Skip to content

CVE-2026-72982

Windows Netlogon stack-based buffer overflow lets unauthorised attackers execute code over a network (CVE-2026-72982)

Critical 9.8 Vendor: Microsoft Published

Microsoft Windows Netlogon has a critical stack-based buffer overflow (CVE-2026-72982). An unauthorised attacker can execute code over a network without user interaction. The September 2026 security update provides fixed builds; apply them to affected Windows clients and servers.

What happened

Microsoft describes CVE-2026-72982 as a stack-based buffer overflow in Windows Netlogon. An unauthorised attacker can reach the flaw over a network without credentials and without user interaction, and can use it to execute code. Microsoft rates the vulnerability critical with a CVSS 3.1 score of 9.8; the vector indicates a network attack vector, low attack complexity, no privileges required, no user interaction, and high impact on confidentiality, integrity and availability. The issue is classed as CWE-121.

Microsoft has not published a workaround in its September 2026 advisory. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalogue, and the sources used for this advisory record it as not publicly disclosed and with no current exploitation.

Who is affected

Microsoft lists affected version ranges for Windows 10 Version 1607, 1809, 21H2 and 22H2; Windows 11 versions 23H2, 24H2, 25H2 and 26H1; and Windows Server 2012 and 2012 R2. The September 2026 update also lists fixed builds for Windows Server 2016, 2019, 2022 and 2025, including Server Core installations where named. Domain controllers and any systems that expose Netlogon to a network are the priority, because the flaw can be reached over a network without credentials.

What to do now

  1. Apply Microsoft's September 2026 security update. Fixed builds and KB numbers include:
  • 10.0.14393.9512 (KB5123099) for Windows 10 Version 1607 and Windows Server 2016
  • 10.0.17763.9245 (KB5122876) for Windows 10 Version 1809 and Windows Server 2019
  • 10.0.19044.7725 and 10.0.19045.7725 (KB5122878) for Windows 10 Version 21H2 and 22H2
  • 10.0.22631.7582 (KB5122880) for Windows 11 23H2
  • 10.0.26100.9445 and 10.0.26200.9445 (KB5124008) for Windows 11 24H2 and 25H2
  • 10.0.28000.2954 (KB5124012) for Windows 11 26H1
  • 6.2.9200.26349 (KB5123065) for Windows Server 2012 and Server Core
  • 6.3.9600.23398 (KB5123066) for Windows Server 2012 R2 and Server Core
  • 10.0.20348.5622 (KB5122882) for Windows Server 2022
  • 10.0.26100.33438 (KB5122871) for Windows Server 2025 and Server Core
  1. Prioritise domain controllers and any system where Netlogon is reachable from untrusted network segments.
  1. Microsoft has not published a workaround. Until patched, restrict network access to domain controllers and the Netlogon service to trusted management networks.
  1. After patching, watch domain controllers for unexpected code execution or authentication activity. No vendor indicators of compromise are published in the advisory.

Beyond the patch

Beyond this update, a network-reachable, no-credential code execution flaw in a core Windows service is a signal to know what is exposed and to watch for what follows. Virtual CISO Services (vCISO) helps identify reachable services and open ports before the next bulletin lands, and Managed Detection & Response (MDR) monitors EDR and SIEM telemetry for the code execution, privilege escalation or credential abuse that a flaw like this can leave behind.

Affected and fixed versions

ProductAffectedFixed in
Windows 10 Version 160710.0.14393.0 – < 10.0.14393.951210.0.14393.9512
Windows 10 Version 180910.0.17763.0 – < 10.0.17763.924510.0.17763.9245
Windows 10 Version 21H210.0.19044.0 – < 10.0.19044.772510.0.19044.7725
Windows 10 Version 22H210.0.19045.0 – < 10.0.19045.772510.0.19045.7725
Windows 11 version 23H210.0.22631.0 – < 10.0.22631.758210.0.22631.7582
Windows 11 Version 23H210.0.22631.0 – < 10.0.22631.758210.0.22631.7582
Windows 11 Version 24H210.0.26100.0 – < 10.0.26100.944510.0.26100.9445
Windows 11 Version 25H210.0.26200.0 – < 10.0.26200.944510.0.26200.9445
Windows 11 version 26H110.0.28000.0 – < 10.0.28000.295410.0.28000.2954
Windows Server 20126.2.9200.0 – < 6.2.9200.263496.2.9200.26349
(Server Core installation) 6.2.9200.26349
R2 6.3.9600.23398
R2 (Server Core installation) 6.3.9600.23398
Windows Server 2012 (Server Core installation)6.2.9200.0 – < 6.2.9200.263496.2.9200.26349
Windows Server 2012 R26.3.9600.0 – < 6.3.9600.233986.3.9600.23398
(Server Core installation) 6.3.9600.23398

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.