Windows Netlogon RCE (CVE-2026-41089): Is It Exploited? Patch Now
A 9.8 CVSS Netlogon RCE in Windows Server domain controllers, patched in May 2026 — now caught in a dispute between Belgium's CCB and Microsoft over active exploitation.

CVE-2026-41089 is a critical, 9.8-severity stack-based buffer overflow in Windows Netlogon that lets an unauthenticated attacker run code on a Windows Server domain controller over the network. Microsoft patched it in the May 2026 Patch Tuesday update, rating exploitation as "less likely" at the time. Belgium's Centre for Cybersecurity (CCB) has since warned that the flaw is now being actively exploited, but Microsoft told reporters it has not seen evidence to back that claim up, while still urging every unpatched domain controller to be updated immediately. Here's what's confirmed, what's disputed, and exactly which update to install.
What is CVE-2026-41089?
CVE-2026-41089, which Microsoft calls the "Windows Netlogon Remote Code Execution Vulnerability," is a stack-based buffer overflow (CWE-121) in the Netlogon Remote Protocol (MS-NRPC), the component Windows Server uses to authenticate computers and users to a domain. According to Microsoft's own advisory, an attacker can send a specially crafted network request to a Windows server that is acting as a domain controller. If the Netlogon service mishandles that request, the attacker can potentially run code on the server without signing in or needing any prior access.
That combination — no authentication, no user interaction, full remote code execution — is what pushes the bug to a maximum-severity CVSS 3.1 base score of 9.8 out of 10, according to both MSRC and the National Vulnerability Database (NVD). The underlying weakness class, a stack buffer overflow, is a decades-old but still dangerous bug pattern; see Wikipedia's overview for how these overflows typically let attackers hijack program execution.
Netlogon itself is the Windows service responsible for setting up the "secure channel" between a domain member and a domain controller, and for processing authentication requests passed over that channel. It's a core piece of plumbing in every Active Directory environment, which is exactly why a remote, unauthenticated code-execution bug in it is treated as one of the most severe vulnerability classes Windows Server can have. Microsoft's own CVE record credits its internal Windows security research team with finding the flaw, meaning it was reported and patched through Microsoft's normal coordinated-disclosure process rather than surfacing first from an outside researcher or an active attack.
Vulnerability details at a glance
| Field | Detail |
|---|---|
| CVE ID | CVE-2026-41089 |
| Microsoft title | Windows Netlogon Remote Code Execution Vulnerability |
| CVSS 3.1 base score | 9.8 (Critical) — AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| Weakness type | CWE-121: Stack-based Buffer Overflow |
| Affected component | Netlogon (MS-NRPC) on Windows Server domain controllers |
| Disclosed | May 12, 2026 (Microsoft's May 2026 Patch Tuesday) |
| Microsoft's exploitability assessment at release | "Exploitation Less Likely"; Microsoft's own "Exploited" flag was set to "No" |
| In CISA's Known Exploited Vulnerabilities catalog? | Not listed as of this writing (checked against CISA's published KEV data) |
Who's affected: Windows Server versions and builds
Netlogon runs on every Windows Server machine configured as a domain controller, and Microsoft's advisory lists the bug as affecting every currently supported release line plus two still under Extended Security Updates (ESU). Ordinary member servers and workstations that aren't acting as domain controllers are not listed as affected.
| Windows Server version | Fixed build | Update KB |
|---|---|---|
| Windows Server 2012 (ESU) | 6.2.9200.26079 | KB5087470 |
| Windows Server 2012 R2 (ESU) | 6.3.9600.23181 | KB5087471 |
| Windows Server 2016 | 10.0.14393.9140 | KB5087537 |
| Windows Server 2019 | 10.0.17763.8755 | KB5087538 |
| Windows Server 2022 | 10.0.20348.5139 | KB5087545 (or hotpatch KB5087424) |
| Windows Server 2022, 23H2 (Server Core) | 10.0.25398.2330 | KB5087541 |
| Windows Server 2025 | 10.0.26100.32860 | KB5087539 (or hotpatch KB5087423) |
Build numbers and KB article numbers above come directly from Microsoft's Security Update Guide entry for CVE-2026-41089. If you're unsure which build a given domain controller is running, compare its reported OS build against the "fixed build" column; anything below that number for its version line is still vulnerable.
The patch: May 2026 Patch Tuesday
Microsoft shipped the fix for CVE-2026-41089 as part of its regular May 2026 Patch Tuesday cumulative updates, released May 12, 2026. There is no standalone, out-of-band patch — the fix is bundled into the monthly cumulative/security updates (and, for Windows Server 2022 and 2025, into the optional hotpatch updates) listed in the table above. All of the updates require a reboot.
At the time of release, Microsoft's own exploitability index rated CVE-2026-41089 as "Exploitation Less Likely," and the "Exploited" field on its advisory was marked "No" — meaning Microsoft had not observed in-the-wild attacks when it shipped the patch. That detail matters for what happened next.
