CVE-2026-41089: Windows Netlogon Pre-Authentication RCE — Unauthenticated Domain Controller Takeover
Microsoft — Windows Netlogon (Windows Server)
A stack-based buffer overflow in Windows Netlogon allows an unauthenticated attacker to achieve SYSTEM-level code execution on any unpatched domain controller. Active exploitation confirmed by Belgium's CCB. Patch immediately — no workaround removes the attack surface.