CVE-2026-41091Active Exploitation(microsoft / malware_protection_engine)

CRITICALCVSS 7.8 · HIGHCISA KEV

Exploitation observed; activity peaked at 45 mentions and remains active

Immediate actions

  • Patch microsoft malware_protection_engine systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally.

8.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-06-03. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-59

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • malware_protection_engine

Threat summary

  • Active exploitation appears in 86 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 121 mentions across 26 observed days

What's happening

  • Active exploitation reported across 86 signals
  • Exploit tool or code specified in 4 signals
  • PoC mentioned or linked in 5 signals
  • Patch or workaround mentioned in 71 signals
  • Technical details provided in 72 signals
  • General: 10 classified signals
  • Peaked 24d ago at 45 mentions (2026-05-21); latest day: 1
  • 121 total mentions across 26 days

Affected systems

Vendors
Products
malware_protection_engine

Deep dive

Activity timeline121 mentions / 26d
011233445Mentions · 2026-05-20: 6Mentions · 2026-05-21: 45Mentions · 2026-05-22: 14Mentions · 2026-05-23: 3Mentions · 2026-05-24: 4Mentions · 2026-05-25: 3Mentions · 2026-05-26: 4Mentions · 2026-05-27: 1Mentions · 2026-05-28: 2Mentions · 2026-05-29: 4Mentions · 2026-05-31: 1Mentions · 2026-06-01: 2Mentions · 2026-06-02: 3Mentions · 2026-06-03: 2Mentions · 2026-06-05: 4Mentions · 2026-06-06: 2Mentions · 2026-06-07: 7Mentions · 2026-06-10: 5Mentions · 2026-06-11: 1Mentions · 2026-06-12: 1Mentions · 2026-06-16: 2Mentions · 2026-06-17: 1Mentions · 2026-06-23: 1Mentions · 2026-07-07: 1Mentions · 2026-08-04: 1Mentions · 2026-09-08: 1PoC Mentioned / Linked · 2026-05-21: 3PoC Mentioned / Linked · 2026-06-10: 1PoC Mentioned / Linked · 2026-06-17: 1Exploit Tool / Code · 2026-05-21: 1Exploit Tool / Code · 2026-06-05: 2Exploit Tool / Code · 2026-06-10: 1Active Exploitation · 2026-05-20: 5Active Exploitation · 2026-05-21: 38Active Exploitation · 2026-05-22: 13Active Exploitation · 2026-05-23: 1Active Exploitation · 2026-05-25: 3Active Exploitation · 2026-05-26: 2Active Exploitation · 2026-05-27: 1Active Exploitation · 2026-05-28: 1Active Exploitation · 2026-05-29: 1Active Exploitation · 2026-06-02: 3Active Exploitation · 2026-06-03: 2Active Exploitation · 2026-06-05: 2Active Exploitation · 2026-06-06: 2Active Exploitation · 2026-06-07: 3Active Exploitation · 2026-06-10: 4Active Exploitation · 2026-06-12: 1Active Exploitation · 2026-06-16: 2Active Exploitation · 2026-06-23: 1Active Exploitation · 2026-08-04: 1Patch / Workaround · 2026-05-20: 4Patch / Workaround · 2026-05-21: 24Patch / Workaround · 2026-05-22: 9Patch / Workaround · 2026-05-23: 3Patch / Workaround · 2026-05-24: 4Patch / Workaround · 2026-05-25: 3Patch / Workaround · 2026-05-26: 2Patch / Workaround · 2026-05-27: 1Patch / Workaround · 2026-05-28: 1Patch / Workaround · 2026-06-01: 1Patch / Workaround · 2026-06-02: 2Patch / Workaround · 2026-06-03: 1Patch / Workaround · 2026-06-05: 2Patch / Workaround · 2026-06-06: 2Patch / Workaround · 2026-06-07: 5Patch / Workaround · 2026-06-10: 2Patch / Workaround · 2026-06-11: 1Patch / Workaround · 2026-06-16: 2Patch / Workaround · 2026-06-17: 1Patch / Workaround · 2026-07-07: 1Technical Details · 2026-05-20: 4Technical Details · 2026-05-21: 32Technical Details · 2026-05-22: 10Technical Details · 2026-05-23: 3Technical Details · 2026-05-24: 3Technical Details · 2026-05-25: 1Technical Details · 2026-05-26: 1Technical Details · 2026-05-27: 1Technical Details · 2026-05-29: 1Technical Details · 2026-06-03: 2Technical Details · 2026-06-05: 1Technical Details · 2026-06-06: 2Technical Details · 2026-06-07: 3Technical Details · 2026-06-10: 4Technical Details · 2026-06-12: 1Technical Details · 2026-06-16: 2Technical Details · 2026-06-17: 105-2005-2205-2405-2605-2805-3106-0206-0506-0706-1106-1606-2308-0409-08
Signal classification7 categories
Active Exploitation
7158.7%
Patch
2924.0%
General
108.3%
Disclosure
86.6%
Exploit
10.8%
Discloasure
10.8%
Referenced assets72 URLs
By indicator
Classification over time
DateTotalLabels
2026-05-206
Active Exploitation4Disclosure1Patch1
2026-05-2145
Active Exploitation32Disclosure3Exploit1General2Patch7
2026-05-2214
Active Exploitation11Patch3
2026-05-233
Patch3
2026-05-244
Patch4
2026-05-253
Active Exploitation1Patch2
2026-05-264
Active Exploitation1General1Patch2
2026-05-271
Active Exploitation1
2026-05-282
Active Exploitation1Discloasure1
2026-05-294
Active Exploitation1Disclosure1General2
2026-05-311
General1
2026-06-012
General1Patch1
2026-06-023
Active Exploitation2General1
2026-06-032
Active Exploitation2
2026-06-054
Active Exploitation2Disclosure1General1
2026-06-062
Active Exploitation2
2026-06-077
Active Exploitation2Disclosure1Patch4
2026-06-105
Active Exploitation4Disclosure1
2026-06-111
Patch1
2026-06-121
Active Exploitation1
2026-06-162
Active Exploitation2
2026-06-171
PoC1
2026-06-231
Active Exploitation1
2026-07-071
Patch1
2026-08-041
Active Exploitation1
2026-09-081
General1
Full discourse20 posts
  • The Hacker News@TheHackersNews
    Active Exploitation

    🚨 Microsoft warns two Defender vulnerabilities are being actively exploited in the wild. https://thehackernews.com/2026/05/microsoft-warns-of-two-actively.html 🔸 CVE-2026-41091 could allow attackers to gain SYSTEM privileges locally. 🔸 CVE-2026-45498 is a denial-of-service flaw impacting Defender. CISA added both to KEV with a June 3, 2026 patch deadline.

    Post summary

    Microsoft alerts that two Defender CVEs are actively exploited in the wild and have been added to CISA KEV, with a patch deadline set for June 3, 2026.

    3122435710233.9K
    1.9M followersView on X
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    General

    مايكروسفت تهدد برفع قضايا على الباحث الامني Nightmare Eclipse بعد مابهدلهم ونشر 6 ثغرات 0day (RedSun) CVE-2026-41091 (UnDefend) CVE-2026-45498 (BlueHammer) CVE-2026-33825 (YellowKey) CVE-2026-45585 (GreenPlasma) (MiniPlasma) مو من صالحهم يعادون مجتمع الباحثين بهالطريقه https://t.co/bFoufGGRYW

    Post summary

    Microsoft is threatening lawsuits against researcher Nightmare Eclipse for publishing six zero‑day CVEs, but the post contains no technical details, PoC references, or evidence of widespread exploitation.

    581453522.4K
    50.0K followersView on X
  • elhacker.NET@elhackernet
    Active Exploitation

    Microsoft alerta sobre dos vulnerabilidades de Defender que están siendo explotadas Escalada de privilegios (CVE-2026-41091) y denegación de servicio (CVE-2026-45498) https://blog.elhacker.net/2026/05/microsoft-alerta-sobre-dos.html

    Post summary

    Microsoft reports that CVE‑2026‑41091 (privilege‑escalation) and CVE‑2026‑45498 (DoS) in Windows Defender are actively being exploited, with no patches or PoC details provided.

