Netlogon RCE Vulnerability Under Active Attack in the Wild
ID: 36e5aa1e-00a3-5745-a7b7-a04444783d79
STIX ID: report--36e5aa1e-00a3-5745-a7b7-a04444783d79
Feed Name: securityonline.info
Threat Score
**Executive summary:** A critical Netlogon RCE (CVE-2026-41089, CVSS 9.8) is being actively exploited to obtain SYSTEM privileges on Windows domain controllers; Microsoft issued patches in the May 2026 Patch Tuesday, and administrators are strongly advised to apply fixes immediately and isolate exposed controllers while investigating anomalous authentication activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
