CISA Issues Alert on Exploited Microsoft Defender Zero-Day Vulnerabilities
ID: eb6269d8-8b77-567f-90f3-da89d0932d8f
STIX ID: report--eb6269d8-8b77-567f-90f3-da89d0932d8f
Feed Name: GBHackers
**Executive summary:** CISA warns of two Microsoft Defender zero-day vulnerabilities—CVE-2026-45498 (denial-of-service) and CVE-2026-41091 (link-following privilege escalation)—that have been added to the KEV and are confirmed to be actively exploited; organizations should apply Microsoft patches or mitigations immediately and follow BOD 22-01 guidance. The DoS can disable endpoint protection, the link-following bug can enable local privilege escalation, and combined exploitation could permit full compromise of affected systems.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
