{"id":495789,"date":"2026-05-21T12:50:22","date_gmt":"2026-05-21T12:50:22","guid":{"rendered":"https:\/\/www.europesays.com\/ie\/495789\/"},"modified":"2026-05-21T12:50:22","modified_gmt":"2026-05-21T12:50:22","slug":"2-new-microsoft-defender-zero-days-exploited-patch-now-rolling-out","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ie\/495789\/","title":{"rendered":"2 New Microsoft Defender Zero-Days Exploited\u2014Patch Now Rolling Out"},"content":{"rendered":"<p><img decoding=\"async\" class=\" top-image\" src=\"https:\/\/www.europesays.com\/ie\/wp-content\/uploads\/2026\/05\/1779367822_111_0x0.jpg\" alt=\"Zero-Day in red under a magnifying glass amongst green binary code.\" data-height=\"3456\" data-width=\"5184\" fetchpriority=\"high\" style=\"position:absolute;top:0\"\/><\/p>\n<p>Microsoft and CISA confirm Defender zero-days exploited in the wild.<\/p>\n<p>Getty<\/p>\n<p>Microsoft has started rolling out an emergency security update for Microsoft Defender after the U.S. Cybersecurity and Infrastructure Security Agency confirmed that two new zero-day vulnerabilities are already being exploited in the wild by attackers. One is a privilege escalation problem that affects the Microsoft Malware Protection Engine, while the other has a broader scope, affecting Microsoft Defender Antimalware Platform and Microsoft&#8217;s System Center Endpoint Protection. Here\u2019s what you need to know about CVE-2026-41091 and CVE-2026-45498, including the mitigation measures confirmed by Microsoft.<\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-1\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2026\/05\/20\/how-to-mitigate-the-microsoft-windows-bitlocker-angry-hacker-0-day\/\" target=\"_blank\" aria-label=\"How To Mitigate The Microsoft Windows BitLocker YellowKey USB 0-Day\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/daveywinder\/2026\/05\/20\/how-to-mitigate-the-microsoft-windows-bitlocker-angry-hacker-0-day\/\" rel=\"nofollow noopener\">ForbesHow To Mitigate The Microsoft Windows BitLocker YellowKey USB 0-DayBy Davey Winder<\/a>Microsoft Defender CVE-2026-41091 And CVE-2026-45498 Zero-Days Explained<\/p>\n<p>Microsoft has now confirmed two new Microsoft Defender zero-days that it said had been exploited. This exploitation was confirmed by CISA, which has added the security flaws to its <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/06\/29\/11-million-critical-vulnerabilities-exposed---act-now\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/06\/29\/11-million-critical-vulnerabilities-exposed---act-now\/\" target=\"_self\" aria-label=\"Known Exploited Vulnerabilities catalog\" rel=\"nofollow noopener\">Known Exploited Vulnerabilities catalog<\/a> and given federal agencies until June 3 to ensure mitigation measures are in place. <\/p>\n<p>It has not been the greatest few days for Microsoft on the security front, especially regarding zero-day vulnerabilities. Microsoft Exchange users have been warned about an <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2026\/05\/18\/microsoft-exchange-active-0-day-exploit-enable-emergency-mitigation-now\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2026\/05\/18\/microsoft-exchange-active-0-day-exploit-enable-emergency-mitigation-now\/\" target=\"_self\" aria-label=\"active zero-day exploit\" rel=\"nofollow noopener\">active zero-day exploit<\/a> demanding emergency mitigation, the now infamous \u2018<a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2026\/05\/14\/microsoft-windows-alert-angry-hacker-drops-2-new-zero-day-exploits\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2026\/05\/14\/microsoft-windows-alert-angry-hacker-drops-2-new-zero-day-exploits\/\" target=\"_self\" aria-label=\"angry hacker\" rel=\"nofollow noopener\">angry hacker<\/a>\u2019 dropped another two public zero-day exploits, and the <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2026\/05\/15\/microsoft-windows-11-exploited-3-times-in-24-hours-by-zero-day-hackers\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2026\/05\/15\/microsoft-windows-11-exploited-3-times-in-24-hours-by-zero-day-hackers\/\" target=\"_self\" aria-label=\"Pwn2Own Berlin\" rel=\"nofollow noopener\">Pwn2Own Berlin<\/a> hacking event uncovered numerous Windows zero-days. All within the space of a week. <\/p>\n<p>The first has a Common Vulnerabilities and Exposures designation of <a class=\"color-link\" href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-41091\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-41091\" aria-label=\"CVE-2026-41091\">CVE-2026-41091<\/a>, and Microsoft described it as a Microsoft Defender elevation of privilege vulnerability caused by an improper link resolution before file access. This zero-day affects the Microsoft Malware Protection Engine up to version 1.1.26030.3008 and could give a successful attacker SYSTEM privileges with all that entails.