Vulnerabilities & Exploits

Netlogon Exploit Puts Active Directory at Risk

An unpatched domain controller is not just a server risk here. CVE-2026-41089 lets an unauthenticated attacker reach the Netlogon service before trust is established and turn that into code execution on the controller, which can open the whole Active Directory domain to takeover.

FortiGuard says the flaw, patched by Microsoft in May 2026, is now being actively exploited in the wild. The bug is a stack-based buffer overflow in the Netlogon RPC interface, and the affected targets include unpatched domain controllers and domain-joined systems.

The practical danger is not a single-machine compromise. A successful hit can lead to account creation, privilege changes, and Group Policy abuse across the domain, so patching the controller is really about protecting the identity system it runs.

2 sources · Jun 10

CVE-2026-41089

NVD KEV

CVSS 9.8 CRITICAL: stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network. EPSS 80% (100th percentile). Microsoft patch: 5087538.

Patch available KB5087538 Download →

Timeline

Sources

Vendor digest: Microsoft

Part of the PlainSec briefing for 2026-06-10

Every edition of this story: Netlogon Exploit Puts Active Directory at Risk

More from today