<< Back
CVE Number Vulnerability Product Severity Date
CVE-2026-41089 Windows Netlogon Remote Code Execution Vulnerability Windows Server Critical 29-05-2026

Technical Information

An unauthorized attacker could exploit a stack-based buffer overflow vulnerability in Windows Netlogon to perform remote code execution by sending a specially crafted network request to a domain controller, causing the Netlogon service to improperly process the request and execute arbitrary code on the affected system without authentication.

Patch release date: May 12, 2026
Further information on this vulnerability is available at : CVE-2026-41089

Affected Software

Windows Server 2019,
Windows Server 2019 (Server Core installation),
Windows Server 2022,
Windows Server 2022 (Server Core installation),
Windows Server 2025 (Server Core installation),
Windows Server 2022, 23H2 Edition (Server Core installation),
Windows Server 2025,
Windows Server 2016,
Windows Server 2016 (Server Core installation),
Windows Server 2012,
Windows Server 2012 (Server Core installation),
Windows Server 2012 R2,
Windows Server 2012 R2 (Server Core installation)