惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

小众软件
小众软件
V
Visual Studio Blog
博客园 - 三生石上(FineUI控件)
Last Week in AI
Last Week in AI
Blog — PlanetScale
Blog — PlanetScale
爱范儿
爱范儿
J
Java Code Geeks
A
About on SuperTechFans
F
Fortinet All Blogs
B
Blog
aimingoo的专栏
aimingoo的专栏
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Engineering at Meta
Engineering at Meta
Y
Y Combinator Blog
有赞技术团队
有赞技术团队
G
Google Developers Blog
Apple Machine Learning Research
Apple Machine Learning Research
V
V2EX
博客园_首页
博客园 - 叶小钗
罗磊的独立博客
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
D
Docker
云风的 BLOG
云风的 BLOG

Forbes - Innovation

Why Do Humans Have Fingerprints? Hint: It’s Not What You Think Booking.com Confirms Data Breach, Reservation PIN Codes Changed Why Major News Sites Are Blocking The Internet Archive’s Wayback Machine iPhone Fold Release Date: New Report Details Frustrating Apple News Comet Tracker: How To See Pan-STARRS And Three Planets On Wednesday NYT Mini Crossword Today: Tuesday, April 14 Hints And Answers Today’s NYT Strands Hints, Spangram, Answers: Tuesday, April 14 (It’s A Little Unclear) Today’s Wordle #1760 Hints And Answer For Tuesday, April 14 Most Of The Microplastics In Urban Air Come From Tires Today’s Wordle #1759 Hints And Answer For Monday, April 13 NYT Mini Crossword Today: Monday, April 13 Hints And Answers NYT Pips Today: Hints, Answers And Walkthrough For Monday, April 13 The YC Chief Who Codes 10,000 Lines A Day Has A Simple Secret Samsung Expands One UI 8.5 Beta To More Galaxy Owners Why You Should Stop Using Your iPhone If It’s On This List Chamath Says Firms That Treat AI As A Strategy Hand Rivals Their Edge 3 Unexpected Habits Of Secure Couples, By A Psychologist The First Lamp That Folds Your Clothes Samsung’s Disappointing Price Update For Galaxy Phone Buyers 3 Subtle Signs Someone Is Falling In Love With You, By A Psychologist Do Mantis Shrimp See More Colors Than Humans? A Biologist Explains NYT Connections Answers Explained For Monday, April 13 (#1,037) NYT Connections Hints Today: Monday, April 13 Clues And Answers (#1,037) LEGO Luigi & Mach 8 (72050) Review: 2026’s Best Set Yet? Marc Andreessen Says AI Productivity Will Trigger A Hiring Boom 3D Printing Is The Ultimate Hack To Reduce Household Spending Apple iPhone Fold: Striking Design Revealed In Leaked Photos Apple Smart Glasses: New Leak Reveals A Major Design Twist To Beat Meta Tested: The AI Coming To The Rivian R2 Quordle Hints Today: Monday, April 13 Clues And Answers
2 New Microsoft Defender Zero-Days Exploited—Patch Now Ro...
Davey Winder · 2026-05-21 · via Forbes - Innovation
Zero-Day in red under a magnifying glass amongst green binary code.

Microsoft and CISA confirm Defender zero-days exploited in the wild.

Getty

Microsoft has started rolling out an emergency security update for Microsoft Defender after the U.S. Cybersecurity and Infrastructure Security Agency confirmed that two new zero-day vulnerabilities are already being exploited in the wild by attackers. One is a privilege escalation problem that affects the Microsoft Malware Protection Engine, while the other has a broader scope, affecting Microsoft Defender Antimalware Platform and Microsoft's System Center Endpoint Protection. Here’s what you need to know about CVE-2026-41091 and CVE-2026-45498, including the mitigation measures confirmed by Microsoft.

ForbesHow To Mitigate The Microsoft Windows BitLocker YellowKey USB 0-Day

Microsoft Defender CVE-2026-41091 And CVE-2026-45498 Zero-Days Explained

Microsoft has now confirmed two new Microsoft Defender zero-days that it said had been exploited. This exploitation was confirmed by CISA, which has added the security flaws to its Known Exploited Vulnerabilities catalog and given federal agencies until June 3 to ensure mitigation measures are in place.

It has not been the greatest few days for Microsoft on the security front, especially regarding zero-day vulnerabilities. Microsoft Exchange users have been warned about an active zero-day exploit demanding emergency mitigation, the now infamous ‘angry hacker’ dropped another two public zero-day exploits, and the Pwn2Own Berlin hacking event uncovered numerous Windows zero-days. All within the space of a week.

The first has a Common Vulnerabilities and Exposures designation of CVE-2026-41091, and Microsoft described it as a Microsoft Defender elevation of privilege vulnerability caused by an improper link resolution before file access. This zero-day affects the Microsoft Malware Protection Engine up to version 1.1.26030.3008 and could give a successful attacker SYSTEM privileges with all that entails.

The second, CVE-2026-45498, is a denial of service vulnerability impacting Microsoft Defender. Microsoft said that this affects the Defender Antimalware Platform up to version 4.18.26030.3011, along with other products that use it, including Microsoft System Center Endpoint Protection, Microsoft System Center 2012 R2 Endpoint Protection, Microsoft System Center 2012 Endpoint Protection and Microsoft Security Essentials.

ForbesMicrosoft Confirms Surprising Edge Password Security U-TurnBy Davey Winder

When adding the zero-days to the KEV Catalog database, CISA warned that “these types of vulnerabilities are frequent attack vectors for malicious cyber actors,” and accordingly gave Federal Civilian Executive Branch agencies just 14 days, starting May 20, to mitigate the threat.

“For enterprise deployments as well as end users,” Microsoft said, “the default configuration in Microsoft antimalware software helps ensure that malware definitions and the Microsoft Malware Protection Engine are kept up to date automatically,” and as such no action is required as the update that is now rolling out will get applied without user input. However, it is worth checking that the default configuration still applies to your copy of Microsoft Defender and that automatic updating is, indeed, enabled. Microsoft has advised that users should verify installation of the update by opening the Windows Security program, selecting Virus & threat protection and then Protection Updates.