It appears there is some confusion about the recent WSUS vulnerability. There are two deserialization bugs, one in the cookie decryption and the other on the reporting service.
The cookie decryption one can only be used with a key thats in the DB and it’s not static.



