CVE-2026-41089 — RCE critic în Windows Netlogon exploatat activ: patch imediat pe toate Domain Controllerele
CVE-2026-41089 (CVSS 9.8) — stack buffer overflow în LSASS pe Domain Controllere Windows, declanșat printr-un singur pachet UDP la portul 389, fără autentificare. Exploatat activ din 1 iunie 2026. Patch disponibil: Patch Tuesday mai 2026 (KB5058385 pentru Server 2025, KB5058411 pentru Server 2022).