Windows Netlogon RCE Reported Under Active Exploitation — Patch Now
Want more insights like this?
Belgium's Centre for Cybersecurity says a critical Windows Netlogon flaw (CVE-2026-41089, CVSS 9.8) is being actively exploited in the wild, putting unpatched domain controllers at serious risk. Microsoft says it has found no evidence for the claim and didn't rate the bug likely to be exploited — but it still tells customers to patch.
The flaw is a stack-based buffer overflow. Attackers need only network access to trigger it — no authentication, no user interaction — allowing full SYSTEM-level code execution and potential domain takeover.
Microsoft patched it on May 12, alongside 15 other critical flaws. Every supported Server branch from 2016 to 2025 has a fixed build; Server 2012 and 2012 R2 are affected too and need Extended Security Updates, and Acros Security has micropatches for unsupported systems.
The CCB says patch as quickly as possible. Prioritise domain controllers, tighten network segmentation, and monitor for Netlogon crashes, anomalous authentication and unexpected admin account creation.
Source: Cybersecurity News