Categories: Cyber Security News

CISA Warns of Microsoft Defender 0-Day Vulnerabilities Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two critical Microsoft Defender vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, warning organizations of active exploitation risks.

The flaws, tracked as CVE-2026-45498 and CVE-2026-41091, impact Microsoft Defender and could allow attackers to disrupt systems or escalate privileges.

Both vulnerabilities were officially added to the KEV list on May 20, 2026, with a remediation deadline of June 3, 2026, under Binding Operational Directive (BOD) 22-01.

Federal agencies and organizations using Microsoft Defender are urged to apply mitigations immediately.

Microsoft Defender Zero-Day Exploits

The first vulnerability, CVE-2026-45498, is a denial-of-service (DoS) flaw in Microsoft Defender.

While the technical specifics remain limited, successful exploitation could allow attackers to disrupt Defender operations, potentially weakening endpoint protection and exposing systems to compromise further.

The second flaw, CVE-2026-41091, is a link-following vulnerability (CWE-59). This issue allows an authorized local attacker to exploit improper handling of symbolic links, leading to privilege escalation.

By leveraging this flaw, attackers could gain elevated access on targeted systems, increasing the risk of lateral movement and deeper network compromise.

Although CISA has not confirmed whether these vulnerabilities are currently used in ransomware campaigns, their inclusion in the KEV catalog indicates evidence of active exploitation in real-world attacks.

Security researchers warn that advanced threat actors and ransomware operators commonly employ privilege escalation and defense-evasion techniques.

The combination of a DoS vulnerability and a privilege escalation flaw in a widely deployed security product like Microsoft Defender raises concerns about defense bypass scenarios.

Attackers may exploit these weaknesses to turn off protections before deploying malware or conducting post-exploitation activities.

CISA strongly advises organizations to take the following actions:

  • Apply security updates and mitigations provided by Microsoft immediately.
  • Follow BOD 22-01 guidelines for cloud and on-premises environments.
  • Monitor systems for unusual behavior, including Defender service disruptions.
  • Restrict local access privileges to minimize the risk of exploitation.
  • Consider discontinuing use of affected systems if patches are unavailable.

Organizations should also review endpoint detection logs and investigate anomalies that may indicate attempted exploitation.

The discovery of actively exploited vulnerabilities in security software highlights an ongoing challenge in cybersecurity: attackers increasingly target defensive tools themselves.

Exploiting such tools can provide a stealthy pathway to bypass detection and maintain persistence.

Security teams are encouraged to adopt a layered defense strategy that combines endpoint protection with behavioral monitoring, threat intelligence, and rapid patch management.

As threat actors continue to evolve their tactics, timely vulnerability remediation remains critical to reducing attack surfaces and preventing breaches.

Follow us on Google NewsLinkedIn, and X to Get More Instant Updates.

The post CISA Warns of Microsoft Defender 0-Day Vulnerabilities Exploited in Attacks appeared first on Cyber Security News.

rssfeeds-admin

Recent Posts

Save $2,400 Off the Alienware 16X Aurora RTX 5070 Gaming Laptop Loaded With 64GB of RAM and 4TB SSD

For Memorial Day, Dell is offering an Alienware 16X Aurora gaming laptop that's loaded with…

4 minutes ago

Save 48% Off the Logitech G29/G920 Racing Wheel With Driving Force Shifter, Perfect for Forza Horizon 6

Forza Horizon 6 for PC and Xbox was released on May 19. This is the…

1 hour ago

Tom Hardy Might Be Dropped from MobLand After Reportedly Clashing With Cast and Crew

Tom Hardy may not return for MobLand Season 3 after reportedly butting heads with cast…

1 hour ago

Today’s Top Deals: Logitech G920 Racing Wheel, LEGO The Starry Night, and a MacBook Air

Heading into Memorial Day weekend, there are some incredible deals on tons of video games…

1 hour ago

Save 20% Off the Apple AirPods Pro 3 Earbuds During the Amazon Memorial Day Sale

If you're an iPhone user, then don't miss this opportunity to pick up a pair…

1 hour ago

LEGO Star Wars Designer Highlights the Ideas Sets He Helped Bring to Life

LEGO produces a lot of new sets each month, with more and more of these…

1 hour ago

This website uses cookies.