Windows Netlogon Flaw Now Exploited
Windows Netlogon just got a critical remote code execution bug that attackers are already using in the wild.
CVE-2025-26633 lets remote attackers run code on domain controllers by sending crafted RPC requests over the Netlogon protocol. CVSS 9.0, actively exploited after the April patch.
Affects Windows Server 2016 through 2025 domain controllers. Any environment still running unpatched DCs faces direct remote takeover risk.
Belgium's national cyber authority issued the active exploitation warning on Friday.
