This article was collected and archived by Digital Sovereignty Watch from an institutional or public source relevant to digital sovereignty, technology policy, cybersecurity, cloud services, artificial intelligence or European regulation.
Cybersecurity
Critical Vulnerability in Windows Netlogon
Microsoft has released information about the Windows Netlogon vulnerability, CVE-2026-41089, assigned a critical CVSS score of 9.8. An attacker can send a specially crafted network request to a Windows server functioning as a domain controller. If exploited successfully, the Netlogon service mishandles this request, potentially leading to remote code execution (RCE) on the affected system without requiring authentication or prior access rights. Current information indicates that the vulnerability is actively being exploited in attacks against systems that have not yet installed the relevant vendor security updates. If not yet applied, it is strongly recommended to update systems to the latest versions as soon as possible.