Belgium's CCB says it's now being exploited
Roughly two and a half weeks after Patch Tuesday, Belgium's Centre for Cybersecurity (CCB) updated its advisory tracking the May 2026 Microsoft patches — which originally covered 118 vulnerabilities, 16 of them critical — to add a new warning specific to CVE-2026-41089. The CCB said the Netlogon flaw was now being actively exploited in the wild, could lead to remote code execution, and reiterated its 9.8 CVSS severity. The agency attributed the information to unnamed "trusted partners" and did not publish further technical indicators, a proof-of-concept, or details of specific incidents.
CCB's advisory is available on its own site, though the specific attack details behind the warning have not been independently published. This is the kind of warning worth taking seriously given the target (domain controllers) and the ease of exploitation, but it's also, so far, a claim from one national cybersecurity agency citing undisclosed sources — not something independently corroborated with public evidence, a tracked threat-actor campaign, or an addition to CISA's exploited-vulnerabilities list (more on that below).
Microsoft's response: "No evidence" to support that claim
Asked about CCB's warning, a Microsoft spokesperson said the company does not currently have evidence to support CCB's claim of active exploitation. Microsoft did not walk back the severity of the vulnerability itself — it's still rated critical, 9.8 — and the company continued to recommend that customers "follow CVE-2026-41089 guidance and install the latest security updates" on any systems that remain unpatched.
In other words, as of this writing there are two attributed, conflicting positions, not a confirmed fact: CCB says it has partner intelligence pointing to active exploitation; Microsoft says it hasn't seen evidence of that itself. Neither CCB nor Microsoft has published forensic indicators of compromise, a CVE-linked threat-actor name, or sample attack traffic that would let defenders verify the claim independently. Treat "actively exploited" as CCB's attributed assessment, not an established fact, until one side publishes supporting evidence or a third party (like CISA) corroborates it.
Is CVE-2026-41089 in CISA's Known Exploited Vulnerabilities catalog?
No — not as of this writing. CISA's Known Exploited Vulnerabilities (KEV) catalog, which the agency updates only after it has independently confirmed a vulnerability is being exploited, does not include CVE-2026-41089. The only Netlogon-family entry currently in the catalog is the unrelated, years-old CVE-2020-1472 ("Zerologon"), which was added back in 2021. If CISA adds CVE-2026-41089 to the KEV catalog later, that would be a meaningful, independent signal beyond CCB's warning — worth checking back for, especially if you manage federal systems bound by CISA's remediation deadlines.
- CVE-2026-41089 affects Windows Server 2012 through 2025 when configured as a domain controller — CVSS 9.8, unauthenticated remote code execution.
- Install the May 2026 cumulative update (or later) for your Windows Server version — see the KB table above for exact numbers.
- Do this regardless of whether you believe CCB's exploitation warning or Microsoft's "no evidence" response — the CVSS 9.8 severity alone justifies prioritizing this patch.
- Reboot is required after installing the update.
- CVE-2026-41089 is not (yet) in CISA's KEV catalog, so there's no federal remediation deadline tied to it today — but don't wait for one.
What to do now: patch guidance for admins
Because Netlogon exploitation targets domain controllers specifically, and a compromised DC can mean a compromised domain, treat CVE-2026-41089 as an emergency patch regardless of which side of the CCB/Microsoft dispute turns out to be right.
- Identify every domain controller in your environment, including read-only domain controllers and any DCs running on older, ESU-covered builds (Windows Server 2012/2012 R2).
- Check build numbers against the "fixed build" column above. Anything below the listed build for its OS version is still exploitable.
- Install the matching KB through Windows Update, WSUS, or the Microsoft Update Catalog, and reboot. For Server 2022 and Server 2025, the hotpatch updates (KB5087424 and KB5087423 respectively) are available as a reboot-light alternative within Microsoft's hotpatch program, where enrolled.
- Prioritize internet-facing or otherwise exposed domain controllers first; Netlogon traffic is normally expected only on internal networks, so audit firewall and network segmentation rules that might be exposing DC ports more broadly than intended.
- Don't treat this as a wait-and-see patch. A 9.8 CVSS, no-authentication RCE against domain controllers is exactly the profile that historically turns into mass exploitation once a public proof-of-concept circulates, whether or not CCB's specific claim is eventually confirmed.
If you're unfamiliar with how vulnerabilities like this get discovered, disclosed, and weaponized in the window between patch release and exploitation, Pandromeda's explainer on how zero-day vulnerabilities work and how to stay safe covers the lifecycle in more depth. CVE-2026-41089 is not a zero-day — a patch existed before any exploitation claim surfaced — but the same patch-now logic applies.
Why domain controllers are such high-value targets
Domain controllers host Active Directory, the database that governs authentication for an entire Windows domain — user accounts, group memberships, and trust relationships. An attacker who gains code execution on a DC can typically move laterally to nearly everything else in the environment, which is why vulnerabilities in Netlogon specifically have a track record of becoming the centerpiece of ransomware and espionage intrusions once exploitation tooling becomes available. This isn't the first time a Netlogon bug has driven urgent patch advisories; the 2020 "Zerologon" vulnerability (CVE-2020-1472) remains on CISA's KEV list today, years after disclosure, because it's still found unpatched in the wild. That history is part of why CCB's warning — confirmed or not — is being taken seriously by administrators rather than dismissed outright.
