---
schema: 1
kind: vulnerability
title: >
  CVE-2026-41089 / CVE-2026-41096 / CVE-2026-41103 / CVE-2026-42898 — Microsoft May 2026 Patch
  Tuesday (120+ CVEs, no zero-days)
headline: >
  CVE-2026-41089 / CVE-2026-41096 / CVE-2026-41103 / CVE-2026-42898 — Microsoft May 2026 Patch
  Tuesday (120+ CVEs, no zero-days)
summary: >
  Microsoft May Patch Tuesday — 120+ CVEs, no zero-days, but a Netlogon pre-auth RCE on the DC.
  CVE-2026-41089 (Windows Netlogon, CVSS 9.8, stack overflow) is a wormable-candidate pre-auth RCE
  against every supported Windows Server; CVE-2026-41096 (Windows DNS Client, CVSS 9.8, heap
  overflow) is reachable from a malicious DNS response on every Windows host; CVE-2026-41103
  (Microsoft SSO Plugin for Jira/Confluence, CVSS 9.1) is rated "Exploitation More Likely". 16 of
  the CVEs were discovered by Microsoft's new MDASH AI scanning harness.
discovered_at: "2026-05-13T05:00:04Z"
updated_at: "2026-06-02T05:00:09Z"
event_date: 2026-05-12
run_id: 2026-05-13-c148b9a5
priority: critical
immediate_action:
  title: Patch domain controllers against CVE-2026-41089 (Windows Netlogon) now
  action: >
    The May 2026 Patch Tuesday fixed an unauthenticated, network-reachable stack-based buffer
    overflow in the Windows Netlogon service that grants remote code execution as SYSTEM on a domain
    controller with no credentials and no user interaction (Microsoft MSRC). On 1 June, Belgium's
    Centre for Cybersecurity (CCB) and multiple outlets reported active in-the-wild exploitation;
    Microsoft had not yet updated its advisory to reflect exploitation (BleepingComputer,
    2026-06-01).
tags:
  - vulnerabilities
  - pre-auth
  - rce
  - identity
  - patch-available
  - actively-exploited
regions:
  - global
  - europe
sectors:
  - public-sector
entities: []
techniques: []
affected_products: []
cves:
  - id: CVE-2026-41089
    cvss: "9.8"
    epss: null
    type: rce
    vector: zero-click
    auth: pre-auth
    status:
      - exploited
      - patch-available
  - id: CVE-2026-41096
    cvss: "9.8"
    epss: null
    type: rce
    vector: zero-click
    auth: pre-auth
    status:
      - patch-available
  - id: CVE-2026-41103
    cvss: "9.1"
    epss: null
    type: rce
    vector: zero-click
    auth: pre-auth
    status:
      - patch-available
  - id: CVE-2026-42898
    cvss: "9.9"
    epss: null
    type: rce
    vector: zero-click
    auth: pre-auth
    status:
      - patch-available
sources:
  - url: "https://www.tenable.com/blog/microsofts-may-2026-patch-tuesday-addresses-118-cves-cve-2026-41103"
    publisher: "Tenable, 2026-05-12"
    role: primary
  - url: "https://www.thezdi.com/blog/2026/5/12/the-may-2026-security-update-review"
    publisher: "ZDI, 2026-05-12"
    role: corroborating
  - url: "https://krebsonsecurity.com/2026/05/patch-tuesday-may-2026-edition/"
    publisher: "Krebs on Security, 2026-05-12"
    role: corroborating
  - url: "https://www.helpnetsecurity.com/2026/05/12/microsoft-may-2026-patch-tuesday/"
    publisher: "Help Net Security, 2026-05-12"
    role: corroborating
  - url: "https://www.bleepingcomputer.com/news/microsoft/critical-windows-netlogon-remote-code-execution-flaw-now-exploited-in-attacks/"
    publisher: BleepingComputer
    role: primary
  - url: "https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-41089"
    publisher: Microsoft MSRC advisory
    role: corroborating
  - url: "https://www.helpnetsecurity.com/2026/06/01/windows-netlogon-rce-exploited-cve-2026-41089/"
    publisher: Help Net Security
    role: corroborating
closed_sources: []
evidence:
  - quote: "CVE-2026-41089, a critical Windows Netlogon RCE flaw that allows remote code execution, is now actively exploited in the wild"
    publisher: Help Net Security
  - quote: Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network.
    publisher: Microsoft MSRC
verification: multi-source
sourcing_note: null
confidence: high
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
classification: null
watchlist_hit: false
actions:
  - "**Roll out May 2026 Windows cumulative update — DCs first, member servers next.** Netlogon (CVE-2026-41089) and DNS Client (CVE-2026-41096) are the wormable-candidate pre-auth RCEs; SSO Plugin for Jira/Confluence (CVE-2026-41103) is \"Exploitation More Likely\". Inventory and update self-managed Atlassian deployments using Microsoft's Entra-ID SSO plugin before the next work week. Disable Outlook Preview Pane fleet-wide as an interim mitigation for the four Word RCEs. See § 2"
  - "**Emergency-patch every domain controller against CVE-2026-41089 (Windows Netlogon)** — unauthenticated RCE to SYSTEM, now reported exploited in the wild. Apply the May 2026 Patch Tuesday cumulative update to all DCs immediately and restrict Netlogon/LDAP reachability to trusted hosts. (."
updates:
  - at: "2026-06-02T05:00:09Z"
    run_id: 2026-06-02-8af85d01
    type: update
    summary: >
      Windows Netlogon pre-auth RCE (CVE-2026-41089, CVSS 9.8) is now actively exploited. Belgium's
      national CSIRT (CCB) confirmed in-the-wild exploitation on 1 June against the stack-based buffer
      overflow in the Windows Netlogon service that yields SYSTEM on any domain controller without
      authentication (BleepingComputer, 2026-06-01). Patched in May 2026 Patch Tuesday; see the
      Immediate Action below and the §4 update.
    fields:
      - actions
      - cves
      - evidence
      - immediate_action
      - priority
      - regions
      - sectors
      - sources
      - tags
      - body
    merged_from: 2026-06-02/windows-netlogon-cve-2026-41089-moves-from-patch-available-t
migrated_from: briefs/2026-05-13.md
---

