CVE-2026-41089: the Netlogon packet that reboots your domain controller
A pre-auth stack overflow in Windows Netlogon, CVSS 9.8, exploited in the wild. Here is what it actually does, why the popular Defender hunt watches the wrong port, and KQL that matches the real CLDAP attack path.