Hackers Exploit Critical Windows Netlogon Vulnerability
TL;DR. Threat actors actively exploit a critical Windows Netlogon vulnerability (CVE-2026-41089) for remote code execution on unpatched servers. - The flaw allows unauthenticated attackers to run code with System privileges on Windows domain controllers. - Microsoft patched the Netlogon security defect on May 12, but attackers are now using it in the wild. - Organizations must immediately apply the patch to prevent server compromise and unauthorized access.
- Threat actors are actively exploiting CVE-2026-41089, a critical Windows Netlogon vulnerability.
- The flaw allows unauthenticated remote code execution with System privileges on Windows domain controllers.
- Microsoft issued a patch for the vulnerability on May 12 but did not flag it for likely exploitation at the time.
- The Centre for Cybersecurity Belgium (CCB) has warned organizations about in-the-wild exploitation.
- Organizations are urged to patch immediately to secure their domain control systems.
Sources
- Critical Windows Netlogon Vulnerability in Attackers’ Crosshairs — securityweek.com
- tomshardware.com — tomshardware.com