Security Advisories

Endpoint management insights, Patch Tuesday analysis, and security intelligence from the team at Patchblox.

Security Advisory

CVE-2026-50444: When One Foothold Owns Your Entire Patch Pipeline

CVE-2026-50444 is a Critical WSUS elevation-of-privilege flaw (CVSS 8.8). Microsoft labeled it 'elevation of privilege,' but on a patch-distribution server that means fleet-wide re…

July 15, 2026 · Dave Gayler
WSUSCVE-2026-50444supply chain security
Security Advisory

CVE-2025-59287: When Your Patch Server Becomes the Attack Vector

A CVSS 9.8 remote code execution vulnerability in WSUS turned the patch delivery infrastructure into an enterprise-wide attack surface. The first fix was incomplete. Here's what ha…

October 28, 2025 · Dave Gayler
WSUSCVE-2025-59287supply chain security