logo

Microsoft Warns of Two Actively Exploited Defender Vulnerabilities

ID: 28a403ea-646d-5da4-8581-723dac63de27

STIX ID: report--28a403ea-646d-5da4-8581-723dac63de27

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2026-05-21

Date Updated: 2026-05-22

Author: [email protected] (The Hacker News)

...
...

Microsoft disclosed active exploitation of multiple Microsoft Defender vulnerabilities, including a local privilege escalation (CVE-2026-41091, CVSS 7.8) and a denial-of-service bug (CVE-2026-45498, CVSS 4.0); a separate heap-based buffer overflow (CVE-2026-45584, CVSS 8.1) was patched but not seen exploited. Microsoft released Defender platform updates to remediate the issues, and CISA added the actively exploited CVEs to its Known Exploited Vulnerabilities catalog, requiring federal agencies to apply fixes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.