Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
How Tier 1 Can Process Alerts 3x Faster with Threat Intel
May 26, 2026
Angular Language Service Flaws Enable Remote Code Execution
May 26, 2026
Quasar Linux RAT Targets Developers via Fileless eBPF
May 26, 2026
Home/CyberSecurity News/CISA Warns: Microsoft Defender 0-Day Vulnerabilities Exploited
CyberSecurity News

CISA Warns: Microsoft Defender 0-Day Vulnerabilities Exploited

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning to organizations regarding two critical Microsoft Defender vulnerabilities. These flaws, now added to...

Marcus Rodriguez
Marcus Rodriguez
May 22, 2026 2 Min Read
19 0

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning to organizations regarding two critical Microsoft Defender vulnerabilities. These flaws, now added to CISA’s Known Exploited Vulnerabilities (KEV) catalog, are actively being exploited.

The flaws, tracked as CVE-2026-45498 and CVE-2026-41091, impact Microsoft Defender and could allow attackers to disrupt systems or escalate privileges.

Both vulnerabilities were officially added to the KEV list on May 20, 2026, with a remediation deadline of June 3, 2026, under Binding Operational Directive (BOD) 22-01.

Federal agencies and organizations using Microsoft Defender are urged to apply mitigations immediately.

Microsoft Defender Zero-Day Exploits

The first vulnerability, CVE-2026-45498, is a denial-of-service (DoS) flaw in Microsoft Defender.

While the technical specifics remain limited, successful exploitation could allow attackers to disrupt Defender operations, potentially weakening endpoint protection and exposing systems to compromise further.

The second flaw, CVE-2026-41091, is a link-following vulnerability (CWE-59). This issue allows an authorized local attacker to exploit improper handling of symbolic links, leading to privilege escalation.

By leveraging this flaw, attackers could gain elevated access on targeted systems, increasing the risk of lateral movement and deeper network compromise.

Although CISA has not confirmed whether these vulnerabilities are currently used in ransomware campaigns, their inclusion in the KEV catalog indicates evidence of active exploitation in real-world attacks.

Security researchers warn that advanced threat actors and ransomware operators commonly employ privilege escalation and defense-evasion techniques.

The combination of a DoS vulnerability and a privilege escalation flaw in a widely deployed security product like Microsoft Defender raises concerns about defense bypass scenarios.

Attackers may exploit these weaknesses to turn off protections before deploying malware or conducting post-exploitation activities.

CISA strongly advises organizations to take the following actions:

  • Apply security updates and mitigations provided by Microsoft immediately.
  • Follow BOD 22-01 guidelines for cloud and on-premises environments.
  • Monitor systems for unusual behavior, including Defender service disruptions.
  • Restrict local access privileges to minimize the risk of exploitation.
  • Consider discontinuing use of affected systems if patches are unavailable.

Organizations should also review endpoint detection logs and investigate anomalies that may indicate attempted exploitation.

The discovery of actively exploited vulnerabilities in security software highlights an ongoing challenge in cybersecurity: attackers increasingly target defensive tools themselves.

Exploiting such tools can provide a stealthy pathway to bypass detection and maintain persistence.

Security teams are encouraged to adopt a layered defense strategy that combines endpoint protection with behavioral monitoring, threat intelligence, and rapid patch management.

As threat actors continue to evolve their tactics, timely vulnerability remediation remains critical to reducing attack surfaces and preventing breaches.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

BreachCVECybersecurityExploitMalwarePatchransomwareSecurityVulnerabilityzero-day

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

Android Malware Auto-Subscribes Users to Silently Victims

Next Post

CISA Adds Langflow Flaw to Exploited Vulner Origin Validation

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Microsoft Defender Isolates Compromised Devices from Ransom
May 26, 2026
GitHub Down: Authentication Issues Deny Access to Actions
May 26, 2026
Hackers Exploit Ghost CMS CVE-2026 CVE-2026-26980 Poison
May 26, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
Emy Elsamnoudy
Emy Elsamnoudy
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Detects Critical MongoDB CVE-

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us