    115058113.2K
    141.0K followersView on X
  • Fabian Bader@fabian_bader
    Patch

    The latest Windows Antivirus Platform 4.18.26040.7 and Engine 1.1.26040.8 fix three security issues, two of them already exploited and publicly available... CVE-2026-41091 (RedSun) CVE-2026-45498 (UnDefend) CVE-2026-45584 (???) #MDE #MDAV https://t.co/yDSi6HaTZK

    Post summary

    Microsoft released a patch for its Windows Antivirus Platform and Engine to fix three CVEs, noting that two are already being exploited in the wild.

    39123614.2K
    10.4K followersView on X
  • Azubuike Ibe@ai_dev_official
    Active Exploitation

    Two Microsoft Defender vulnerabilities were disclosed yesterday. Both are already being exploited. CVE-2026-41091 is a local privilege escalation flaw caused by improper link resolution. An attacker with local access can use it to gain elevated system privileges. Microsoft and CISA have both confirmed active exploitation in the wild. CVE-2026-45498 is a Denial-of-Service vulnerability targeting Defender components. Also confirmed exploited. Also added to CISA’s Known Exploited Vulnerabilities catalog on May 20. These are not theoretical. They are in the KEV list. That means attackers are using them now. The exploitation scope is still being assessed. No major vendor has published confirmed telemetry on large-scale chained campaigns yet. But the window between disclosure and weaponisation has been closing for years. Waiting for a full incident report before patching is how organisations end up in the incident report. Here is what you should do today. Update your Defender platform and engine versions immediately. Check your local admin and service account permissions. Enable behavioral monitoring and EDR telemetry if it is not already on. Audit your Defender exclusion policies. Watch for abnormal Defender service activity. Default Defender configurations were not built for a threat landscape where CVEs hit the KEV list the day after disclosure. Layered controls are not optional in 2026. My name is Azubuike Ibe and I write about threats that are already moving before most people have read the advisory. Share this with a developer or sysadmin on your team who has not patched yet. It may save them a very bad week. #Cybersecurity #MicrosoftDefender #WindowsSecurity #DevSecOps #AppSec

    Post summary

    The message alerts that two Microsoft Defender CVEs are actively exploited, urges immediate patching and hardening, and highlights the urgency of addressing the vulnerabilities.

    03077137
    1.5K followersView on X
  • ChainPatrol@ChainPatrol
    Patch

    🚨 Microsoft patched two Defender zero-days (CVE-2026-41091 & CVE-2026-45498) — one escalates a low-privileged attacker to SYSTEM level (local exploit, no user interaction needed), the other causes a denial-of-service. Both actively exploited; CISA added both to its KEV catalog. Most systems auto-update, but verify your Defender engine is on 1.1.26040.8+. https://www.bleepingcomputer.com/news/security/microsoft-warns-of-new-defender-zero-days-exploited-in-attacks/

    Post summary

    Microsoft has issued patches for two Defender zero-day vulnerabilities (CVE-2026-41091 and CVE-2026-45498) that are currently being actively exploited; users should ensure their Defender engine is updated to version 1.1.26040.8 or newer.

    040101321
    5.1K followersView on X
  • yousukezan@yousukezan
    PoC

    Microsoft Defenderのゼロデイ脆弱性「RoguePlanet」が公開され、SYSTEM権限の取得が可能になることが明らかになった。Microsoftは現在修正プログラムを開発中で、CVE-2026-50656として追跡している。 Microsoftはこの問題を権限昇格の脆弱性と説明しており、CVSSスコアは7.8。Microsoft Malware Protection Engineに存在し、同社は「高品質なセキュリティ更新プログラムの提供に向けて作業している」としている。 RoguePlanetは研究者のChaotic Eclipse(Nightmare-Eclipse)が先週公開した。公開されたPoCは競合状態(Race Condition)を悪用するもので、成功するとSYSTEM権限のシェルを取得できる。研究者によると成功率は環境によって異なるが、一部環境では100%の成功率を確認したという。 さらに研究者は、リアルタイム保護の有効・無効に関係なくPoCが動作すると説明しており、Defenderのパッシブモードでも影響する可能性があるとしている。 Microsoftは公開当初から脆弱性の有効性と影響範囲を調査していた。Chaotic Eclipseが公開したDefender関連の脆弱性は今回で4件目となり、過去のBlueHammer(CVE-2026-33825)、UnDefend(CVE-2026-45498)、RedSun(CVE-2026-41091)はすでに修正されている。 https://thehackernews.com/2026/06/microsoft-confirms-rogueplanet-defender_02022423645.html

