A critical remote code execution vulnerability in Windows Netlogon (CVE-2026-41089) is being actively exploited in the wild. The Centre for Cybersecurity Belgium (CCB) issued an urgent warning about the flaw, which was originally disclosed by Microsoft on May 12, 2026.

The vulnerability is a stack-based buffer overflow that allows attackers to execute arbitrary code by sending a specially crafted network request to a Windows server acting as a domain controller. Successful exploitation can lead to full Active Directory compromise, including credential access, directory reconnaissance, and lateral movement across the entire domain environment. Any organization running unpatched Windows domain controllers is at immediate risk.

Source

Reported by Help Net Security and Penligent.

Commentary

Netlogon vulnerabilities are the stuff of domain admin nightmares — we’ve been here before with Zerologon (CVE-2020-1472), and the pattern repeats. When attackers can remotely compromise a domain controller, the entire AD forest is at risk. The fact that this is already being exploited in the wild just three weeks after disclosure means the window for patching is closing fast.

If you run Windows domain controllers and haven’t applied the May 2026 patches yet, stop reading and go patch. This isn’t the kind of vuln you can mitigate with compensating controls while you plan a maintenance window — the blast radius is too severe. Every day unpatched is a day you’re betting your entire AD environment on attackers not finding you.

By Allan