logo

Microsoft Defender Zero-Day Vulnerabilities Actively Exploited in the Wild

ID: f5f1aa00-b7e1-52b3-8182-ca71a8c2ea4c

STIX ID: report--f5f1aa00-b7e1-52b3-8182-ca71a8c2ea4c

Feed Name: GBHackers

Threat Score
85/100

Date Published: 2026-05-21

Date Updated: 2026-05-21

Author: Mayura Kathir

...
...

Microsoft disclosed two actively exploited zero-day vulnerabilities in Microsoft Defender: CVE-2026-41091 is a local elevation-of-privilege bug (CVSS 7.8, CWE-59) that allows low-privileged attackers to gain high-level access without user interaction, and CVE-2026-45498 is a lower-severity local DoS (CVSS 4.0) that can disrupt Defender availability. Microsoft has issued fixes and organizations are urged to apply updates immediately, review logs for suspicious activity, and employ defense-in-depth controls such as EDR and least-privilege access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.