Critical Windows Netlogon Vulnerability in Attackers’ Crosshairs

https://www.securityweek.com/wp-content/uploads/2023/01/Cybersecurity_News-SecurityWeek.jpg

Threat actors are exploiting a critical-severity Windows Netlogon vulnerability for remote code execution, Centre for Cybersecurity Belgium (CCB) warns.

Tracked as CVE-2026-41089 (CVSS score of 9.8), the security defect was publicly disclosed on May 12, when Microsoft patched it along with 136 other bugs as part of its Patch Tuesday security updates.

According to Redmond’s advisory, the flaw is a stack-based buffer overflow issue that could be exploited via crafted network requests.

Unauthenticated attackers can exploit the security weakness by targeting a Windows server acting as a domain controller, Microsoft’s advisory revealed.

“If successful, this could cause the Netlogon service to improperly handle the request, potentially allowing the attacker to run code on the affected system without needing to sign in or have prior access,” the advisory reads.

Roughly a dozen of the vulnerabilities Microsoft resolved with the May 2026 Patch Tuesdayupdates were flagged as likely to be exploited...

Copyright of this story solely belongs to securityweek.com. To see the full text click HERE