KEVIntel
9.8
CVSS
Critical

CVE-2026-41089

PUBLISHED

Windows Netlogon Remote Code Execution Vulnerability

Exploited in the wild PoC available Remote Low complexity No user interaction
Vendor
Microsoft
Product
Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025, Windows Server 2025 (Server Core installation)
Published
May 12, 2026
EPSS
0.1% · 26% pctl

Automate this intelligence with the Pro API

Everything on this page — CVSS, EPSS, exploit status, PoCs, scanner integrations, mentions, tags, and immediate honeypot data — is available programmatically for VM, SOC, and CTI workflows.

Description

Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network.

windows microsoft

Weaknesses (CWE)

  • Stack-based Buffer Overflow

CVSS scores

CVSS v3.1 9.8 Critical

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

Exploitation status

Exploited in the wild

Recorded 2026-06-02 11:06:00 UTC · KEVIntel

Proof of concept available

Recorded 2026-06-09 15:31:13 UTC · GitHub

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
KEVIntel First 2026-06-02 11:06 UTC
The Shadowserver (via CIRCL) 2026-06-02 17:21 UTC

Potential proof of concepts

These PoCs are unverified and could contain malware. Use at your own risk.

Coasttruvitalize/CVE-2026-41089-latest

github · Created 2026-06-09 15:31:13 UTC · 0 stars

CVE-2026-41089 PoC — Netlogon CLDAP stack buffer overflow (CVSS 9.8 CRITICAL)

SpiralSealFill/CVE-2026-41089-hub

github · Created 2026-06-09 14:14:43 UTC · 0 stars

CVE-2026-41089 PoC — Netlogon CLDAP stack buffer overflow (CVSS 9.8 CRITICAL)

jenniferreire26/CVE-2026-41089

github · Created 2026-06-09 11:16:32 UTC · 0 stars

RoyalViceroyBear/CVE-2026-41089-706

github · Created 2026-06-06 15:47:31 UTC · 0 stars

CVE-2026-41089 PoC — Netlogon CLDAP stack buffer overflow (CVSS 9.8 CRITICAL)

CrimsonKingfisher/CVE-2026-41089-245

github · Created 2026-06-06 15:39:39 UTC · 0 stars

CVE-2026-41089 PoC — Netlogon CLDAP stack buffer overflow (CVSS 9.8 CRITICAL)

Powderbatpatch/CVE-2026-41089-397

github · Created 2026-06-06 15:37:04 UTC · 0 stars

CVE-2026-41089 PoC — Netlogon CLDAP stack buffer overflow (CVSS 9.8 CRITICAL)

StampDreamFitting/CVE-2026-41089-986

github · Created 2026-06-06 14:17:37 UTC · 0 stars

CVE-2026-41089 PoC — Netlogon CLDAP stack buffer overflow (CVSS 9.8 CRITICAL)

segmentjoninsecret/CVE-2026-41089-334

github · Created 2026-06-06 14:02:43 UTC · 0 stars

CVE-2026-41089 PoC — Netlogon CLDAP stack buffer overflow (CVSS 9.8 CRITICAL)

raingatorrouter/CVE-2026-41089-224

github · Created 2026-06-06 13:42:34 UTC · 0 stars

CVE-2026-41089 PoC — Netlogon CLDAP stack buffer overflow (CVSS 9.8 CRITICAL)

raingatorrouter/CVE-2026-41089-953

github · Created 2026-06-06 13:29:33 UTC · 0 stars

CVE-2026-41089 PoC — Netlogon CLDAP stack buffer overflow (CVSS 9.8 CRITICAL)

SightFinchFall/CVE-2026-41089-238

github · Created 2026-06-06 13:21:55 UTC · 0 stars

CVE-2026-41089 PoC — Netlogon CLDAP stack buffer overflow (CVSS 9.8 CRITICAL)

sectiondukestring25/CVE-2026-41089-971

github · Created 2026-06-06 12:11:11 UTC · 0 stars

CVE-2026-41089 PoC — Netlogon CLDAP stack buffer overflow (CVSS 9.8 CRITICAL)

Mapclaregister/CVE-2026-41089-191

github · Created 2026-06-06 11:59:09 UTC · 0 stars

CVE-2026-41089 PoC — Netlogon CLDAP stack buffer overflow (CVSS 9.8 CRITICAL)

GalleryJoiner/CVE-2026-41089-686

github · Created 2026-06-05 11:05:43 UTC · 0 stars

CVE-2026-41089 PoC — Netlogon CLDAP stack buffer overflow (CVSS 9.8 CRITICAL)

Planetpliexpose/CVE-2026-41089-277

github · Created 2026-06-05 11:02:12 UTC · 0 stars

CVE-2026-41089 PoC — Netlogon CLDAP stack buffer overflow (CVSS 9.8 CRITICAL)

System32manager/CVE-2026-41089-699

github · Created 2026-06-05 08:23:12 UTC · 0 stars

CVE-2026-41089 PoC — Netlogon CLDAP stack buffer overflow (CVSS 9.8 CRITICAL)

ADScanPro/CVE-2026-41089-LongLogon

github · Created 2026-06-03 16:30:35 UTC · 8 stars

CVE-2026-41089 checker: unauthenticated, non-destructive detection for the Netlogon CLDAP stack buffer overflow (CVSS 9.8). Reports whether a domain controller's domain is long enough to crash, without sending the overflow. The binary-verified analysis the public PoCs got wrong.

hnytgl/CVE-2026-41089

github · Created 2026-06-03 02:29:06 UTC · 11 stars

CVE-2026-41089 是 Windows Netlogon 服务中一个关键的远程代码执行漏洞

hnytgl/CVE-2026-41089-Detector

github · Created 2026-06-03 00:59:29 UTC · 0 stars

这是一个用于防御巡检的 CVE-2026-41089 检测脚本。该漏洞是 Microsoft 在 2026 年 5 月安全更新中披露的 Windows Netlogon 远程代码执行漏洞。

0xBlackash/CVE-2026-41089

github · Created 2026-06-02 10:35:26 UTC · 2 stars

CVE-2026-41089

0xABCD01/CVE-2026-41089

github · Created 2026-06-01 04:22:29 UTC · 159 stars

CVE-2026-41089 PoC — Netlogon CLDAP stack buffer overflow (CVSS 9.8 CRITICAL)

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel

  • KEV confirmed by The Shadowserver (via CIRCL)

  • Proof of Concept Exploit Available