logo

Microsoft Patches Actively Exploited Defender Vulnerabilities Affecting Enterprise Systems

ID: 2a4fa527-d7fa-5273-8508-d5cb0a2878df

STIX ID: report--2a4fa527-d7fa-5273-8508-d5cb0a2878df

Feed Name: The Cyber Express

Threat Score
78/100

Date Published: 2026-05-22

Date Updated: 2026-07-20

Author: Ashish Khaitan

...
...

**Microsoft Defender actively exploited vulnerabilities** — The report describes active in-the-wild exploitation of CVE-2026-41091 (local privilege escalation, CVSS 7.8) and CVE-2026-45498 (denial-of-service, CVSS 4.0), notes an additional patched RCE (CVE-2026-45584), references researcher observations and possible ties to previously disclosed issues (RedSun/UnDefend), and highlights CISA adding the actively exploited CVEs to its KEV catalog with mitigation guidance and automatic Defender updates.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.