ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz1

Windows Netlogon RCE exploited, domain controllers at risk (CVE-2026-41089)

criticalVulnerability exploited in the wildimportance 60CVE-2026-41089

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-41089
Unauthenticated Stack Buffer Overflow RCE in Windows Server Netlogon (CVE-2026-41089)

CVE-2026-41089 is a stack-based buffer overflow (CWE-121) in the Netlogon service of Windows Server. An unauthenticated remote attacker can trigger it by sending crafted network requests to the Netlogon RPC interface, with no privileges or user interaction required per the CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N). Successful exploitation yields remote code execution with high confidentiality, integrity, and availability impact; on domain controllers, where Netlogon runs by default, this typically means compromise of a critical authentication server and risk of broader domain compromise. All organizations running the affected Windows Server versions (2012, 2016, 2019, 2022, 2022 23H2, and 2025) are in scope, with Active Directory domain controllers the highest-value targets. Microsoft fixed the flaw in its May 2026 Patch Tuesday release (138 vulnerabilities patched), and security reporting indicates the RCE is being exploited with domain controllers at risk; a public proof-of-concept is available, it is not yet in CISA KEV, and EPSS assigns a 79.6% probability of exploitation within 30 days.

Do: Apply Microsoft's May 2026 cumulative security updates (or later) to all listed Windows Server versions, prioritizing domain controllers. Until patched, restrict unauthenticated network access to domain controllers' Netlogon/RPC interfaces (e.g., limit TCP 135 and dynamic RPC ports to trusted hosts) and monitor for anomalous Netlogon activity. The flaw is not yet in CISA KEV, but treat it as actively exploited given current reporting and the available public PoC.

9.880% PoC ×3
  • microsoft Windows Server 2012
  • microsoft Windows Server 2016
  • microsoft Windows Server 2019
  • +3 more
massmillions of systems (Netlogon runs by default on every Windows Server Active Directory domain controller and most domain-joined servers)
Full article375 words · extracted from helpnetsecurity.com · click to collapse

CVE-2026-41089, a critical Windows Netlogon RCE flaw that allows remote code execution, is now actively exploited in the wild, the Centre for Cybersecurity Belgium (CCB) warned on Friday.

Windows Netlogon RCE exploited CVE-2026-41089

About CVE-2026-41089

CVE-2026-41089 is a stack-based buffer overflow vulnerability in Windows Netlogon, the service and protocol that handles authentication and security within a Windows domain environment.

The flaw can be exploited by attackers by sending a specially crafted network request to a Windows server that is acting as a domain controller, and may allow them to execute code over a network.

The company disclosed the vulnerability on May 12, 2026, and credited its Windows Attack Research & Protection (WARP) team with reporting it.

At the time, Microsoft deemed the flaw to be “less likely” to be exploited, but AI-enabled adversaries are shrinking the gap between a CVE’s public disclosure and the first observed exploitation by threat actors.

Security researchers and AI companies are, likewise, reverse-engineering patches and publicly sharing their root cause analyses and proof-of-concept exploits.

Unfortunately, CCB has yet to publicly share details about the attacks in progress.
We’ve reached out to CCB with questions about the in-the-wild exploitation and will update this article when we hear back from them.

What to do?

Microsoft issued security patches for CVE-2026-41089 across multiple Windows Server versions in last week’s Patch Tuesday release.

At the time, Jason Kikta, CTO at Automox, advised admins to patch the flaw on all domain controllers in the same maintenance window, while noting that “half-patched forests are not a defensible state for a pre-auth [Domain Controller] bug.”

He also advised security teams to restrict Netlogon traffic at the network layer and review their DC exposure.

“Inside an already-compromised perimeter, CVE-2026-41089 becomes a fast path to forest-wide takeover,” he noted, and outlined events that might point to active exploitation:

  • The Netlogon service unexpectedly crashing or restarting
  • Anomalous Netlogon traffic patterns from non-DC source addresses
  • Authentication failures or domain trust errors immediately after suspicious network activity hits a domain controller.

Acros Security has released micropatches for CVE-2026-41089 for legacy Windows Server versions: Windows Server 2008 R2, Windows Server 2012, and Windows Server 2012 R2.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2026/06/01/windows-netlogon-rce-exploited-cve-2026-41089/