Critical Windows Netlogon RCE flaw now exploited in attacks
A critical Remote Code Execution (RCE) vulnerability (CVE-2026-41089) in Windows Netlogon is now being actively exploited in attacks, according to Belgium's national cybersecurity authority, the Centre for Cybersecurity Belgium (CCB). The vulnerability, affecting supported Windows Server versions, allows unprivileged attackers to gain remote code execution. Organizations are urged to immediately patch vulnerable systems to mitigate the risk.
The vulnerability, discovered by Microsoft's WARP team, is a stack-based buffer overflow within the Netlogon service. It allows an attacker to send a specially crafted network request to a domain controller, potentially leading to code execution without prior authentication or access. This poses a significant threat to organizations relying on Windows domain networks, particularly those with outdated systems. The CCB’s warning highlights the urgency of patching, emphasizing the active exploitation of the flaw in the wild. Microsoft’s response, while acknowledging the issue, recommends following established guidance and installing the latest security updates, mirroring the advice given by the CCB.