2026-007: Critical Vulnerability in Windows Netlogon
Actively exploited CVSS 9.8 Windows Netlogon flaw lets unauthenticated attackers execute code with SYSTEM privileges on domain controllers.
Microsoft's May 2026 advisory describes CVE-2026-41089, a stack-based buffer overflow in Windows Netlogon (CVSS 9.8) that allows unauthenticated remote code execution with SYSTEM privileges on domain controllers via specially crafted packets. The Centre for Cybersecurity Belgium reports the flaw is currently being exploited by threat actors. All Windows Server versions from 2012 through 2025 acting as domain controllers are affected and require the May updates.
- Unauthenticated RCE with SYSTEM privileges on targeted domain controllers
- Actively exploited in the wild according to Belgium's CCB
- Affects Windows Server 2012 through 2025 domain controllers
- Stack-based buffer overflow triggered by crafted network packets
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-41089 | Unauthenticated Stack Buffer Overflow RCE in Windows Server Netlogon (CVE-2026-41089) CVE-2026-41089 is a stack-based buffer overflow (CWE-121) in the Netlogon service of Windows Server. An unauthenticated remote attacker can trigger it by sending crafted network requests to the Netlogon RPC interface, with no privileges or user interaction required per the CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N). Successful exploitation yields remote code execution with high confidentiality, integrity, and availability impact; on domain controllers, where Netlogon runs by default, this typically means compromise of a critical authentication server and risk of broader domain compromise. All organizations running the affected Windows Server versions (2012, 2016, 2019, 2022, 2022 23H2, and 2025) are in scope, with Active Directory domain controllers the highest-value targets. Microsoft fixed the flaw in its May 2026 Patch Tuesday release (138 vulnerabilities patched), and security reporting indicates the RCE is being exploited with domain controllers at risk; a public proof-of-concept is available, it is not yet in CISA KEV, and EPSS assigns a 79.6% probability of exploitation within 30 days. Do: Apply Microsoft's May 2026 cumulative security updates (or later) to all listed Windows Server versions, prioritizing domain controllers. Until patched, restrict unauthenticated network access to domain controllers' Netlogon/RPC interfaces (e.g., limit TCP 135 and dynamic RPC ports to trusted hosts) and monitor for anomalous Netlogon activity. The flaw is not yet in CISA KEV, but treat it as actively exploited given current reporting and the available public PoC. | 9.8 | 80% | PoC ×3 |
| massmillions of systems (Netlogon runs by default on every Windows Server Active Directory domain controller and most domain-joined servers) |
Full article193 words · extracted from cert.europa.eu · click to collapse
Release Date: 10-06-2026 06:47:08
History:
- 10/06/2026 --- v1.0 -- Initial publication
Summary
On 12 May 2026, Microsoft published a security advisory addressing a critical vulnerability affecting Windows Server when acting as a domain controller [1]. This vulnerability allows an unauthenticated attacker to execute arbitrary code over a network.
According to The Centre for Cybersecurity Belgium (CCB), this vulnerability is currently exploited by threat actors [2]. It is strongly recommended updating affected Windows servers as soon as possible.
Technical Details
The vulnerability CVE-2026-41089, with the CVSS score of 9.8, is a stack-based buffer overflow in Windows Netlogon [1].
An unauthenticated attacker could execute arbitrary code with SYSTEM privileges on targeted domain controllers by sending specially crafted packets [3].
Affected Products
The following Windows Server versions are affected:
- Windows Server 2012 / 2012 R2
- Windows Server 2016 (prior to 10.0.14393.9140)
- Windows Server 2019 (prior to 10.0.17763.8755)
- Windows Server 2022 (prior to 10.0.20348.5074)
- Windows Server 2022 23H2 (prior to 10.0.25398.2330)
- Windows Server 2025 (prior to 10.0.26100.32772)
Additional information is available in the vendor’s advisory [1].
Recommendations
It is recommended updating affected Windows Server asset as soon as possible.
References
[1] https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41089
Text extracted automatically; images, tables and formatting may be missing. Original: https://cert.europa.eu/publications/security-advisories/2026-007/