CyberzSOC

Publication detail
← Back to advisories & guidance

2026-007: Critical Vulnerability in Windows Netlogon ↗ source

June 10, 2026 CERT-EU Advisory

Summary

This vulnerability allows an unauthenticated attacker to execute arbitrary code over a network. According to The Centre for Cybersecurity Belgium (CCB), this vulnerability is currently exploited by threat actors [2]. It is strongly recommended updating affected Windows servers as ThevulnerabilityCVE-2026-41089,withtheCVSSscoreof9.8,isastack-basedbufferoverflow An unauthenticated attacker could execute arbitrary code with SYSTEM privileges on targeted domain controllers by sending specially crafted packets [3]. The following Windows Server versions are affected: Additional information is available in the vendor’s advisory [1]. It is recommended updating affected Windows Server asset as soon as possible.

News Coverage

DateSourceArticle
2026-06-09 FortiGuard Labs Threat Signal Windows Netlogon Remote Code Execution Vulnerability CVE-2026-41089
2026-06-08 Check Point Research 8th June – Threat Intelligence Report CVE-2026-41089

Articles from the monitored vendor research blogs and security news feeds that reference a CVE cited in this publication, or name the campaign it covers. Coverage begins when feed monitoring started; earlier articles are not indexed.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2026-41089 9.8 Critical Microsoft Windows Server 2012 Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network.

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.