vulnerability
Microsoft warns of new Defender zero-days exploited in attacks
High
Summary
Microsoft has released security patches for two zero-day vulnerabilities, CVE-2026-41091 (RedSun) and CVE-2026-45498 (UnDefend), that are being actively exploited in attacks. These flaws, affecting Microsoft Defender and related products, allow for privilege escalation and denial-of-service attacks. CISA has issued a Binding Operational Directive (BOD) 22-01 to federal agencies to address the vulnerabilities immediately.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data