CuraSec

Act active

CVE-2026-41089 Netlogon RCE: Public PoC Released, EPSS 0.80

2026-09-12 14:04 UTC · GitHub Trending · read the source ↗ #netlogon#rce#active-directory
  • Engineer — Act: Netlogon RCE with EPSS 0.80 and a public PoC is a critical, imminent-exploitation risk for any Active Directory environment. Apply the Microsoft patch for CVE-2026-41089 to all domain controllers immediately, prioritizing before the weekend.
  • SOC/IR — Act: With a public PoC and EPSS 0.80, exploitation attempts are likely already occurring; initiate a hunt for anomalous Netlogon traffic and failed authentication spikes (Windows Event IDs 5805, 4625) against domain controllers since the PoC publication date.
  • Leader — Act: A Netlogon RCE with public exploit code represents a domain-wide compromise scenario comparable to ZeroLogon — confirm with your team that emergency DC patching is underway and brief leadership now, before this surfaces in the news.
  • Signals: CVE-2026-41089 — CISA KEV: not listed, EPSS 0.80, public PoC on GitHub
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.