BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Exploited Microsoft Defender Flaws Prompt Urgent Fix

Microsoft patches two actively exploited Defender flaws; CISA mandates urgent updates.

  • Two actively exploited vulnerabilities in Microsoft Defender, CVE-2026-41091 and CVE-2026-45498, have been patched according to an advisory dated May 21, 2026.
  • The flaws, a privilege escalation bug and a denial-of-service issue, require immediate patching as they have been added to the CISA Known Exploited Vulnerabilities catalog.
  • These are part of a recent wave of exploited Microsoft vulnerabilities, including a separate Exchange Server bug disclosed the previous week.
  • Federal agencies have been mandated to apply fixes for these and several other older, critical vulnerabilities by June 3, 2026.

Microsoft disclosed on May 21, 2026, that two critical vulnerabilities in its Defender security software are being actively weaponized in real-world attacks. The company urgently addressed a privilege escalation flaw and a denial-of-service bug, according to its security advisory.

- Advertisement -

Tracked as CVE-2026-41091, the privilege escalation flaw could allow an attacker to gain SYSTEM privileges. However, the second vulnerability, CVE-2026-45498, is a less severe denial-of-service issue specifically impacting Defender.

Consequently, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added both defects to its Known Exploited Vulnerabilities (KEV) catalog. Federal Civilian Executive Branch agencies must now apply the provided fixes by June 3, 2026.

Meanwhile, this marks three exploited Microsoft vulnerabilities within a single week. Last week, the company also disclosed an exploited cross-site scripting flaw in on-premise Exchange Server tracked as CVE-2026-42897.

The latest CISA update also included four other high-severity, historical Microsoft flaws. These older vulnerabilities, such as CVE-2010-0806 in Internet Explorer and CVE-2008-4250 in Windows Server Service, still pose significant remote code execution risks.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

AnyDesk Linux pre-auth RCE exploit gives root access

Security researchers published AnyPwn, a working exploit for a pre-authentication remote code execution flaw...

CleanSpark Ends Monthly Bitcoin Reports, Cites Data Center Growth

CleanSpark produced 529 BTC in September, averaging 17.64 BTC per day, and holds 13,530...

China doc exposes pig butchering scam border horrors

China released a documentary series exposing pig butchering scams across Southeast AsiaNearly 100,000 law...

Qureshi Slams Drake’s ‘Bunker Mode’ as Crypto Doomerism

Dragonfly managing partner Haseeb Qureshi called Ethereum researcher Justin Drake’s “bunker mode” warning “cryptographic...

CISA Adds 5 Flax Typhoon Exploited Flaws to KEV Catalog

CISA added five vulnerabilities to its Known Exploited Vulnerabilities catalog after China-linked threat actor...

Must Read

Crypto in New York: The 2026 Guide to Legal Exchanges and BitLicense Regulations

TL;DR: Trading crypto in New York is legal but heavily regulated by the New York Department of Financial Services (NYDFS). Platforms must hold a BitLicense...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading