logo

Microsoft warns of new Defender zero-days exploited in attacks

ID: 25a1c029-e165-5faa-a402-0286a646f77c

STIX ID: report--25a1c029-e165-5faa-a402-0286a646f77c

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2026-05-21

Date Updated: 2026-05-21

Author: Sergiu Gatlan

...
...

Microsoft released patches for two actively exploited Microsoft Defender zero-day vulnerabilities — CVE-2026-41091 (privilege escalation to SYSTEM via improper link resolution) and CVE-2026-45498 (Denial-of-Service in the Defender Antimalware Platform). Customers are advised to ensure automatic updates are enabled and verify updated Malware Protection Engine/Antimalware Platform versions; CISA added both issues to its KEV catalog and mandated federal agencies remediate under BOD 22-01.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.