• News/
  • bleepingcomputer-20260521074948

Microsoft warns of new Defender zero-days exploited in attacks

BleepingComputer
·
Sergiu Gatlan
·
Published May 21, 2026
·
Updated

On Wednesday, Microsoft started rolling out security patches for two Defender vulnerabilities that have been exploited in zero-day attacks. The first one, tracked as CVE-2026-41091, is a privilege escalation security flaw affecting Microsoft Malware Protection Engine 1.1.26030.3008 and earlier, which provides the scanning, detection, and cleaning capabilities for Microsoft antivirus and antispyware software. This flaw stems from an improper link resolution before file access (link following) weakness, which allows attackers to gain SYSTEM privileges. A second vulnerability (CVE-2026-45498) affects systems running the Microsoft Defender Antimalware Platform 4.18.26030.3011 and earlier, a collection of security tools also used by Microsoft's System Center Endpoint Protection, System Center 2012 R2 Endpoint Protection, System Center 2012 Endpoint Protection, and Security Essentials. According to Microsoft, successful exploitation enables threat actors to trigger denial-of-service (DoS) states on unpatched Windows devices. Microsoft has released Malware Protection Engine versions 1.1.26040.8 and 4.18.26040.7, respectively, to address the two security flaws, and added that customers shouldn't have to take any action to secure their systems because "the default configuration in Microsoft antimalware software helps ensure that malware definitions and the Windows Defender Antimalware Platform are kept up to date automatically." However, users should still check whether Windows Defen...

Read full article

Affected Software

6 affected components
Microsoft Malware Protection Engine<=1.1.26030.3008
Microsoft Defender Antimalware Platform<=4.18.26030.3011
Microsoft System Center Endpoint Protection
Microsoft System Center 2012 R2 Endpoint Protection
Microsoft System Center 2012 Endpoint Protection
Microsoft Security Essentials
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What vulnerabilities are reported in the article?

The article reports on two zero-day vulnerabilities in Microsoft Defender, specifically CVE-2026-41091.

2

What is the main security risk associated with the vulnerabilities?

The main security risk is privilege escalation that can allow attackers to exploit the vulnerabilities in zero-day attacks.

3

Which Microsoft products are affected by these vulnerabilities?

The affected products include Microsoft Malware Protection Engine, Microsoft Defender Antimalware, and several Microsoft System Center Endpoint Protection versions.

4

What action has Microsoft taken in response to these vulnerabilities?

Microsoft has started rolling out security patches to address the two Defender vulnerabilities.

5

When was the security alert about these vulnerabilities published?

The security alert was published on May 21, 2026.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203