Stack-based buffer overflow in Windows Server - CVE-2026-41089
Published: May 13, 2026 / Updated: August 31, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error in Windows Netlogon. A remote unauthenticated attacker can send specially crafted network request to a domain controller server, trigger a stack-based buffer overflow and execute arbitrary code with SYSTEM privileges.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system and the entire AD.
Affected software
How to mitigate CVE-2026-41089
Links to Public Exploits and PoC-codes
- Exploit #13020 - CVE-2026-41089-LongLogon (CVE-2026-41089 checker: unauthenticated, non-destructive detection for the Netlogon CLDAP stack buffer overflow (CVSS 9.8). Reports whether a domain controller's domain is long enough to crash, without sending the overflow. The b (August 31, 2026)
- Exploit #12883 - CVE-2026-41089 (CVE-2026-41089 - Windows Netlogon CLDAP Remote Code Execution Exploit (CVSS 9.8)) (August 6, 2026)
- Exploit #12778 - CVE-2026-41089 (CVE-2026-41089 PoC — Netlogon CLDAP stack buffer overflow (CVSS 9.8 CRITICAL)) (June 23, 2026)