2026-007: Critical Vulnerability in Windows Netlogon

Imported from official source

Advisory

Cybersecurity Classified by Officially

Critical Vulnerability in Windows Netlogon

  • 10/06/2026 --- v1.0 -- Initial publication
  • On 12 May 2026, Microsoft published a security advisory addressing a critical vulnerability affecting Windows Server when acting as a domain controller [1]. This vulnerability allows an unauthenticated attacker to execute arbitrary code over a network.

    According to The Centre for Cybersecurity Belgium (CCB), this vulnerability is currently exploited by threat actors [2]. It is strongly recommended updating affected Windows servers as soon as possible.

    The vulnerability CVE-2026-41089, with the CVSS score of 9.8, is a stack-based buffer overflow in Windows Netlogon [1].

    An unauthenticated attacker could execute arbitrary code with SYSTEM privileges on targeted domain controllers by sending specially crafted packets [3].

    The following Windows Server versions are affected:

  • Windows Server 2016 (prior to 10.0.14393.9140)
  • Windows Server 2019 (prior to 10.0.17763.8755)
  • Windows Server 2022 (prior to 10.0.20348.5074)
  • Windows Server 2022 23H2 (prior to 10.0.25398.2330)
  • Windows Server 2025 (prior to 10.0.26100.32772)
  • Additional information is available in the vendor’s advisory [1].

    It is recommended updating affected Windows Server asset as soon as possible.

    This is an extract. The publication continues at the source.

    Read the original at the source: https://cert.europa.eu/publications/security-advisories/2026-007/

    Officially imported this from CERT-EU’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

    Provenance

    Organization
    CERT-EU — imported from official source
    Official source
    https://www.cert.europa.eu/publications/security-advisories-rss RSS
    Imported
    September 15, 2026 20:57
    Versions
    1 recorded
    Identity
    security-advisories-10944

    Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.