Windows Server Update Service (WSUS) Tampering Vulnerability

Plan PatchCVSS 7.5CVE-2026-50328Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

An uncaught exception in Windows Server Update Service (WSUS) allows an unauthenticated attacker on the network to perform tampering. An attacker could intercept or modify Windows updates before they are distributed to client machines, potentially injecting malicious content into legitimate patches. This affects Windows Server 2016, 2019, 2022, and 2025 running WSUS, and impacts all downstream Windows systems that receive updates from the compromised WSUS server.

What this means
What could happen
An attacker on your network could tamper with Windows updates delivered through your WSUS server, potentially injecting malicious code into patches that get deployed to all your Windows systems including OT workstations and servers.
Who's at risk
This affects any organization using Windows Server 2016, 2019, 2022, or 2025 as a WSUS server to manage updates for Windows 10 or Windows Server clients. Water authorities and utilities using WSUS to patch their office networks, engineering workstations, and HMI systems need to prioritize this update to prevent attackers from tampering with the software supply chain for their entire Windows environment.
How it could be exploited
An attacker with network access to your WSUS server can send a specially crafted request that triggers an uncaught exception in the service, allowing them to intercept or modify updates before they are distributed to client machines. This could affect any Windows system configured to receive updates from that WSUS server.
Prerequisites
  • Network access to WSUS server (typically port 8530 or 8531)
  • WSUS service running with the vulnerability present
remotely exploitableno authentication requiredlow complexityaffects software supply chain (all patched systems downstream)
Exploitability
Some exploitation risk — EPSS score 1.2%
Affected products (11)
11 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9020
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9020
Windows Server 2019All versionsBuild 10.0.17763.9020
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9020
Windows Server 2022All versionsBuild 10.0.20348.5386
Windows Server 2025 (Server Core installation)All versionsBuild 10.0.26100.33158
Windows Server 2025All versionsBuild 10.0.26100.33158
Windows 10 Version 1607 for 32-bit SystemsAll versionsBuild 10.0.14393.9339
Remediation & Mitigation
0/3
Do now
0/1
WORKAROUNDRestrict network access to WSUS ports (8530 for HTTP, 8531 for HTTPS) to only authorized client machines and administrators using firewall rules
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

Windows Server 2019
HOTFIXApply the July 2026 security update to all WSUS servers (Windows Server 2016 Build 10.0.14393.9339, Windows Server 2019 Build 10.0.17763.9020, Windows Server 2022 Build 10.0.20348.5386, or Windows Server 2025 Build 10.0.26100.33158)
Long-term hardening
0/1
HARDENINGImplement network segmentation to isolate WSUS servers from untrusted network segments
API: /api/v1/advisories/e7e6add8-77cf-4221-b06b-10322d2b1491

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows Server Update Service (WSUS) Tampering Vulnerability | CVSS 7.5 - OTPulse