Microsoft released out-of-band patches on May 21, 2026 to address two actively exploited zero-day vulnerabilities in Windows Defender. The company pushed the updates globally after confirming real-world attacks targeting the security software. CISA added both flaws to its Known Exploited Vulnerabilities catalog on May 20, 2026.
Two actively exploited zero-day vulnerabilities in Windows Defender patched globally on May 21, 2026
The first vulnerability, CVE-2026-41091, carries a CVSS score of 7.8 and allows attackers to escalate privileges to SYSTEM level. This flaw stems from improper link resolution during Defender scans. The second issue, CVE-2026-45498, has a CVSS rating of 4.0 and causes denial-of-service conditions against the protection engine. Attackers can exploit this weakness to block definition updates.
Microsoft resolved both issues in Malware Protection Engine version 1.1.26040.8 and Antimalware Platform version 4.18.26040.7. The vendor distributed these out-of-band patches directly to users on May 21, 2026. A third flaw, CVE-2026-45584, remains unconfirmed in active exploitation campaigns.
Security Week and BleepingComputer reported the details of the security update. Microsoft provided the technical specifications for the patched components. The National Vulnerability Database at nvd.nist.gov lists the severity scores for both disclosed vulnerabilities.



Discussion
0 comments
Log in to join the thread with a thoughtful take, question, or correction.