Microsoft shipped roughly 120 CVE fixes in the May 2026 cumulative updates (source counts vary 118–138 depending on whether developer-tools and Azure-only items are included); ZDI counts ~30 Critical, none under active exploitation at release ([Tenable, 2026-05-12](https://www.tenable.com/blog/microsofts-may-2026-patch-tuesday-addresses-118-cves-cve-2026-41103); [Krebs on Security, 2026-05-12](https://krebsonsecurity.com/2026/05/patch-tuesday-may-2026-edition/); [ZDI, 2026-05-12](https://www.thezdi.com/blog/2026/5/12/the-may-2026-security-update-review)). **CVE-2026-41089** (Windows Netlogon, CVSS 9.8, CWE-121 stack buffer overflow): unauthenticated remote attacker over the network reaches the domain-controller Netlogon RPC endpoint; Microsoft marks "Exploitation Less Likely" but ZDI flags the pattern as wormable-candidate. **CVE-2026-41096** (Windows DNS Client, CVSS 9.8, CWE-122 heap overflow in `dnsapi.dll`): a crafted DNS response from a MitM or rogue resolver yields code execution as `NetworkService` on every Windows host; defender exposure is anywhere a host might receive an attacker-influenced DNS reply. **CVE-2026-41103** (Microsoft SSO Plugin for Jira/Confluence, CVSS 9.1, "Exploitation More Likely"): unauthenticated attacker forges an Entra ID credential to sign in to self-managed Atlassian; affects public-sector DevSecOps stacks using Microsoft's Entra-ID auth plugin. **CVE-2026-42898** (Dynamics 365 On-Premises, CVSS 9.9): authenticated code injection with scope change — a rare privilege-boundary violation in this product family. Four Microsoft Word RCEs (CVE-2026-40361 / CVE-2026-40364 / CVE-2026-40366 / CVE-2026-40367, CVSS 8.4 each) have the Preview Pane as an attack vector and two are rated "Exploitation More Likely". MITRE ATT&CK mappings: `T1210 Exploitation of Remote Services` (Netlogon), `T1071.004 Application Layer Protocol: DNS` (DNS Client), `T1078.004 Cloud Accounts` (Entra forgery). Detection concepts: monitor Netlogon authentication-pattern anomalies (`4624 Logon Type 3` to DCs from unexpected internal sources, paired with `4769` ticket-request anomalies); alert on outbound DNS to non-corporate resolvers from DC and member hosts; audit Atlassian SSO plugin version inventory; disable Outlook Preview Pane as an interim mitigation for Word RCEs. Hardening: prioritise DCs first (Netlogon is on the DC boundary); inventory `dnsapi.dll` patch state across the fleet; inventory self-managed Atlassian deployments and apply the SSO plugin update before the next work week.

## Update — 2026-06-02T05:00:09Z

The Windows Netlogon stack-based buffer-overflow RCE patched in May 2026 Patch Tuesday is now reported as exploited in the wild. Belgium's Centre for Cybersecurity (CCB) confirmed active exploitation on 1 June, and BleepingComputer, Help Net Security and SecurityWeek reported the same ([BleepingComputer, 2026-06-01](https://www.bleepingcomputer.com/news/microsoft/critical-windows-netlogon-remote-code-execution-flaw-now-exploited-in-attacks/) · [Help Net Security, 2026-06-01](https://www.helpnetsecurity.com/2026/06/01/windows-netlogon-rce-exploited-cve-2026-41089/)).

The vulnerability is an unauthenticated, network-reachable overflow in the Netlogon service that yields SYSTEM on a domain controller, affecting all currently supported Windows Server releases including Server 2025 ([Microsoft MSRC](https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-41089)). Microsoft had not updated its advisory to mark the CVE exploited as of 1 June, so the exploitation signal currently rests on CCB plus the reporting outlets rather than the vendor. The operational shift is decisive: a flaw previously reasonable to schedule into a patch cycle is now an emergency change for every internet- or network-reachable DC.
