---
schema: 1
kind: vulnerability
title: "Windows Netlogon RCE CVE-2026-41089 now confirmed exploited in the wild in the EU; CERT-EU issues advisory 2026-007"
headline: "Windows Netlogon RCE CVE-2026-41089 now confirmed exploited in the wild in the EU; CERT-EU issues advisory 2026-007"
summary: "Windows Netlogon RCE CVE-2026-41089 (CVSS 9.8, pre-auth SYSTEM on any unpatched DC) is now confirmed exploited in the wild in the EU by Belgium's CCB; CERT-EU issued advisory 2026-007 (CERT-EU, 2026-06-10). The fix shipped in May 2026 Patch Tuesday — unpatched domain controllers are a forest-compromise path."
discovered_at: "2026-06-11T05:00:06Z"
event_date: 2026-06-10
run_id: 2026-06-11-7edf1d8a
priority: high
immediate_action: null
tags:
  - vulnerabilities
  - actively-exploited
  - pre-auth
  - rce
  - identity
regions:
  - europe
  - global
sectors:
  - public-sector
entities: []
cves:
  - id: CVE-2026-41089
    cvss: "9.8"
    epss: null
    type: rce
    vector: zero-click
    auth: pre-auth
    status:
      - exploited
      - patch-available
sources:
  - url: "https://cert.europa.eu/publications/security-advisories/2026-007/"
    publisher: CERT-EU 2026-007
    role: primary
  - url: "https://www.bleepingcomputer.com/news/microsoft/critical-windows-netlogon-remote-code-execution-flaw-now-exploited-in-attacks/"
    publisher: BleepingComputer
    role: corroborating
closed_sources: []
evidence:
  - quote: "UPDATE (originally covered 2026-W23 weekly): CERT-EU published advisory 2026-007 on 10 June 2026 confirming that CVE-2026-41089 — a CVSS 9.8 stack-based buffer overflow (CWE-121) in the Windows Netlogon service — is being actively exploited in the wild, citing Belgium's Centre for Cybersecurity …"
    publisher: ctipilot v2 brief (migrated)
verification: multi-source
sourcing_note: "migration: evidence backfilled from v2 brief body (item predates the Evidence footer field); migration: update target unresolved (no originally-covered date in v2 body)"
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
watchlist_hit: false
actions:
  - "**Confirm all domain controllers carry the May 2026 Patch Tuesday update (CVE-2026-41089).** Pre-auth Netlogon RCE giving SYSTEM on any unpatched DC is now confirmed exploited in the wild in the EU by Belgium's CCB. Where a DC cannot be patched immediately (legacy Server 2012/2012 R2 past ESU), isolate it behind a management VLAN with firewall rules blocking Netlogon from untrusted subnets."
migrated_from: briefs/2026-06-11.md
---

**UPDATE (originally covered 2026-W23 weekly):** CERT-EU published advisory 2026-007 on 10 June 2026 confirming that CVE-2026-41089 — a CVSS 9.8 stack-based buffer overflow (CWE-121) in the Windows Netlogon service — is being actively exploited in the wild, citing Belgium's Centre for Cybersecurity (CCB) ([CERT-EU, 2026-06-10](https://cert.europa.eu/publications/security-advisories/2026-007/)). This is the material delta since the weekly's disclosure-only coverage: an EU national authority has now attributed in-the-wild exploitation, roughly 20 days after the May 2026 Patch Tuesday fix.

An unauthenticated remote attacker sends a crafted Netlogon RPC packet to obtain SYSTEM-level code execution on an unpatched domain controller — functionally a full Active Directory forest compromise, in the ZeroLogon lineage of Netlogon-channel attacks ([BleepingComputer, 2026-06-01](https://www.bleepingcomputer.com/news/microsoft/critical-windows-netlogon-remote-code-execution-flaw-now-exploited-in-attacks/)). CERT-EU's advisory carries the per-version patched-build table: Server 2016 before 10.0.14393.9140, Server 2019 before 10.0.17763.8755, Server 2022 before 10.0.20348.5074, Server 2022 23H2 before 10.0.25398.2330, and Server 2025 before 10.0.26100.32772, with Server 2012/2012 R2 also affected.
