CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →
← Back to Daily brief 2026-05-13
CRITICALCVE-2026-41089 +3exploitedupdatedvulnerability

CVE-2026-41089 / CVE-2026-41096 / CVE-2026-41103 / CVE-2026-42898; Microsoft May 2026 Patch Tuesday (120+ CVEs, no zero-days)

Defender actions

  • Roll out May 2026 Windows cumulative update, DCs first, member servers next. Netlogon (CVE-2026-41089) and DNS Client (CVE-2026-41096) are the wormable-candidate pre-auth RCEs; SSO Plugin for Jira/Confluence (CVE-2026-41103) is "Exploitation More Likely". Inventory and update self-managed Atlassian deployments using Microsoft's Entra-ID SSO plugin before the next work week. Disable Outlook Preview Pane fleet-wide as an interim mitigation for the four Word RCEs. See § 2
  • Emergency-patch every domain controller against CVE-2026-41089 (Windows Netlogon), unauthenticated RCE to SYSTEM, now reported exploited in the wild. Apply the May 2026 Patch Tuesday cumulative update to all DCs immediately and restrict Netlogon/LDAP reachability to trusted hosts. (.

Analysis

Microsoft shipped roughly 120 CVE fixes in the May 2026 cumulative updates (source counts vary 118–138 depending on whether developer-tools and Azure-only items are included); ZDI counts ~30 Critical, none under active exploitation at release (Tenable, 2026-05-12; Krebs on Security, 2026-05-12; ZDI, 2026-05-12). CVE-2026-41089 (Windows Netlogon, CVSS 9.8, CWE-121 stack buffer overflow): unauthenticated remote attacker over the network reaches the domain-controller Netlogon RPC endpoint; Microsoft marks "Exploitation Less Likely" but ZDI flags the pattern as wormable-candidate. CVE-2026-41096 (Windows DNS Client, CVSS 9.8, CWE-122 heap overflow in dnsapi.dll): a crafted DNS response from a MitM or rogue resolver yields code execution as NetworkService on every Windows host; defender exposure is anywhere a host might receive an attacker-influenced DNS reply. CVE-2026-41103 (Microsoft SSO Plugin for Jira/Confluence, CVSS 9.1, "Exploitation More Likely"): unauthenticated attacker forges an Entra ID credential to sign in to self-managed Atlassian; affects public-sector DevSecOps stacks using Microsoft's Entra-ID auth plugin. CVE-2026-42898 (Dynamics 365 On-Premises, CVSS 9.9): authenticated code injection with scope change, a rare privilege-boundary violation in this product family. Four Microsoft Word RCEs (CVE-2026-40361 / CVE-2026-40364 / CVE-2026-40366 / CVE-2026-40367, CVSS 8.4 each) have the Preview Pane as an attack vector and two are rated "Exploitation More Likely". MITRE ATT&CK mappings: T1210 Exploitation of Remote Services (Netlogon), T1071.004 Application Layer Protocol: DNS (DNS Client), T1078.004 Cloud Accounts (Entra forgery). Detection concepts: monitor Netlogon authentication-pattern anomalies (4624 Logon Type 3 to DCs from unexpected internal sources, paired with 4769 ticket-request anomalies); alert on outbound DNS to non-corporate resolvers from DC and member hosts; audit Atlassian SSO plugin version inventory; disable Outlook Preview Pane as an interim mitigation for Word RCEs. Hardening: prioritise DCs first (Netlogon is on the DC boundary); inventory dnsapi.dll patch state across the fleet; inventory self-managed Atlassian deployments and apply the SSO plugin update before the next work week.

Cited evidence

CVE-2026-41089, a critical Windows Netlogon RCE flaw that allows remote code execution, is now actively exploited in the wild

Help Net Security

Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network.

Microsoft MSRC

Updates1

Update

The Windows Netlogon stack-based buffer-overflow RCE patched in May 2026 Patch Tuesday is now reported as exploited in the wild. Belgium's Centre for Cybersecurity (CCB) confirmed active exploitation on 1 June, and BleepingComputer, Help Net Security and SecurityWeek reported the same (BleepingComputer, 2026-06-01 · Help Net Security, 2026-06-01).

The vulnerability is an unauthenticated, network-reachable overflow in the Netlogon service that yields SYSTEM on a domain controller, affecting all currently supported Windows Server releases including Server 2025 (Microsoft MSRC). Microsoft had not updated its advisory to mark the CVE exploited as of 1 June, so the exploitation signal currently rests on CCB plus the reporting outlets rather than the vendor. The operational shift is decisive: a flaw previously reasonable to schedule into a patch cycle is now an emergency change for every internet- or network-reachable DC.

Sources7

Revision history

  1. Published 2026-05-13-c148b9a5
  2. Update 2026-06-02-8af85d01

    Windows Netlogon pre-auth RCE (CVE-2026-41089, CVSS 9.8) is now actively exploited. Belgium's national CSIRT (CCB) confirmed in-the-wild exploitation on 1 June against the stack-based buffer overflow in the Windows Netlogon service that yields SYSTEM on any domain controller without authentication (BleepingComputer, 2026-06-01). Patched in May 2026 Patch Tuesday; see the Immediate Action below and the §4 update.

    Changed: actions cves evidence immediate_action priority regions sectors sources tags body

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.