
Microsoft’s warning about two actively exploited Defender zero-days is a reminder that security software is also software, and it must be patched with the same urgency as any exposed system component. The vulnerabilities are tracked as CVE-2026-41091 and CVE-2026-45498, affecting Microsoft Malware Protection Engine and Microsoft Defender Antimalware Platform respectively. One flaw can allow attackers to gain SYSTEM privileges, while the other can trigger denial-of-service conditions on unpatched Windows systems.
This is especially important because Defender is widely deployed across endpoints and servers, often with automatic updates assumed to be working in the background. Microsoft has released updated versions 1.1.26040.8 and 4.18.26040.7 to address the issues, and while default configurations should update automatically, administrators should still verify that the updates were actually installed. “It should update automatically” is not a control; it is a hope wearing an enterprise license.
CISA has also added both vulnerabilities to its Known Exploited Vulnerabilities catalog, requiring U.S. federal agencies to remediate them by June 3, 2026, which underlines that these are not theoretical risks. They are already being exploited in the wild.
Organizations should immediately confirm Defender engine and platform versions, ensure malware definitions and antimalware platform updates are enabled, review endpoint health status, and monitor for suspicious privilege escalation or service disruption events. Security teams should also pay special attention to systems where Defender updates are delayed due to proxy issues, disconnected networks, frozen images, golden templates, or change-control rituals designed by people who have never met an attacker.
The larger lesson is simple: endpoint protection cannot be treated as a static checkbox. Security tools need update validation, visibility, logging, and exception monitoring. If the defensive layer itself becomes vulnerable, attackers get the best possible outcome: using trusted security infrastructure as part of the attack path.
On Wednesday, Microsoft started rolling out security patches for two Defender vulnerabilities that have been exploited in zero-day attacks. [...]
Source: Microsoft warns of new Defender zero-days exploited in attacks via Bleeping Computer — published 21 May 2026.
Was this article helpful?
Your feedback helps us improve the knowledge base.