CVE-2026-72982: Critical Unauthenticated Netlogon RCE Puts Every Unpatched Domain Controller at Risk CVE-2026-72982, patched in Microsoft’s September 2026 security release, is a critical, unauthenticated remote code execution flaw in the Windows Netlogon... Sep 24, 2026 5 min read Active Directory / Security