    Post summary

    A newly disclosed Windows Defender privilege‑escalation zero‑day (CVE‑2026‑50656) has a publicly released PoC that uses a race condition to gain SYSTEM rights, while Microsoft works on a patch.

    020821.4K
    14.8K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    Microsoft has patched a critical privilege escalation flaw (CVE-2026-41091) in Defender. Verify your Anti-malware version is 4.18.26040.7 or later today. #MicrosoftDefender #Cybersecurity #PatchTuesday #CVE202641091 #WindowsSecurity #Infosec #SystemAdmin https://meterpreter.org/urgent-patch-microsoft-defender-update-fixes-critical-system-level-privilege-escalation-flaw/ https://t.co/nZA1KlpzCX

    Post summary

    The tweet announces the Microsoft Defender patch for CVE-2026-41091 and advises users to update, but does not discuss PoCs, exploits, or active attacks.

    02071550
    12.5K followersView on X
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(5/20追加) 🛡️No.1594 CVE-2008-4250 Microsoft Windows Buffer Overflow Vulnerability ==================================== ✅概要 ・深刻度:緊急 9.8 (CVSS Base) / CISA-ADP ・種別:バッファエラー (CWE-119) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Microsoft Windows の Server service において、細工された RPC リクエストによりパス正規化処理中にオーバーフローが発生し、リモートから任意のコード実行をされる恐れがあります。 ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:低 ✅攻撃前提条件 ・影響を受ける Windows Server service が稼働していること。 ・攻撃者が対象へネットワーク越しに到達可能であること。 ・認証は不要。 ✅悪用時影響 ・リモートで任意のコードを実行される ・影響を受けるシステムを完全に制御される ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:未確認 ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2008-4250 https://learn.microsoft.com/ja-jp/security-updates/securitybulletins/2008/ms08-067 🛡️No.1595 CVE-2009-1537 Microsoft DirectX NULL Byte Overwrite Vulnerability =================================== ✅概要 ・深刻度:重要 8.8 (CVSS Base) / CISA-ADP ・種別:NULL バイトまたは NULL キャラクタの不適切な無害化 (CWE-158) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Microsoft DirectX の DirectShow に含まれる QuickTime Movie Parser Filter において、細工された QuickTime メディアファイルにより任意のコード実行をされる恐れがあります。 ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:中 ✅攻撃前提条件 ・影響を受ける DirectX/Windows 環境が稼働していること。 ・攻撃者が細工された QuickTime メディアファイルを対象へ到達させること。 ・利用者が当該ファイルを処理すること。 ✅悪用時影響 ・リモートで任意のコードを実行される ・細工されたメディアファイルの処理によりシステムが侵害される ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:確認済み。Microsoft は、当時このエクスプロイトコードを使用した限定的なアクティブ攻撃を認識していると報告。 ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2009-1537 https://learn.microsoft.com/ja-jp/security-updates/securityadvisories/2009/971778 🛡️No.1596 CVE-2009-3459 Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability ==================================== ✅概要 ・深刻度:重要 8.8 (CVSS Base) / CISA-ADP ・種別:ヒープベースのバッファオーバーフロー (CWE-122) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Adobe Reader および Acrobat において、細工された PDF の処理によりメモリ破損が発生し、リモートで任意コードを実行される恐れがあります。 ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:中 ✅攻撃前提条件 ・影響を受ける Adobe Reader または Acrobat が稼働していること。 ・攻撃者が細工された PDF ファイルを対象へ到達させること。 ・利用者が当該 PDF を開くこと。 ✅悪用時影響 ・リモートで任意のコードを実行される ・PDF 処理時のメモリ破損によりシステムを侵害される✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:未確認 ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2009-3459 http://blogs.adobe.com/psirt/2009/10/adobe_reader_and_acrobat_issue_1.html 🛡️No.1597 CVE-2010-0249 Microsoft Internet Explorer Use-After-Free Vulnerability ✅概要 ・深刻度:重要 8.8 (CVSS Base) / NVD ・種別:解放済みメモリの使用 (CWE-416) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Microsoft Internet Explorer 6/7/8 における use-after-free の脆弱性が存在。