logo

CISA Warns of Microsoft Defender 0-Day Vulnerabilities Exploited in Attacks

ID: 9dd619a7-524a-5225-8cea-cd24d725e293

STIX ID: report--9dd619a7-524a-5225-8cea-cd24d725e293

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2026-05-22

Date Updated: 2026-05-22

Author: Abinaya

...
...

**CISA added two critical Microsoft Defender vulnerabilities (CVE-2026-45498 — DoS, and CVE-2026-41091 — symlink-based local privilege escalation) to its KEV catalog on May 20, 2026, citing evidence of active exploitation and requiring remediation by June 3, 2026 under BOD 22-01; organizations are urged to apply patches and mitigations immediately to prevent defense bypass and potential escalations.**

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.