Netlogon Exploit Puts Active Directory at Risk

An unpatched domain controller is not just a server risk here. CVE-2026-41089 lets an unauthenticated attacker reach the Netlogon service before trust is established and turn that into code execution on the controller, which can open the whole Active Directory domain to takeover. FortiGuard says the flaw, patched by Microsoft in May 2026, is now being actively exploited in the wild. The bug is a stack-based buffer overflow in the Netlogon RPC interface, and the affected targets include unpatched domain controllers and domain-joined systems. The practical danger is not a single-machine compromise. A successful hit can lead to account creation, privilege changes, and Group Policy abuse across the domain, so patching the controller is really about protecting the identity system it runs.

Part of the PlainSec briefing for 2026-06-11

Sources