Scan Windows Domain Controllers for CVE-2026-41089 to detect unauthenticated remote code execution vulnerabilities in the Netlogon service.

Scan Windows Domain Controllers for CVE-2026-41089 to detect unauthenticated remote code execution vulnerabilities in the Netlogon service.

Published 26 Aug 2026Updated 26 Aug 2026145 sources
CVSS 9.8 CRITICALPoC CANDIDATE

What happened

Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network.

Affected versions

Unknown product: See original advisory Fixed: See vendor advisory.

Why it matters

This source correlation may provide earlier visibility while structured CVE metadata is still being updated.

Detection & mitigation

  • Review the original advisory and validate affected versions.
  • Apply vendor-provided updates or mitigations when available.

Public PoC references

RepositoryAuthorFirst seenReference
CVE-Intel · opensource-arrozconpollo191/CVE-2026-41089-Netlogon-RCEScan Windows Domain Controllers for CVE-2026-41089 to detect unauthenticated remote code execution vulnerabilities in the Netlogon service.RCEPythonCRITICALAnalyzed★ 1⑂ 0EPSS 79.62%CVE data: NISTCode indexedUpdated 26 Aug 2026Tags: active-directory, buffer-overflow, cve-2026-41089, cybersecurity, domain-controller, exploit-poc, netlogon-rce, privilege-escalationopensource-arrozconpollo1912026-07-22CandidateCVE-Intel · HydraSoft/CVE-2026-41089-Netlogon-RCETechnical analysis and Proof-of-Concept (PoC) for CVE-2026-41089, a critical unauthenticated Remote Code Execution (RCE) vulnerability in the Windows Netlogon service affecting Domain Controllers.RCEHTMLCRITICALAnalyzed★ 16⑂ 10EPSS 79.62%CVE data: NISTCode indexedUpdated 25 Aug 2026Tags: active-directory, buffer-overflow, cve-2026-41089, cybersecurity, domain-controller, exploit-poc, netlogon-rce, privilege-escalationHydraSoft2026-07-21CandidateCVE-Intel · 0xABCD01/CVE-2026-41089CVE-2026-41089 PoC — Netlogon CLDAP stack buffer overflow (CVSS 9.8 CRITICAL)PoCPythonCRITICALAnalyzed★ 212⑂ 66EPSS 79.62%CVE data: NISTCode indexedUpdated 24 Aug 2026Tags: buffer-overflow, cldap, cve, cve-2026-41089, exploit, poc, vulnerability, vulnerability-detection0xABCD012026-06-01CandidateCVE-Intel · ADScanPro/CVE-2026-41089-LongLogonCVE-2026-41089 checker: unauthenticated, non-destructive detection for the Netlogon CLDAP stack buffer overflow (CVSS 9.8). Reports whether a domain controller's domain is long enough to crash, without sending the overflow. The binary-verified analysis the public PoCs got wrong.DoSPythonCRITICALAnalyzed★ 14⑂ 2EPSS 79.62%CVE data: NISTCode indexedUpdated 24 Aug 2026Tags: active-directory, buffer-overflow, cldap, cve, cve-2026-41089, domain-controller, exploit, longlogonADScanPro2026-06-03CandidateCVE-Intel · jelasin/CVE-2026-41089CVE-2026-41089 PoC — Netlogon CLDAP stack buffer overflow (CVSS 9.8 CRITICAL)PoCCRITICALAnalyzed★ 0⑂ 0EPSS 79.62%CVE data: NISTUpdated 19 Aug 2026jelasin2026-06-01CandidateCVE-Intel · 0xBlackash/CVE-2026-41089CVE-2026-41089ExploitPythonCRITICALAnalyzed★ 10⑂ 1EPSS 79.62%CVE data: NISTCode indexedUpdated 28 Jul 20260xBlackash2026-06-02CandidateCVE-Intel · hnytgl/CVE-2026-41089CVE-2026-41089 是 Windows Netlogon 服务中一个关键的远程代码执行漏洞,单包即可崩溃 lsass.exe,导致域控制器在约 30-60 秒内重启。此期间该 DC 的所有域认证将失败。ExploitPythonCRITICALAnalyzed★ 14⑂ 13EPSS 79.62%CVE data: NISTCode indexedUpdated 28 Jun 2026hnytgl2026-06-03CandidateCVE-Intel · hnytgl/CVE-2026-41089-Detector这是一个用于防御巡检的 CVE-2026-41089 检测脚本。该漏洞是 Microsoft 在 2026 年 5 月安全更新中披露的 Windows Netlogon 远程代码执行漏洞。ExploitPythonCRITICALAnalyzed★ 0⑂ 1EPSS 79.62%CVE data: NISTCode indexedUpdated 6 Jun 2026hnytgl2026-06-03Candidate