Belgium’s national cybersecurity authority, the Centre for Cybersecurity Belgium (CCB), warns that attackers are now exploiting a recently patched critical Windows Netlogon vulnerability in the wild. The issue, tracked as CVE-2026-41089, is a remote code execution (RCE) flaw affecting Windows Netlogon, the service and protocol used for authentication and security in Windows domain environments. According to the CCB, threat actors send specially crafted network requests to targeted systems that are running the Netlogon service, aiming to trigger the vulnerability and execute code remotely. The reports characterize CVE-2026-41089 as a stack-based buffer overflow that can be reached via network traffic, putting domain controllers and other machines that provide domain authentication at risk. Both outlets cite the CCB’s Friday advisory as the basis for the exploitation claim, emphasizing that the vulnerability has already been patched but is still being used by attackers. The guidance in the coverage centers on the fact that defenders should address the known flaw promptly to reduce exposure.