Port 8530: Windows Server Update Services (HTTP)
Port 8530 has no IANA assignment; it falls inside the unassigned block 8504 to 8553. Windows Server Update Services (WSUS) uses 8530 by default for HTTP connections from client computers and downstream WSUS servers, paired with 8531 for HTTPS. Microsoft's guidance uses HTTP on 8530 for update payloads and TLS on 8531 for update metadata.
Port Details
Security Exposure
CVE-2025-59287 is a deserialization flaw in WSUS that allows remote code execution, and CISA added it to the Known Exploited Vulnerabilities catalog on October 24, 2025. CISA's alert warns that an unauthenticated actor can reach SYSTEM-level code execution and tells organizations to prioritize servers with the WSUS role enabled and ports 8530/8531 open. Microsoft also notes that without TLS, an attacker can modify update information in transit between WSUS servers and clients.
Hardening
- +Apply Microsoft's security updates for WSUS, including the October 23, 2025 out-of-band update for CVE-2025-59287, and reboot afterward.
- +Allow 8530 and 8531 only from managed clients and downstream WSUS servers, and never from the internet.
- +Configure TLS on 8531 and point clients at the HTTPS URL so update metadata is protected.
- +If patching is delayed, disable the WSUS role or block inbound 8530/8531 at the host firewall as CISA describes.
Monitoring
Follow CISA's guidance for CVE-2025-59287 and vet child processes with SYSTEM-level permissions spawned by wsusservice.exe or w3wp.exe. Alert on connections to 8530/8531 from addresses that are not managed clients or downstream servers, and track which servers have the WSUS role installed.
WSUS Vulnerabilities
1 CVEs| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2025-59287 | Windows Server Update Service (WSUS) Remote Code Execution Vulnerability | Microsoft | 9.8 | 100.0% | KEV | 2025-10-14 |
Tools for Auditing and Monitoring WSUS
Microsoft Defender for Endpoint
CommercialMicrosoft enterprise EDR covering Windows, macOS, Linux, and mobile from one console.
Nmap
Free / CommercialNetwork discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.
Nessus
CommercialTenable vulnerability scanner with the industry’s largest plugin library; time-limited free Essentials license.
Related Tool Categories
Frequently Asked Questions
What is port 8530 used for?→
It is the default HTTP port for Windows Server Update Services. Clients and downstream WSUS servers connect to it to download updates, and 8531 carries HTTPS.
Should I block port 8530?→
Block it from the internet and from any network that does not contain WSUS clients. CISA lists blocking inbound 8530/8531 at the host firewall as a temporary mitigation for CVE-2025-59287 until the update is installed.
What is the difference between 8530 and 8531?→
Microsoft configures 8530 for HTTP update payloads and 8531 for HTTPS update metadata. If the ports change, the HTTP port must be exactly one less than the HTTPS port.
Which vulnerabilities affect the service on port 8530?→
This database lists 1 CVE related to WSUS, 1 of them confirmed as exploited by CISA. Examples: CVE-2025-59287.
Sources
Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 8530 is not guaranteed to be WSUS. Exploited-in-the-wild data from the CISA KEV catalog (CC0).