CVE-2026-41089: Windows Netlogon Remote Code Execution Vulnerability
Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network.
Other sources
Windows Netlogon Remote Code Execution Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.32860Fixed in 10.0.26100.32772Patch KB5087423 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.23181Patch KB5087471 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.25398.2330Patch KB5087541 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.9140Patch KB5087537 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.5139Fixed in 10.0.20348.5074Patch KB5087424 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.8755Patch KB5087538 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.2.9200.26079Patch KB5087470
Event History
Frequently Asked Questions
What is the severity of CVE-2026-41089?
CVE-2026-41089 is classified as a critical severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2026-41089?
To fix CVE-2026-41089, apply the relevant patches released by Microsoft for your affected Windows Server version.
What software is affected by CVE-2026-41089?
CVE-2026-41089 affects several versions of Windows Server including 2025, 2019, 2016, 2012 R2, and others.
What type of vulnerability is CVE-2026-41089?
CVE-2026-41089 is a stack-based buffer overflow vulnerability within the Windows Netlogon component.
Can CVE-2026-41089 be exploited remotely?
Yes, CVE-2026-41089 can be exploited by an unauthorized attacker over a network.