A critical security flaw in Windows is being actively exploited by attackers right now, and any business running Windows servers needs to act.
- What it is: A vulnerability (CVE-2026-41089) in the Windows Netlogon service — the component that handles user logins across a business network — allows an attacker to take full control of a Windows server without needing a username or password.
- Who is affected: Any organisation running Windows Server (2016, 2019, 2022, or 2025) as a domain controller — the server that manages logins and user accounts.
- What the risk is: An attacker who exploits this flaw gains complete control of your network. They can create admin accounts, access all files, and move freely across every connected device. The severity rating is 9.8 out of 10.
- What to do: Apply the May 2026 Windows security updates immediately. If your business uses managed IT support, confirm with your provider that domain controllers have been patched. Do not delay — active exploitation has been confirmed.
If you are unsure whether your systems are up to date, contact your IT provider as a priority. Sources: Help Net Security, Microsoft Security Response Centre