Critical Windows Netlogon RCE flaw now exploited in attacks
Belgium’s CCB says attackers are actively exploiting a newly patched Windows Netlogon flaw that can lead to remote code execution on domain controllers.
Intelligence analysis by GPT-5.4 Mini

The Centre for Cybersecurity Belgium says CVE-2026-41089 is now being exploited in the wild. The bug affects supported Windows Server versions and can let an unauthenticated attacker run code on a domain controller, so admins are being urged to patch immediately.
A big lock on a computer door has a crack in it. That crack lets a bad person do something they should not be able to do, even without a key.
This crack is in a Windows service that helps important office computers recognize people and share access. If it is used on a main server, the attacker could take control of it.
Think of it like a house with a broken front lock. If burglars are already trying the door, the safest move is to fix the lock right away before they get in.
Analysis
What happened
Belgium’s national cybersecurity authority, the CCB, warned that threat actors are actively exploiting CVE-2026-41089, a critical Windows Netlogon flaw that Microsoft patched in May 2026. The issue is described as a stack-based buffer overflow in Netlogon that can let an attacker without privileges achieve remote code execution on targeted domain controllers.
Why the flaw is serious
Netlogon is a core Windows Server service used for authentication in domain-based networks. Microsoft says a specially crafted network request sent to a server acting as a domain controller could trigger improper handling in the service and potentially allow code execution without sign-in or prior access. Microsoft said the bug affects all currently supported Windows Server versions, including Windows Server 2025.
What the article says about exploitation
The CCB said on Friday that the flaw is now “actively exploited in the wild” and urged administrators to patch vulnerable servers quickly. BleepingComputer says the authority did not provide details about the attacks and did not respond to a request for more information. Microsoft had not updated its advisory at the time of publication, and the company also did not reply to BleepingComputer’s request for confirmation.
Context
Microsoft says its internal WARP team discovered the issue. The article also places this disclosure alongside several other Windows zero-days attributed to researcher Nightmare Eclipse, including vulnerabilities Microsoft has already addressed or that are reportedly being exploited. For security teams, the immediate takeaway is simple: domain controllers running supported Windows Server releases need prompt patching and exposure review.
Key points
- Belgium’s CCB says CVE-2026-41089 is being actively exploited in the wild.
- The flaw is a critical Netlogon buffer overflow that can lead to remote code execution.
- Microsoft patched the issue in May 2026 and says it affects supported Windows Server versions, including Server 2025.
- The CCB urged administrators to patch vulnerable servers immediately.
- Microsoft had not publicly confirmed the exploitation claim at the time of the article.
If administrators patch quickly, they can close off a path to remote code execution on domain controllers before more attacks land. The CCB warning also gives defenders a clear signal to prioritize affected Windows Server systems now rather than waiting for routine maintenance.
If organizations delay patching, an attacker may be able to send a crafted request and run code on a domain controller without logging in. Because the article says exploitation is already happening in the wild, slow response could leave enterprise networks exposed to compromise.



