A Windows Server bug is now under real attack, and it hits the one machine that decides who gets into a company network. If you run Windows servers, patch them now.
The flaw, called CVE-2026-41089, is in Netlogon. That is the part of Windows that handles logins and trust inside a company's network. Belgium's Centre for Cybersecurity says attackers are already using the bug in the wild. Microsoft shipped a fix on May 12, 2026, as part of its monthly batch of updates.
This bug lives on the domain controller, which makes it serious. A domain controller is the server that checks who every user and computer is before letting them in. It is the gatekeeper for the whole network. Break into one desktop and you have a foothold. Break into the domain controller and you are standing at the front door with the keys to everyone's account. A single flaw here matters far more than a normal bug on an ordinary machine.
Centre for Cybersecurity Belgium, Microsoft release note
No clicks, no password, full control
The attack needs nothing from the user. No bad link to click. No stolen password. An attacker just sends specially crafted data over the network to a server, and a mistake in how Netlogon handles memory lets them run their own program on it instead. Microsoft rates the bug 9.8 out of 10, which is right near the top of the industry danger scale.
Belgium's warning is worse than Microsoft's first note. On May 29, the Centre updated it to say the bug is being used right now. It also said a working attack can run with what Windows calls SYSTEM rights. SYSTEM is the highest power level on a Windows machine, with full control over everything on it. There is nothing above it. So an attacker who pulls this off does not get a small toehold. They get the whole server.
Microsoft CVE-2026-41089 record
What to patch first
Microsoft says the bug hits Windows Server versions from 2012 up to 2025. The oldest ones, Server 2012 and 2012 R2, only get the fix through a paid extended support plan, so check you are on the right path for those.
Domain controllers are not servers you reboot on a whim. If you break logins, you break everything that depends on them. So go in order. Patch the exposed and most important domain controllers first. Then watch your login traffic for anything odd. The attacks are real and happening now, so do not wait for next month's maintenance window. One weak login server can hand an attacker a clear shot at the rest of the network.
Microsoft CVE-2026-41089 record, Centre for Cybersecurity Belgium




