CISA Warns of Microsoft Defender 0-Day Vulnerabilities Exploited in Attacks
ID: 9dd619a7-524a-5225-8cea-cd24d725e293
STIX ID: report--9dd619a7-524a-5225-8cea-cd24d725e293
Feed Name: cybersecurityNews.com
Threat Score
**CISA added two critical Microsoft Defender vulnerabilities (CVE-2026-45498 — DoS, and CVE-2026-41091 — symlink-based local privilege escalation) to its KEV catalog on May 20, 2026, citing evidence of active exploitation and requiring remediation by June 3, 2026 under BOD 22-01; organizations are urged to apply patches and mitigations immediately to prevent defense bypass and potential escalations.**
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
