惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

D
Docker
人人都是产品经理
人人都是产品经理
小众软件
小众软件
博客园 - Franky
WordPress大学
WordPress大学
Jina AI
Jina AI
Google DeepMind News
Google DeepMind News
I
InfoQ
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
F
Fortinet All Blogs
博客园 - 【当耐特】
IT之家
IT之家
G
Google Developers Blog
J
Java Code Geeks
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
云风的 BLOG
云风的 BLOG
Recent Announcements
Recent Announcements
有赞技术团队
有赞技术团队
V
Visual Studio Blog
U
Unit 42
阮一峰的网络日志
阮一峰的网络日志
月光博客
月光博客
GbyAI
GbyAI
雷峰网
雷峰网

Help Net Security

ChatGPT advanced account security adds passkeys and hardware keys Week in review: High-severity LPE vulnerability in the Linux kernel, cPanel 0-day exploited for months Automating Pentest Delivery: A Step-by-Step Guide - PlexTrac Open-source privacy proxy masks PII before prompts reach external AI services Shadow AI risks deepen as 31% of users get no employer training Identity is the control plane for distributed infrastructure AI traffic is getting bigger, louder, and less predictable New infosec products of the month: April 2026 cPanel zero-day exploited for months before patch release (CVE-2026-41940) Cisco releases open-source toolkit for verifying AI model lineage Met Police face criticism for using AI to spy on their own officers Nine-year-old Linux kernel flaw enables reliable local privilege escalation (CVE-2026-31431) Hacker with a special interest in breaching sports institutions ends behind bars - Help Net Security IP Fabric MCP server adds governance and control to enterprise AIOps workflows - Help Net Security Aqua Compass MCP server enables real-time investigation and containment of runtime threats - Help Net Security Google brings instant email verification to Android, no OTP needed - Help Net Security If cyber espionage via HDMI worries you, NCSC built a device to stop it - Help Net Security Apple fixes iPhone bug that let FBI retrieve deleted Signal messages(CVE-2026-28950) - Help Net Security GopherWhisper APT group hides command and control traffic in Slack and Discord - Help Net Security OpenAI tackles a bad habit people have when interacting with AI - Help Net Security A year in, Zoom's CISO reflects on balancing security and business - Help Net Security Scenario: Open-source framework for automated AI app red-teaming - Help Net Security GDPR works, but only where someone enforces it - Help Net Security Ransomware, fraud, and lawsuits drive cyber insurance claims to new peaks - Help Net Security Google’s Workspace Intelligence promises privacy while running on your data - Help Net Security Cyberattack on French government agency triggers phishing alert - Help Net Security Claude Mythos finds 271 Firefox flaws, Mozilla believes zero-days are numbered - Help Net Security Prove Identity Platform connects verification, authentication, and fraud prevention - Help Net Security New Mirai variants target routers and DVRs in parallel campaigns - Help Net Security Acronis GenAI Protection gives MSPs control over AI usage and data risks - Help Net Security
Microsoft Defender vulnerabilities exploited in the wild ...
Zeljka Zorz · 2026-05-21 · via Help Net Security

Attackers are exploiting two Microsoft Defender vulnerabilities (CVE-2026-41091 and CVE-2026-45498), Microsoft acknowledged and CISA confirmed by adding them to its Known Exploited Vulnerabilities catalog.

The vulnerabilities

CVE-2026-41091 allows for local privilege elevation (LPE), and is caused by the Microsoft Malware Protection Engine improperly resolving links before accessing files. “An attacker who successfully exploited this vulnerability could gain SYSTEM privileges,” Microsoft noted.

CVE-2026-45498 can cause a denial-of-service (DoS) state, i.e., it can be used to prevent Microsoft Defender from working as it should.

Both vulnerabilities are publicly disclosed and have been observed being exploited in the wild, Microsoft says.

CVE-2026-41091, along a third Microsoft Defender remote code execution vulnerability (CVE-2026-45584), affect Microsoft Malware Protection Engine v1.26030.3008, and have been fixed in v1.1.26040.8.

CVE-2026-45498 affects Microsoft Defender Antimalware Platform, “a collection of user-mode binaries (…) and kernel-mode drivers that run on top of Windows to keep devices protected against new and prevalent threats”, and has been fixed in v4.18.26040.7.

“For enterprise deployments as well as end users, the default configuration in Microsoft antimalware software helps ensure that malware definitions and the Microsoft Malware Protection Engine are kept up to date automatically,” Microsoft noted, and said that this Malware Protection Engine update also “includes defense-in-depth updates to help improve security-related features.”

The same goes for the Microsoft Defender Antimalware Platform.

Both the Protection Engine and the Antimalware Platform are used by Microsoft Defender, but also by Microsoft’s System Center Endpoint Protection and Microsoft Security Essentials. (The latter may still run on old, unsupported Windows versions but is no longer updated.)

By adding the two exploited flaws to its KEV catalog, CISA mandated that by June 3, 2026, US federal civilian agencies must either apply Microsoft’s patches or drop the product entirely.

A wave of Microsoft Defender PoC exploits

On April 3 and 15, a disgruntled security researcher who goes by Nightmare Eclipse released proof-of-concept exploits for three Microsoft Defender vulnerabilities: BlueHammer (a LPE flaw), RedSun (another LPE), and UnDefend (a DoS vulnerability).

Huntress incident responders have observed an attacker leveraging the BlueHammer, RedSun, and UnDefend exploits.

BlueHammer, which received the CVE-2026-33825 identifier and has been patched, was added to CISA’s KEV catalog in late April. Researchers Zen Dodd and Yuanpei Xu were credited with reporting it.

Microsoft thanked several researchers for flagging CVE-2026-41091, and none for CVE-2026-45498.

Two days ago, Microsoft shared mitigation advice for CVE-2026-45585 (aka YellowKey), a BitLocker bypass flaw for which Nightmare Eclipse also published a PoC exploit.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!