削除済みオブジェクトに関連するポインタへアクセスさせることで、リモートで任意コードを実行される恐れがあります。 ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:中 ✅攻撃前提条件 ・影響を受ける Internet Explorer が稼働していること。 ・攻撃者が細工された Web ページへ利用者を誘導できること。 ・利用者が当該 Web ページを表示すること。 ✅悪用時影響 ・リモートで任意のコードを実行される ・メモリ内オブジェクトの不適切な取り扱いによりブラウザ経由で侵害される ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:未確認 ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2010-0249 https://learn.microsoft.com/ja-jp/security-updates/securitybulletins/2010/ms10-002 🛡️No.1598 CVE-2010-0806 Microsoft Internet Explorer Use-After-Free Vulnerability ✅概要 ・深刻度:重要 8.8 (CVSS Base) / CISA-ADP ・種別:解放済みメモリの使用 (CWE-416) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Internet Explorer の Peer Objects component(iepeers.dll)における use-after-free の脆弱性が存在。オブジェクト削除後の無効ポインタ参照により、リモートで任意コードを実行される恐れがあります。 ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:中 ✅攻撃前提条件 ・影響を受ける Internet Explorer が稼働していること。 ・攻撃者が細工された Web ページへ利用者を誘導できること。 (Microsoft Learn) ・利用者が当該 Web ページを表示すること。 ✅悪用時影響 ・リモートで任意のコードを実行される ・オブジェクト解放後の不正参照によりブラウザ経由で侵害される ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:未確認 ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2010-0806 https://learn.microsoft.com/ja-jp/security-updates/securitybulletins/2010/ms10-018 🛡️No.1599 CVE-2026-41091 Microsoft Defender Elevation of Privilege Vulnerability =================================== ✅概要 ・深刻度:重要 7.8 (CVSS Base) / Microsoft Corporation ・種別:リンク解釈の問題 (CWE-59) ・CVSS:CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Microsoft Defender における link following の脆弱性が存在。認証済みの攻撃者により、ローカル上で権限昇格される恐れがあります。 ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:高 ✅攻撃前提条件 ・影響を受ける Microsoft Malware Protection Engine が稼働していること。 ・攻撃者がローカルで認証済み権限を有していること。 ・ローカルで悪用可能な環境であること。 ✅悪用時影響 ・ローカルで権限昇格される ・機密性、完全性、可用性に高い影響が生じる ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:未確認 ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2026-41091 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41091 🛡️No.1600 CVE-2026-45498 Microsoft Defender Denial of Service Vulnerability ✅概要 ・深刻度:重要 7.5 (CVSS Base) / NVD ・種別:リソースの枯渇 (CWE-400) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Microsoft Defender におけるサービス運用妨害の脆弱性が存在。 ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:低 ✅攻撃前提条件 ・影響を受ける Microsoft Defender Antimalware Platform が稼働していること。 ・NVD 採点上、攻撃者がネットワーク越しに到達可能であること。 ・認証は不要。 ✅悪用時影響 ・サービス運用妨害により可用性へ高い影響が生じる ・Microsoft Defender の動作停止または機能阻害につながる ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:未確認 ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2026-45498 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45498 https://www.cisa.gov/news-events/alerts/2026/05/20/cisa-adds-seven-known-exploited-vulnerabilities-catalog #vulnerability

    Post summary

    The post announces CISA’s addition of seven known‑exploited vulnerabilities to its KEV catalog, detailing each CVE’s severity, technical nature, and active exploitation status, with links to vendor patch advisories.

    020626.3K
    43.9K followersView on X
  • DC3 DCISE@DC3DCISE
    Active Exploitation

    An actively exploited flaw in Microsoft Defender (CVE-2026-41091) is granting attackers full system-level privileges. Visit @TheRecord_Media for details on how you can secure endpoint protections now.

    Post summary

    The post claims CVE-2026-41091 is actively exploited to give attackers system‑level privileges, but offers no technical specifics, exploit code, or patch details.

    13130323
    737 followersView on X
  • Mr.Rabbit@01ra66it
    Active Exploitation

    【Microsoft Defenderの実悪用ゼロデイ2件、CISA KEVに追加】 Microsoft DefenderのCVE-2026-41091とCVE-2026-45498が実悪用されています。 前者はローカル権限昇格によりSYSTEM権限取得につながる可能性があり、後者はDefenderのDoSを引き起こす脆弱性です。 初期侵入済み端末で悪用されると、防御機能の妨害、資格情報窃取、横展開、ランサムウェア展開までの足場になり得ます。 自動更新前提の環境でも、隔離端末、VDI、長期間停止端末、管理外端末では更新漏れを確認すべきです。 Defenderのエンジン/Platformバージョン、保護更新失敗、SYSTEM権限での不審プロセス生成を重点的に確認してください。 #MicrosoftDefender #CVE #KEV #ZeroDay #WindowsSecurity #SOC #ThreatHunting https://www.helpnetsecurity.com/2026/05/21/microsoft-defender-vulnerabilities-cve-2026-41091-cve-2026-45498/

    Post summary

    The post reports that Microsoft Defender CVE-2026-41091 and CVE-2026-45498 are being actively exploited in the wild, with potential for privilege escalation and denial-of-service attacks.

    00032503
    3.7K followersView on X
  • CiberBaur@BotBauR
    Active Exploitation

    Acaba de confirmarse: Microsoft Defender tiene dos vulnerabilidades explotadas en el mundo real, identificadas como CVE-2026-41091 y CVE-2026-45498. Microsoft Defender es el producto afectado. La vulnerabilidad CVE-2026-41091 permite la elevación de privilegios local. Estas vulnerabilidades pueden ser explotadas por atacantes. Es importante que los administradores de sistemas revisen sus configuraciones de seguridad. ¿Hay parche? No se menciona. ¿Estás en riesgo? Revisa esto: asegúrate de que tus sistemas estén actualizados. #CiberseguridadMX #Ransomware #CVE https://www.helpnetsecurity.com/2026/05/21/microsoft-defender-vulnerabilities-cve-2026-41091-cve-2026-45498/

    Post summary

    The post confirms that CVE‑2026‑41091 (local privilege escalation) and CVE‑2026‑45498 in Microsoft Defender are being actively exploited, but offers no PoC, exploit code, patch, or detailed technical breakdown beyond the type of privilege escalation.

    0102181
    460 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    00:00 UTC: CVE-2026-41091 disclosed. CISA: CVE-2026-41091 added to Known Exploited Vulnerabilities — Microsoft Defender Status: ✅ Confirmed exploited in the wild Date added: 2026-05-20 Required action: Apply mitigations per vendor instructions, follow applicable BOD…

    Post summary

    The post confirms that CVE-2026-41091 is actively exploited in the wild and urges users to apply vendor mitigations.

    1001143
    258 followersView on X
  • Clone Systems@CloneSystemsInc
    Active Exploitation

    Vulnerability Alert — Microsoft Defender Microsoft disclosed two actively exploited Defender vulnerabilities now added to CISA’s KEV catalog. • CVE-2026-41091 (CVSS 7.8) — Privilege escalation to SYSTEM • CVE-2026-45498 (CVSS 4.0) — Denial of Service Organizations should verify Defender platform updates and ensure systems are running the latest protection engine versions. #CyberSecurity #VulnerabilityAlert #MicrosoftDefender #PatchNow

    Post summary

    Microsoft has identified two actively exploited Microsoft Defender vulnerabilities, CVE‑2026‑41091 and CVE‑2026‑45498, and urges organizations to apply the latest updates to mitigate the risks.

