 24, 2025
  • ShadowPad Malware Actively Exploits WSUS Vulnerability for Full System Access — Thehackernews · November 24, 2025
  • Chinese Hackers Exploiting WSUS Remote Code Execution Vulnerability to Deploy ShadowPad Malware — Cybersecuritynews · November 21, 2025
  • Chinese Hackers Exploiting WSUS Remote Code Execution Vulnerability to Deploy ... — Gbhackers · November 21, 2025

CVSS v3.1 Breakdown