CVE-2026-41089 followed a string of urgent, actively-exploited disclosures this year, including September's Patch Tuesday, which fixed two Windows zero-days already under attack, and an unrelated but similarly critical networking-gear flaw covered in Pandromeda's report on the Cisco Catalyst SD-WAN Manager vulnerability. The pattern across all of these: critical infrastructure components — domain controllers, SD-WAN managers, network edge devices — keep landing at the top of attackers' target lists, and patch delay is consistently the deciding factor in whether a disclosed bug turns into an incident.
It's also worth remembering that CVSS severity and real-world exploitation are two different things. A 9.8 score describes how bad a successful attack could be and how easy it would be to attempt, not whether anyone has actually attempted it yet. That's exactly the gap CCB and Microsoft are currently disagreeing about: both sides agree on the 9.8 severity; they disagree on whether attackers have started using it. Defenders shouldn't need that question resolved before patching — the severity alone is justification enough — but it's a useful distinction to keep straight when reading competing claims about any disclosed vulnerability.
Is this the same bug as "Zerologon"?
No. CVE-2026-41089 is a distinct, newly disclosed vulnerability from CVE-2020-1472, the Netlogon elevation-of-privilege bug nicknamed "Zerologon" that Microsoft patched in August 2020. The two share a component — Netlogon — and a target — domain controllers — which is part of why CVE-2026-41089 is getting this much attention from administrators who remember how damaging Zerologon exploitation became. But the underlying flaw is different: Zerologon abused a cryptographic weakness in Netlogon's authentication handshake (CWE-330), while CVE-2026-41089 is a memory-safety bug, a stack-based buffer overflow (CWE-121), in how Netlogon parses network input. Don't assume patching one covers the other; they require separate updates, and only CVE-2020-1472 currently appears in CISA's KEV catalog.
What's next
The open question is whether CCB's exploitation warning gets corroborated — by Microsoft updating its own "Exploited" status, by CISA adding CVE-2026-41089 to the KEV catalog, or by independent security researchers publishing indicators of compromise — or whether it remains an unconfirmed, partner-sourced claim. Pandromeda will update this article if either Microsoft or CISA changes its public position. In the meantime, the patch has been available since May 12, 2026, the vulnerability's severity is undisputed at 9.8, and the only action that matters today is the same regardless of how the CCB/Microsoft disagreement resolves: confirm every domain controller is running the May 2026 update or later.
Frequently asked questions
Is CVE-2026-41089 being actively exploited?
Belgium's Centre for Cybersecurity (CCB) says yes, citing information from unnamed 'trusted partners,' but Microsoft has told reporters it does not currently have evidence to support that claim. Microsoft still recommends installing the May 2026 patch regardless. As of this writing, CVE-2026-41089 has not been added to CISA's Known Exploited Vulnerabilities catalog, which only lists vulnerabilities CISA has independently confirmed are being exploited.
What is CVE-2026-41089?
It's a critical, CVSS 9.8 stack-based buffer overflow (CWE-121) in Windows Netlogon that lets an unauthenticated attacker execute code on a Windows Server domain controller by sending a specially crafted network request.
Which Windows Server versions are affected?
Windows Server 2012, 2012 R2 (both under Extended Security Updates), 2016, 2019, 2022, 2022 23H2, and 2025, when configured as domain controllers, per Microsoft's advisory.
How do I patch CVE-2026-41089?
Install your version's May 2026 cumulative security update (KB5087470 through KB5087545 depending on OS version; see the table in this article) and reboot. Hotpatch alternatives KB5087423 and KB5087424 are available for Server 2025 and Server 2022 respectively.
Is CVE-2026-41089 in CISA's KEV catalog?
No, not as of this writing. Only the unrelated 2020 'Zerologon' vulnerability (CVE-2020-1472) currently appears in CISA's Known Exploited Vulnerabilities catalog under Netlogon.
Is this the same vulnerability as Zerologon?
No. Zerologon (CVE-2020-1472) was a 2020 cryptographic flaw in Netlogon's authentication handshake. CVE-2026-41089 is a separate, newly disclosed memory-safety bug (a stack-based buffer overflow) patched in May 2026. Each requires its own update.
Sources
- Microsoft Security Response Center — CVE-2026-41089 advisorymsrc.microsoft.com
- NVD — CVE-2026-41089 recordnvd.nist.gov
- CISA Known Exploited Vulnerabilities Catalogcisa.gov
- Centre for Cybersecurity Belgium — May 2026 Patch Tuesday advisoryccb.belgium.be
- Microsoft Support — KB5087545 (Windows Server 2022 update)support.microsoft.com
- Wikipedia — Domain controlleren.wikipedia.org
Sana Qureshi runs the security and privacy desk. She reports on actively exploited vulnerabilities, vendor patches and data breaches, and covers the password managers, VPNs and authentication tools readers use to protect themselves. Her alerts cite vendor advisories, CISA and the CVE record directly.

