<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Netlogon on CuraSec</title><link>https://curasec.metacog.co.kr/tags/netlogon/</link><description>Recent content in Netlogon on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sat, 12 Sep 2026 14:04:45 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/netlogon/index.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-41089 Netlogon RCE: Public PoC Released, EPSS 0.80</title><link>https://curasec.metacog.co.kr/insights/2026-09-12-syntaxmethod-cve-2026-41089-netlogon-rce-poc-58/</link><pubDate>Sat, 12 Sep 2026 14:04:45 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-09-12-syntaxmethod-cve-2026-41089-netlogon-rce-poc-58/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> Netlogon RCE with EPSS 0.80 and a public PoC is a critical, imminent-exploitation risk for any Active Directory environment. Apply the Microsoft patch for CVE-2026-41089 to all domain controllers immediately, prioritizing before the weekend.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> With a public PoC and EPSS 0.80, exploitation attempts are likely already occurring; initiate a hunt for anomalous Netlogon traffic and failed authentication spikes (Windows Event IDs 5805, 4625) against domain controllers since the PoC publication date.&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> A Netlogon RCE with public exploit code represents a domain-wide compromise scenario comparable to ZeroLogon — confirm with your team that emergency DC patching is underway and brief leadership now, before this surfaces in the news.&lt;/li>
&lt;li>&lt;strong>Signals:&lt;/strong> CVE-2026-41089 — CISA KEV: not listed, EPSS 0.80, public PoC on GitHub&lt;/li>
&lt;/ul></description></item></channel></rss>