<\/p>\n<p>The second, <a class=\"color-link\" href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-45498\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-45498\" aria-label=\"CVE-2026-45498\">CVE-2026-45498<\/a>, is a denial of service vulnerability impacting Microsoft Defender. Microsoft said that this affects the Defender Antimalware Platform up to version 4.18.26030.3011, along with other products that use it, including Microsoft System Center Endpoint Protection, Microsoft System Center 2012 R2 Endpoint Protection, Microsoft System Center 2012 Endpoint Protection and Microsoft Security Essentials.<\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-2\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2026\/05\/19\/microsoft-does-u-turn-on-edge-by-design-password-vulnerability\/\" target=\"_blank\" aria-label=\"Microsoft Confirms Surprising Edge Password Security U-Turn\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/daveywinder\/2026\/05\/19\/microsoft-does-u-turn-on-edge-by-design-password-vulnerability\/\" rel=\"nofollow noopener\">ForbesMicrosoft Confirms Surprising Edge Password Security U-TurnBy Davey Winder<\/a><\/p>\n<p>When adding the zero-days to the KEV Catalog database, <a class=\"color-link\" href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2026\/05\/20\/cisa-adds-seven-known-exploited-vulnerabilities-catalog\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/www.cisa.gov\/news-events\/alerts\/2026\/05\/20\/cisa-adds-seven-known-exploited-vulnerabilities-catalog\" aria-label=\"CISA warned\">CISA warned<\/a> that \u201cthese types of vulnerabilities are frequent attack vectors for malicious cyber actors,\u201d and accordingly gave Federal Civilian Executive Branch agencies just 14 days, starting May 20, to mitigate the threat.<\/p>\n<p>\u201cFor enterprise deployments as well as end users,\u201d Microsoft said, \u201cthe default configuration in Microsoft antimalware software helps ensure that malware definitions and the Microsoft Malware Protection Engine are kept up to date automatically,\u201d and as such no action is required as the update that is now rolling out will get applied without user input. However, it is worth checking that the default configuration still applies to your copy of Microsoft Defender and that automatic updating is, indeed, enabled.  Microsoft has advised that users should verify installation of the update by opening the Windows Security program, selecting Virus &amp; threat protection and then Protection Updates.<\/p>\n","protected":false},"excerpt":{"rendered":"Microsoft and CISA confirm Defender zero-days exploited in the wild. Getty Microsoft has started rolling out an emergency&hellip;\n","protected":false},"author":2,"featured_media":495790,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","_share_on_mastodon":"0"},"categories":[74],"tags":[215981,215982,215983,215980,18,19,17,102681,215979,215984,215985,82,33828],"class_list":["post-495789","post","type-post","status-publish","format-standard","has-post-thumbnail","category-technology","tag-cisa","tag-cve-2026-41091","tag-cve-2026-45498","tag-defender-zero-day-attacks","tag-eire","tag-ie","tag-ireland","tag-kev","tag-microsoft-defender","tag-microsoft-defender-emergency-update","tag-microsoft-defender-zero-day-exploit-confirmed","tag-technology","tag-zero-day"],"share_on_mastodon":{"url":"https:\/\/pubeurope.com\/@ie\/116612657233139729","error":""},"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/posts\/495789","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/comments?post=495789"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/posts\/495789\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/media\/495790"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/media?parent=495789"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/categories?post=495789"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/tags?post=495789"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}