CVE-2026-72982
Windows Netlogon stack-based buffer overflow lets unauthorised attackers execute code over a network (CVE-2026-72982)
Microsoft Windows Netlogon has a critical stack-based buffer overflow (CVE-2026-72982). An unauthorised attacker can execute code over a network without user interaction. The September 2026 security update provides fixed builds; apply them to affected Windows clients and servers.
What happened
Microsoft describes CVE-2026-72982 as a stack-based buffer overflow in Windows Netlogon. An unauthorised attacker can reach the flaw over a network without credentials and without user interaction, and can use it to execute code. Microsoft rates the vulnerability critical with a CVSS 3.1 score of 9.8; the vector indicates a network attack vector, low attack complexity, no privileges required, no user interaction, and high impact on confidentiality, integrity and availability. The issue is classed as CWE-121.
Microsoft has not published a workaround in its September 2026 advisory. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalogue, and the sources used for this advisory record it as not publicly disclosed and with no current exploitation.
Who is affected
Microsoft lists affected version ranges for Windows 10 Version 1607, 1809, 21H2 and 22H2; Windows 11 versions 23H2, 24H2, 25H2 and 26H1; and Windows Server 2012 and 2012 R2. The September 2026 update also lists fixed builds for Windows Server 2016, 2019, 2022 and 2025, including Server Core installations where named. Domain controllers and any systems that expose Netlogon to a network are the priority, because the flaw can be reached over a network without credentials.
What to do now
- Apply Microsoft's September 2026 security update. Fixed builds and KB numbers include:
- 10.0.14393.9512 (KB5123099) for Windows 10 Version 1607 and Windows Server 2016
- 10.0.17763.9245 (KB5122876) for Windows 10 Version 1809 and Windows Server 2019
- 10.0.19044.7725 and 10.0.19045.7725 (KB5122878) for Windows 10 Version 21H2 and 22H2
- 10.0.22631.7582 (KB5122880) for Windows 11 23H2
- 10.0.26100.9445 and 10.0.26200.9445 (KB5124008) for Windows 11 24H2 and 25H2
- 10.0.28000.2954 (KB5124012) for Windows 11 26H1
- 6.2.9200.26349 (KB5123065) for Windows Server 2012 and Server Core
- 6.3.9600.23398 (KB5123066) for Windows Server 2012 R2 and Server Core
- 10.0.20348.5622 (KB5122882) for Windows Server 2022
- 10.0.26100.33438 (KB5122871) for Windows Server 2025 and Server Core
- Prioritise domain controllers and any system where Netlogon is reachable from untrusted network segments.
- Microsoft has not published a workaround. Until patched, restrict network access to domain controllers and the Netlogon service to trusted management networks.
- After patching, watch domain controllers for unexpected code execution or authentication activity. No vendor indicators of compromise are published in the advisory.
Beyond the patch
Beyond this update, a network-reachable, no-credential code execution flaw in a core Windows service is a signal to know what is exposed and to watch for what follows. Virtual CISO Services (vCISO) helps identify reachable services and open ports before the next bulletin lands, and Managed Detection & Response (MDR) monitors EDR and SIEM telemetry for the code execution, privilege escalation or credential abuse that a flaw like this can leave behind.
Affected and fixed versions
| Product | Affected | Fixed in |
|---|---|---|
| Windows 10 Version 1607 | 10.0.14393.0 – < 10.0.14393.9512 | 10.0.14393.9512 |
| Windows 10 Version 1809 | 10.0.17763.0 – < 10.0.17763.9245 | 10.0.17763.9245 |
| Windows 10 Version 21H2 | 10.0.19044.0 – < 10.0.19044.7725 | 10.0.19044.7725 |
| Windows 10 Version 22H2 | 10.0.19045.0 – < 10.0.19045.7725 | 10.0.19045.7725 |
| Windows 11 version 23H2 | 10.0.22631.0 – < 10.0.22631.7582 | 10.0.22631.7582 |
| Windows 11 Version 23H2 | 10.0.22631.0 – < 10.0.22631.7582 | 10.0.22631.7582 |
| Windows 11 Version 24H2 | 10.0.26100.0 – < 10.0.26100.9445 | 10.0.26100.9445 |
| Windows 11 Version 25H2 | 10.0.26200.0 – < 10.0.26200.9445 | 10.0.26200.9445 |
| Windows 11 version 26H1 | 10.0.28000.0 – < 10.0.28000.2954 | 10.0.28000.2954 |
| Windows Server 2012 | 6.2.9200.0 – < 6.2.9200.26349 | 6.2.9200.26349 (Server Core installation) 6.2.9200.26349 R2 6.3.9600.23398 R2 (Server Core installation) 6.3.9600.23398 |
| Windows Server 2012 (Server Core installation) | 6.2.9200.0 – < 6.2.9200.26349 | 6.2.9200.26349 |
| Windows Server 2012 R2 | 6.3.9600.0 – < 6.3.9600.23398 | 6.3.9600.23398 (Server Core installation) 6.3.9600.23398 |