Two critical Microsoft vulnerabilities are currently being actively exploited in the wild. With Patch Tuesday scheduled for tomorrow, June 9, businesses running Windows servers and Exchange should treat patching as urgent.
- CVE-2026-41089 – Windows Netlogon RCE: This vulnerability allows a remote attacker to execute code on your systems with no prior access or user interaction required. CISA has added it to its Known Exploited Vulnerabilities catalogue, confirming active real-world exploitation. Any Windows Server environment is at risk.
- CVE-2026-42897 – Exchange Server Spoofing (currently unpatched): Actively exploited against Exchange Server 2016, 2019, and Subscription Edition. Microsoft has classified this as critical but has not yet released a patch. Monitor Exchange environments closely for unusual activity until a fix is available.
- CVE-2026-41091 – Microsoft Defender Elevation of Privilege: Publicly known exploit code exists for this vulnerability, increasing the likelihood of it being incorporated into broader attack chains.
We recommend ensuring all Windows systems are patched immediately following tomorrow's Patch Tuesday release. For the unpatched Exchange vulnerability, increased monitoring is advised in the interim. Contact OzComm if you need assistance reviewing your exposure.