CVE-2026-41089: A Pre-Auth Netlogon RCE Lands on Your Domain Controllers
A CVSS 9.8 stack-based buffer overflow in Windows Netlogon gives an unauthenticated attacker code execution on a domain controller. Microsoft called exploitation ‘less likely.’ Belgium’s CCB says it’s happening now.