On Wednesday, Microsoft started rolling out security patches for two Defender vulnerabilities that have been exploited in zero-day attacks. The first one, tracked as CVE-2026-41091, is a privilege escalation security flaw affecting Microsoft Malware Protection Engine 1.1.26030.3008 and earlier, which provides the scanning, detection, and cleaning capabilities for Microsoft antivirus and antispyware software. This flaw stems from an improper link resolution before file access (link following) weakness, which allows attackers to gain SYSTEM privileges. A second vulnerability (CVE-2026-45498) affects systems running the Microsoft Defender Antimalware Platform 4.18.26030.3011 and earlier, a collection of security tools also used by Microsoft's System Center Endpoint Protection, System Center 2012 R2 Endpoint Protection, System Center 2012 Endpoint Protection, and Security Essentials. According to Microsoft, successful exploitation enables threat actors to trigger denial-of-service (DoS) states on unpatched Windows devices. Microsoft has released Malware Protection Engine versions 1.1.26040.8 and 4.18.26040.7, respectively, to address the two security flaws, and added that customers shouldn't have to take any action to secure their systems because "the default configuration in Microsoft antimalware software helps ensure that malware definitions and the Windows Defender Antimalware Platform are kept up to date automatically." However, users should still check whether Windows Defen...
Microsoft warns of new Defender zero-days exploited in attacks
BleepingComputer
·Sergiu Gatlan
·Published May 21, 2026
·Updated
Affected Software
6 affected components
Microsoft Malware Protection Engine<=1.1.26030.3008
Microsoft Defender Antimalware Platform<=4.18.26030.3011
Microsoft System Center Endpoint Protection
Microsoft System Center 2012 R2 Endpoint Protection
Microsoft System Center 2012 Endpoint Protection
Microsoft Security Essentials
Frequently Asked Questions
1
What vulnerabilities are reported in the article?
The article reports on two zero-day vulnerabilities in Microsoft Defender, specifically CVE-2026-41091.
2
What is the main security risk associated with the vulnerabilities?
The main security risk is privilege escalation that can allow attackers to exploit the vulnerabilities in zero-day attacks.
3
Which Microsoft products are affected by these vulnerabilities?
The affected products include Microsoft Malware Protection Engine, Microsoft Defender Antimalware, and several Microsoft System Center Endpoint Protection versions.
4
What action has Microsoft taken in response to these vulnerabilities?
Microsoft has started rolling out security patches to address the two Defender vulnerabilities.
5
When was the security alert about these vulnerabilities published?
The security alert was published on May 21, 2026.