daily cyber × ai intelligence

index

tagged

[CVE-2026-41089]

2 editions · 2 items

June 24, 2026

  • CVE-2026-41089, a Windows Netlogon RCE via a CLDAP stack buffer overflow, now has a public PoC. A single crafted UDP packet to port 389 overflows a 528-byte stack buffer inside LSASS on any unpatched domain controller — no authentication required — currently demonstrated as a reliable DC crash/reboot (~60 seconds) with code-execution potential. Dark Web Informer. Patch DCs and restrict CLDAP exposure. · Offensive & Red Team

in Two Netlogon Flaws Hit Domain Controllers as FortiBleed Lands in Finland