logo

Microsoft Defender vulnerabilities exploited in the wild (CVE-2026-41091, CVE-2026-45498)

ID: 162a6777-c9a4-51f9-9439-1de8598a1a22

STIX ID: report--162a6777-c9a4-51f9-9439-1de8598a1a22

Feed Name: Help Net Security

Threat Score
75/100

Date Published: 2026-05-21

Date Updated: 2026-05-21

Author: Zeljka Zorz

...
...

Microsoft Defender has multiple publicly disclosed vulnerabilities being exploited in the wild: CVE-2026-41091 (local privilege elevation to SYSTEM) and CVE-2026-45498 (Denial-of-Service affecting the antimalware platform). Microsoft issued fixes for the affected Malware Protection Engine and Antimalware Platform versions, CISA added the flaws to its KEV catalog requiring federal entities to patch or stop using the products, and several proof-of-concept exploits (BlueHammer, RedSun, UnDefend, YellowKey) have been released and observed by responders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.