2 New Microsoft Defender Zero-Days Exploited—Patch Now Rolling Out

2 New Microsoft Defender Zero-Days Exploited—Patch Now Rolling Out

By Davey Winder
Publication Date: 2026-05-21 12:40:00

Microsoft has started rolling out an emergency security update for Microsoft Defender after the U.S. Cybersecurity and Infrastructure Security Agency confirmed that two new zero-day vulnerabilities are already being exploited in the wild by attackers. One is a privilege escalation problem that affects the Microsoft Malware Protection Engine, while the other has a broader scope, affecting Microsoft Defender Antimalware Platform and Microsoft’s System Center Endpoint Protection. Here’s what you need to know about CVE-2026-41091 and CVE-2026-45498, including the mitigation measures confirmed by Microsoft.

ForbesHow To Mitigate The Microsoft Windows BitLocker YellowKey USB 0-Day

Microsoft Defender CVE-2026-41091 And CVE-2026-45498 Zero-Days Explained

Microsoft has now confirmed two new Microsoft Defender zero-days that it said had been exploited. This exploitation was confirmed by CISA, which has…