إبراهيم بوحيمد | Ibrahim Buhaimed[verified]@buhaimediDisclosure
The tweet reports that Microsoft threatens to sue security researcher Nightmare Eclipse after the researcher disclosed six zero-day vulnerabilities (CVE-2026-41091, CVE-2026-45498, CVE-2026-33825, CVE-2026-45585 and two unnamed).
Azubuike Ibe[verified]@ai_dev_officialActive Exploitation
The post reports that two Microsoft Defender vulnerabilities (LLPE and DoS) are actively being exploited in the wild and urges immediate patching and security hardening.
yousukezan[verified]@yousukezanPoC
Microsoft Defender vulnerability CVE-2026-50656 has a publicly disclosed PoC demonstrating SYSTEM privilege escalation through a race condition; Microsoft is developing a fix, but no evidence of active exploitation exists.
piyokango[verified]@piyokangoPatch
The post announces seven CVEs added to CISA's catalog, detailing their severity, technical nature, and linking to vendor patches, with a note that CVE-2009-1537 has confirmed active exploitation.
Mr.Rabbit[verified]@01ra66itActive Exploitation
Microsoft Defender CVE-2026-41091 and CVE-2026-45498 are actively exploited, exposing systems to privilege escalation, DoS, credential theft, lateral movement, and ransomware; defenders should verify update status and monitor for suspicious processes.
CiberBaur[verified]@BotBauRActive Exploitation
Microsoft Defender versions have two CVEs (CVE-2026-41091 and CVE-2026-45498) that are currently being exploited in the wild, with CVE-2026-41091 enabling local privilege escalation; no patch or workaround is mentioned.
Clone Systems[verified]@CloneSystemsIncActive Exploitation
Microsoft has identified two actively exploited Microsoft Defender CVEs, added to CISA’s KEV catalog, and urges organizations to verify updates and run the latest protection engine versions to mitigate the risk.
Upwind Security MDR[verified]@UpwindMDRActive Exploitation
Microsoft announced two actively exploited vulnerabilities in Defender (CVE‑2026‑41091 and CVE‑2026‑45498), detailing privilege‑escalation and denial‑of‑service flaws, confirming wild exploitation, and providing patch versions.