Skip to main content

Port Details

Port
8530
Transport
TCP
Service
WSUS
IANA service name
unassigned
Range
User port (1024-49151)
Related ports
853180443

Security Exposure

CVE-2025-59287 is a deserialization flaw in WSUS that allows remote code execution, and CISA added it to the Known Exploited Vulnerabilities catalog on October 24, 2025. CISA's alert warns that an unauthenticated actor can reach SYSTEM-level code execution and tells organizations to prioritize servers with the WSUS role enabled and ports 8530/8531 open. Microsoft also notes that without TLS, an attacker can modify update information in transit between WSUS servers and clients.

Hardening

  • +Apply Microsoft's security updates for WSUS, including the October 23, 2025 out-of-band update for CVE-2025-59287, and reboot afterward.
  • +Allow 8530 and 8531 only from managed clients and downstream WSUS servers, and never from the internet.
  • +Configure TLS on 8531 and point clients at the HTTPS URL so update metadata is protected.
  • +If patching is delayed, disable the WSUS role or block inbound 8530/8531 at the host firewall as CISA describes.

Monitoring

Follow CISA's guidance for CVE-2025-59287 and vet child processes with SYSTEM-level permissions spawned by wsusservice.exe or w3wp.exe. Alert on connections to 8530/8531 from addresses that are not managed clients or downstream servers, and track which servers have the WSUS role installed.

WSUS Vulnerabilities

1 CVEs
CVETitleVendorCVSSEPSSKEVPublished
CVE-2025-59287
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
Microsoft9.8100.0%KEV2025-10-14

Tools for Auditing and Monitoring WSUS

SIEM Tools

Microsoft enterprise EDR covering Windows, macOS, Linux, and mobile from one console.

LicenseProprietary
PlatformWindows, macOS, Linux, iOS, Android, Web

Nmap

Free / Commercial
Penetration Testing Tools

Network discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.

LicenseNPSL-0.95 (Nmap Public Source License, not OSI-approved)
PlatformLinux, macOS, Windows

Nessus

Commercial
Vulnerability Scanning

Tenable vulnerability scanner with the industry’s largest plugin library; time-limited free Essentials license.

LicenseProprietary
PlatformLinux, Windows, Web

Frequently Asked Questions

What is port 8530 used for?→

It is the default HTTP port for Windows Server Update Services. Clients and downstream WSUS servers connect to it to download updates, and 8531 carries HTTPS.

Should I block port 8530?→

Block it from the internet and from any network that does not contain WSUS clients. CISA lists blocking inbound 8530/8531 at the host firewall as a temporary mitigation for CVE-2025-59287 until the update is installed.

What is the difference between 8530 and 8531?→

Microsoft configures 8530 for HTTP update payloads and 8531 for HTTPS update metadata. If the ports change, the HTTP port must be exactly one less than the HTTPS port.

Which vulnerabilities affect the service on port 8530?→

This database lists 1 CVE related to WSUS, 1 of them confirmed as exploited by CISA. Examples: CVE-2025-59287.

Sources

Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 8530 is not guaranteed to be WSUS. Exploited-in-the-wild data from the CISA KEV catalog (CC0).