vulnerability
Microsoft Warns of Two Actively Exploited Defender Vulnerabilities
High
Summary
Microsoft has disclosed two actively exploited vulnerabilities within its Defender security platform, CVE-2026-41091 and CVE-2026-45498, both of which allow for privilege escalation and denial-of-service attacks. These vulnerabilities have been observed in the wild by threat actors including RedSun, UnDefend, and BlueHammer, and have prompted a response from CISA, which has added them to its Known Exploited Vulnerabilities catalog. Microsoft has released updates to address these issues, and recommends users follow their update procedures to maintain optimal protection.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
