Vulnerability record · CVE-2026-41089 · published 12 May 2026
CVE-2026-41089: Windows Netlogon stack buffer overflow allows remote code execution
Microsoft · Windows Server 2012
CVE-2026-41089 is a stack-based buffer overflow (CWE-121) in Windows Netlogon that lets an unauthorized attacker execute code over a network. It carries a CVSS 3.1 score of 9.8 (critical) with a network vector requiring no privileges or user interaction, and it affects multiple Windows Server releases. Because Netlogon is a core domain authentication service, a remotely reachable pre-auth code execution flaw in it is a serious risk to domain controllers.
Description
Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with a network, no-privilege, no-interaction vector against a core Windows domain authentication service, plus a very high EPSS score, makes this a top patching priority.
What it is
CVE-2026-41089 is a stack-based buffer overflow (CWE-121) in Windows Netlogon that lets an unauthorized attacker execute code over a network. It carries a CVSS 3.1 score of 9.8 (critical) with a network vector requiring no privileges or user interaction, and it affects multiple Windows Server releases. Because Netlogon is a core domain authentication service, a remotely reachable pre-auth code execution flaw in it is a serious risk to domain controllers.
Impact
An attacker can run arbitrary code on the target server, which on a domain controller means potential full compromise of the domain. The CVSS confidentiality, integrity and availability impacts are all rated high.
Attack surface
Reached over the network via the Netlogon service (CVSS AV:N); the vector shows no privileges (PR:N) and no user interaction (UI:N), so it is pre-authentication. The record does not specify the exact protocol path or port, only that the attack is network-based.
Exploitation
Not listed in CISA KEV and no ransomware use is documented, but EPSS is very high at 0.796 (99.6th percentile), indicating elevated likelihood of exploitation activity. The only reference is the Microsoft advisory, so no public exploit or in-the-wild confirmation is stated.
What to do
- Apply the Microsoft security update for CVE-2026-41089 to all affected Windows Server versions as the first action.
- Prioritize patching domain controllers, since Netlogon compromise there affects the whole domain.
- Restrict network access to Netlogon/RPC ports from untrusted segments and hosts until patching is complete.
- Monitor Microsoft guidance for any interim workaround if patching cannot be done immediately.
Detection
- Monitor for unexpected crashes or restarts of the Netlogon service and related Windows error reporting on servers.
- Alert on anomalous network traffic to Netlogon/RPC endpoints, especially from hosts that do not normally authenticate.
- Review server and domain controller logs for unusual process creation or code execution following Netlogon activity.
- Track Microsoft advisories and threat intel for exploit indicators specific to this CVE.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41089 | Vendor Advisory |
Track CVE-2026-41089 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-41089), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.