Skip to main content

CVE detail

CVE-2026-41089

Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network.

CVSS 9.8 · CriticalBuzz score 62.04 public exploit repository references

Buzz score

Why this CVE is surfacing

Buzz score total 62.0

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 24.0 · diversity 20.0 · KEV 0.0 · OTX 0.0 · PoC 18.0
Mention score
24.0
10 evidence mentions in the snapshot
Diversity score
20.0
8 sources across 3 categories
KEV score
0.0
No KEV entry observed
OTX score
0.0
0 OTX pulses
PoC score
18.0
4 repos · best confidence 0.99
Best PoC traction
208
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
10 source links · newest first
  • 8th June – Threat Intelligence ReportCheck Point Research

    eft. VULNERABILITIES AND PATCHES Google has released its June Android security patch for 124 vulnerabilities, including CVE-2025-48595, a high-severity Android Framework flaw under exploitation. Local attackers can use the vulnerability to gain code execution and escalate privileges on devices running Android 14 or later. Cisco has released patches for

    vendorresearch.checkpoint.comJun 8, 2026, 2:47 PM
  • Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: OWASP Agent Memory Guard: Stop AI agents from being weaponized through their own memory Agent Memory Guard is an open-source runtime defense layer that sits between an agent and its memory store, screening every read and write through a pipeline of detectors and a YAML policy. The project is the OWASP reference implementation for ASI06, Memory Poisoning, one entry in … More →

    newswww.helpnetsecurity.comJun 7, 2026, 8:00 AM
  • CVE-2026-41089Hacker News

    Linked URL: https://gemini.google.com/share/ab8ed0f5c0ec | Posted by redog | 3 points | 2 comments

    communitynews.ycombinator.comJun 1, 2026, 8:12 PM
  • Organizations are advised to patch CVE-2026-41089 as soon as possible, given its severity, the potential ongoing exploitation.

    newswww.securityweek.comJun 1, 2026, 3:02 PM
  • CVE-2026-41089, a critical Windows Netlogon RCE flaw that allows remote code execution, is now actively exploited in the wild, the Centre for Cybersecurity Belgium (CCB) warned on Friday. About CVE-2026-41089 CVE-2026-41089 is a stack-based buffer overflow vulnerability in Windows Netlogon, the service and protocol that handles authentication and security within a Windows domain environment. The flaw can be exploited by attackers by sending a specially crafted network request to a Windows server that is acting … More →

    newswww.helpnetsecurity.comJun 1, 2026, 2:17 PM
  • Microsoft’s May 2026 Patch Tuesday fixed 138 flaws, including 30 critical bugs, across Windows, Office, Azure, Edge, SQL Server, and more. Microsoft’s May 2026 Patch Tuesday patched 138 vulnerabilities in a single release. That is a number that gives pause even for people accustomed to these cycles. The affected products span virtually the entire Microsoft […]

    newssecurityaffairs.comMay 13, 2026, 7:28 PM
  • Critical vulnerabilities in Windows Server’s networking and identity infrastructure, as well as a serious hole in Microsoft Dynamics 365 on-premises version, highlight Microsoft’s May Patch Tuesday fixes. They are among the 118 vulnerabilities identified this month by the company. Some in cloud-based services like Azure and Microsoft Teams have already been fixed, so no admin […]

    newswww.csoonline.comMay 13, 2026, 12:54 AM
  • Microsoft has marked May 2026 Patch Tuesday by releasing fixes for 120+ CVE-numbered vulnerabilities, none of which (for a change) are actively exploited or have been publicly disclosed. Still, some deserve more consideration and should be addressed sooner than others. Patches to prioritize For Satnam Narang, senior staff research engineer at Tenable, the four critical remote code execution bugs in Microsoft Word stand out in this release, and especially the two (CVE-2026-40361, CVE-2026-40364) that have … More →

    newswww.helpnetsecurity.comMay 12, 2026, 7:03 PM
  • The May 2026 Security Update ReviewZero Day Initiative

    take a closer look at some of the more interesting updates for this month, starting with a nasty-looking bug in DNS: - CVE-2026-41096 - Windows DNS Client Remote Code Execution Vulnerability This patch fixes a heap-based buffer overflow in the DNS Client triggered by a malicious DNS response. No authentication or user interaction needed, and since the

    vendorwww.thezdi.comMay 12, 2026, 6:38 PM
  • Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network.

    vendormsrc.microsoft.comMay 12, 2026, 2:00 PM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

4 repository references · best confidence 0.99 · max 208 stars

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence