Microsoft is warning about two zero-day vulnerabilities in Microsoft Defenderthat are reportedly being exploited in real-world attacks. The vulnerabilities are listed as CVE-2026-41091 and CVE-2026-45498 , and involve Escalation Local (LPE) and denial-of-service (DoS) respectively.

Microsoft Defender (and its subsystems) is found on millions of Windows endpoints and servers, both in home and enterprise environments. In practical terms, an LPE bug can turn an initial “click” (e.g. low privileges from phishing, malicious attachment, or stolen credentials) into complete system control, allowing persistence, disabling security tools, and lateral movement.
What we know about CVE-2026-41091
CVE-2026-41091 is described as an “improper link resolution before file access” (also known as link following) issue. Simply put, under certain circumstances, unsafe rendering of links before accessing files could allow an attacker, who already has local access, to escalate their privileges to SYSTEM – the highest level of privilege in Windows.
See also: Pardus Linux: Chain of vulnerabilities allows complete system takeover
Escalating privileges to SYSTEM is a game changer for many attackers, especially in cases where the initial foothold is limited. Just remember that much of the real damage in incident response comes not from the first step, but from escalation and endpoint capture.
What we know about CVE-2026-45498
The second vulnerability, CVE-2026-45498, concerns Denial-of-Service. Although a DoS bug is not as dangerous as an RCE, here the element that raises the risk is that it concerns the protection mechanism: a DoS in Defender can degrade or interrupt critical detection/protection functions, creating a “window” for later stages of the attack.

Active exploitation and addition to the KEV List
Both vulnerabilities are reported as “exploited in the wild,” meaning we’re not just talking about a theoretical flaw or PoC. In addition, inclusion on CISA’s Known Exploited Vulnerabilities (KEV) list is considered a strong signal of prioritization: when a vulnerability is on the KEV, organizations tend to put it “higher up” in their patching queues.
According to reports, CISA has set a deadline of June 3, 2026 for the implementation of fixes in federal agencies (FCEB). While this concerns the US, historically such deadlines act as a "regulator" of urgency for the global market as well.
Microsoft Defender: Which products/versions are affected and what are the fixes?
– For CVE-2026-41091: Microsoft Malware Protection Engine (versions 1.1.26030.3008 and earlier reported). Fix: update to 1.1.26040.8.
– For CVE-2026-45498: Microsoft Defender Antimalware Platform (versions 4.18.26030.3011 and earlier reported). Fix: update to 4.18.26040.7.
See also: Drupal Core vulnerability allows RCE attacks on PostgreSQL sites
Note: Microsoft states that in many cases updates are done automatically by default, but in enterprise environments, confirmation (compliance/telemetry) must be made that they have indeed been applied everywhere
What vulnerabilities mean for organizations in Greece
– Many Greek businesses use Windows endpoints with Defender (either standalone or integrated into MDE/EDR strategies). An LPE in SYSTEM dramatically increases the risk in incident response.
– MSPs/IT admins should confirm with reports that engine/platform versions have been updated on all endpoints, especially on servers, VDI pools, “old” laptops and remote endpoints.
– In organizations with strict change management, “automatic” updates may be delayed. An exception/fast-track is needed here.

Practical section for admins/users
1) Check that Defender/engine updates are passing normally (policy + telemetry).
2) Confirm versions:
– Malware Protection Engine ≥ 1.1.26040.8
– Defender Antimalware Platform ≥ 4.18.26040.7
3) Watch for suspicious signs of privilege escalation:
– sudden changes in local admin groups
– new scheduled tasks/services
– suspicious processes with SYSTEM
4) If there is a suspicion of compromise, treat it as an incident: log collection, isolation, forensics.
See also: YellowKey BitLocker bypass – Microsoft's mitigations and what IT admins should change
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
IOCs / Timeline
At present, no details have been published on exactly how the exploitation is done, nor are there specific IOCs, so the best defense is to immediately confirm patch level and monitor suspicious activities.
Source: www.bleepingcomputer.com
