Critical Windows Netlogon flaw (CVE-2026-41089) under active attack; hackers seize domain controllers with no password
Attackers are actively exploiting a critical unauthenticated Netlogon vulnerability (CVE-2026-41089) in Windows Server. A single crafted network request grants SYSTEM-level remote code execution on domain controllers. Belgium's national cyber agency confirmed live exploitation; M
CVE-2026-41089 is a stack buffer overflow in Windows Netlogon, rated CVSS 9.8. Unauthenticated attackers with network access to a domain controller can run code as SYSTEM with no user interaction. Affects Windows Server 2012 R2 through 2025. Patched May 2026; active exploitation confirmed by Belgium's CCB.
Published on
TikTokFacebookYouTubeBlueskyX