    0003073
    256 followersView on X
  • Upwind Security MDR@UpwindMDR
    Active Exploitation

    🚨 Microsoft reports two actively exploited vulnerabilities in Microsoft Defender (CVE-2026-41091)(CVE-2026-45498). (CVE-2026-41091) Microsoft Defender Privilege EscalationImproper link resolution before file access ('link following') allows an authorized local attacker to elevate privileges and gain SYSTEM level access. (CVE-2026-45498) Microsoft Defender Denial of Service A denial-of-service vulnerability that can disrupt Microsoft Defender operations. Both vulnerabilities are actively exploited in the wild and added to CISA KEV catalog. Fixed in Microsoft Defender Antimalware Platform versions 1.1.26040.8 and 4.18.26040.7. Affected: Microsoft Defender (all active installations)

    Post summary

    Microsoft reported two actively exploited Defender vulnerabilities, detailing their nature and providing patch information.

    00030113
    255 followersView on X
  • Help Net Security@helpnetsecurity
    Active Exploitation

    Microsoft Defender vulnerabilities exploited in the wild (CVE-2026-41091, CVE-2026-45498) - https://www.helpnetsecurity.com/2026/05/21/microsoft-defender-vulnerabilities-cve-2026-41091-cve-2026-45498/ - @Microsoft @MsftSecIntel #MicrosoftDefender #Vulnerability #VulnerabilityDisclosure #Windows #Cybersecurity #CybersecurityNews https://t.co/MPKZmjCuBz

    Post summary

    The tweet announces that Microsoft Defender CVE-2026-41091 and CVE-2026-45498 are being actively exploited in the wild, with no technical details or mitigation information provided.

    01020388
    60.1K followersView on X
  • كاسبر سكاي@KasperskyDev
    Active Exploitation

    ⚠️ ثغرة تصعيد امتيازات في Microsoft Defender تحت استغلال فعلي تمنح المهاجم صلاحيات SYSTEM، أضافتها CISA لقائمة KEV المعرّف : CVE-2026-41091 درجة الخطورة : 7.8 (CVSS) - High الحل : Update engine to 1.1.26040.8 #CVE #Microsoft #CyberSecurity #CVE202641091

    Post summary

    CVE-2026-41091 is a privilege‑escalation flaw in Microsoft Defender that is actively exploited; users should update to engine 1.1.26040.8 to mitigate.

    11000242
    40.0K followersView on X
  • NEWSTECNICAS | Tecnología, IA y Gaming.@newstecnicas
    Patch

    🚨 #Vulnerabilidad crítica de escalada de privilegios en #Microsoft #Defender (CVE-2026-41091 / CVE-2026-45498) (+MITIGACIÓN) https://www.newstecnicas.com/2026/05/vulnerabilidad-critica-de-escalada-de.html

    Post summary

    The tweet announces critical privilege‑escalation vulnerabilities in Microsoft Defender (CVE‑2026‑41091 and CVE‑2026‑45498) and references mitigation steps.

    0101040
    1.2K followersView on X
  • kimiyoya Teck Note@KimiyoyaN39483
    General

    Windows Defenderに脆弱性😨! 「CVE-2026-41091って何?自分のPC大丈夫?」という初心者向けに、わかりやすくまとめました💻 まず確認したい対策を丁寧に解説しています👇 https://kimiyoya.com/windows-defender-cve-2026-41091/ #Windows11 #Windows10 #MicrosoftDefender #WindowsDefender #セキュリティ #脆弱性

    Post summary

    The post merely introduces CVE-2026-41091 with a link to a beginner‑friendly article, offering no PoC, exploit detail, patch information, or evidence of active exploitation.

    00020126
    19 followersView on X
  • ✨_geeknik_//✨@geeknik
    Patch

    Your antivirus is now the exploit. Defender's own remediation engine writes SYSTEM-level files to attacker-chosen paths via a symlink race. Check MPE version 1.1.26040.8 manually. Auto-update is a faith-based control. https://www.decryptiondigest.com/blog/cve-2026-41091-defender-zero-day-patch

    Post summary

    The text highlights a critical symlink race vulnerability in Microsoft Defender that allows SYSTEM-level file writes, advising users to manually verify they have version 1.1.26040.8 due to unreliable auto-updates.

    00011244
    20.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftmalware_protection_engine---

Explore more