2026-007: Critical Vulnerability in Windows Netlogon

CERT-EU Version 1 original current

Imported from official source

On 12 May 2026, Microsoft published a security advisory addressing a critical vulnerability affecting Windows Server when acting as a domain controller. This vulnerability allows an unauthenticated attacker to execute arbitrary code over a network. According to The Centre for Cybersecurity Belgium (CCB), this vulnerability is currently exploited by threat actors. It is strongly recommended updating affected Windows servers as soon as possible.

This version

Version
1 of 1
Recorded
September 15, 2026 20:57
Change
Initial
Content hash
4772c4af512e5520b35f20e67ca17fe4
All versions
Revision history

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.