Critical Windows Netlogon vulnerability reported under exploitation
A critical Windows Netlogon remote code execution vulnerability, tracked as CVE-2026-41089 with a CVSS score of 9.8, is reported to be exploited in attacks. Microsoft patched the flaw on 12 May 2026, describing it as a stack-based buffer overflow in Netlogon, a core service for authentication in domain-based networks. According to Microsoft's advisory, an unauthenticated attacker could send a specially crafted network request to a domain controller and potentially achieve code execution without prior access or credentials. The Centre for Cybersecurity Belgium warned on 29 May 2026 that the flaw was being actively exploited and urged administrators to patch immediately. No technical details of the observed exploitation have been published, and Microsoft has not updated its advisory to list the vulnerability as exploited.
What this means for your organisation
A domain controller is the trust anchor of a Windows estate. Code execution there without credentials effectively means control over identities, access and onward movement in the network, and it is the kind of entry point that often precedes a ransomware event. Since the fix has been available since May, the real question is how quickly the organisation actually gets updates installed on its most critical servers.
Berigo recommends
- Confirm that the May updates are genuinely installed on every domain controller.
- Restrict who can reach Netlogon over the network and separate administrative zones from client networks.
- Review domain controller logs for unexpected authentication patterns and service failures.
- Ensure the incident response plan covers a compromised domain controller, including identity service recovery.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch