- Engineer — Act: Netlogon RCE with EPSS 0.80 and a public PoC is a critical, imminent-exploitation risk for any Active Directory environment. Apply the Microsoft patch for CVE-2026-41089 to all domain controllers immediately, prioritizing before the weekend.
- SOC/IR — Act: With a public PoC and EPSS 0.80, exploitation attempts are likely already occurring; initiate a hunt for anomalous Netlogon traffic and failed authentication spikes (Windows Event IDs 5805, 4625) against domain controllers since the PoC publication date.
- Leader — Act: A Netlogon RCE with public exploit code represents a domain-wide compromise scenario comparable to ZeroLogon — confirm with your team that emergency DC patching is underway and brief leadership now, before this surfaces in the news.
- Signals: CVE-2026-41089 — CISA KEV: not listed, EPSS 0.80, public PoC on GitHub