Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
CISA Warns of Critical SonicWall SMA 1000 Zero-Days Exploited in Ransomware Attacks
August 11, 2026
Critical VMware vCenter CVE-2023-34048 Under Active Exploitation
August 11, 2026
Critical ClamAV Vulnerabilities Let Attackers Trigger DoS
August 11, 2026
Home/CyberSecurity News/Critical Microsoft Defender SmartScreen Zero-Day Actively Exploited
CyberSecurity News

Critical Microsoft Defender SmartScreen Zero-Day Actively Exploited

Key Takeaways Two critical vulnerabilities, CVE‑2026‑41091 and CVE‑2026‑45498, have been discovered in Microsoft Defender. Both flaws are actively being exploited in the wild, allowing local...

Marcus Rodriguez
Marcus Rodriguez
May 21, 2026 3 Min Read
69 0

Key Takeaways

  • Two critical vulnerabilities, CVE‑2026‑41091 and CVE‑2026‑45498, have been discovered in Microsoft Defender.
  • Both flaws are actively being exploited in the wild, allowing local attackers to elevate privileges to SYSTEM or cause a denial of service.
  • The vulnerabilities impact core Microsoft Defender components across all supported Windows versions.
  • Microsoft has released patches, with automatic updates typically addressing the issues without manual intervention.
  • CISA has added both CVEs to its Known Exploited Vulnerabilities Catalog, mandating remediation for U.S. federal agencies by June 3, 2026.

Microsoft Defender, the default endpoint protection solution for Windows, is currently facing active exploitation from two recently disclosed zero-day vulnerabilities. These critical flaws could allow local attackers to escalate privileges to the highest SYSTEM level or trigger a denial of service, potentially undermining security across Windows environments.

Table Of Content

  • Key Takeaways
  • Microsoft Defender Elevation of Privilege Vulnerability
  • Microsoft Defender Denial of Service Vulnerability
  • What You Should Do

The vulnerabilities, identified as CVE‑2026‑41091 (Elevation of Privilege) and CVE‑2026‑45498 (Denial of Service), were publicly disclosed on May 19, 2026. They affect fundamental components of Microsoft Defender, impacting all currently supported Windows operating system versions.

Microsoft Defender Elevation of Privilege Vulnerability

Tracked as CVE‑2026‑41091, this “Important” severity flaw enables privilege escalation due to an improper link resolution mechanism in Microsoft Defender’s scanning engine. Specifically, the vulnerability arises from “link following” behavior before file access, which an attacker can manipulate.

An authenticated local attacker could exploit this weakness by crafting malicious links or junctions. Defender’s scanning logic would then follow these crafted paths, operating on attacker-controlled directories and ultimately granting the attacker SYSTEM-level privileges. Microsoft has confirmed active exploitation of this vulnerability, noting its “Exploitation Detected” status on its exploitability index.

Successful exploitation of CVE‑2026‑41091 provides threat actors with significant control over compromised systems. This includes the ability to disable or tamper with security software, deploy persistent malware, access sensitive data, and create new accounts with elevated privileges, thereby amplifying the impact of any initial breach. The vulnerability is present in Microsoft Malware Protection Engine versions up to 1.1.26030.3008 and is resolved in version 1.1.26040.8 and later.

Even systems where Defender is intentionally disabled may still register as vulnerable during security scans. This occurs because the affected binaries and versioned components often remain on disk, even if the security configuration itself is not exploitable in practice.

Microsoft Defender Denial of Service Vulnerability

The second critical flaw, CVE‑2026‑45498, is a Denial-of-Service vulnerability impacting the Microsoft Defender Antimalware Platform. Like the privilege escalation bug, this vulnerability has been publicly disclosed and is actively exploited, confirmed by Microsoft’s “Exploitation Detected” status.

By leveraging this platform-level weakness, attackers can potentially crash or disrupt Defender’s core protection functionalities. Such an outage creates a critical window for subsequent attacks, allowing threat actors to bypass defenses, establish stealthy persistence, or execute further malicious activities without immediate detection. The last affected platform version is 4.18.26030.3011, with the fix implemented in version 4.18.26040.7. Similar to the engine vulnerability, systems with disabled Defender might still show up as vulnerable in scan reports due to residual binaries, even if not actively exploitable.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has taken the significant step of adding both CVE‑2026‑41091 and CVE‑2026‑45498 to its Known Exploited Vulnerabilities (KEV) Catalog. This inclusion underscores the confirmed in-the-wild exploitation of both flaws. Under Binding Operational Directive (BOD) 22‑01, Federal Civilian Executive Branch (FCEB) agencies are mandated to remediate these vulnerabilities on all Windows endpoints and servers by June 3, 2026, providing a two-week window from their KEV listing on May 20.

What You Should Do

  • Verify that the Microsoft Defender engine version is at least 1.1.26040.8 and the Antimalware Platform version is at least 4.18.26040.7 on all Windows endpoints and servers.
  • Utilize the Windows Security application: navigate to “Virus & threat protection,” then “Protection updates,” and select “Check for updates” to manually initiate an update if needed.
  • Confirm the Antimalware Client version in Windows Security → Settings → About meets or exceeds the specified fixed versions.
  • Ensure that your organization’s update distribution pipelines for Microsoft Defender are functioning correctly and that updates are being consistently delivered and applied.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVECybersecurityExploitMalwareSecurityThreatVulnerability

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

Critical Linux Kernel Vulnerability Exposes SSH Private Keys

Next Post

Critical GitHub Flaw in VS Code Extension Exposed Internal Repositories

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Gunra Ransomware Exploits Fortinet VPN Flaws, Bypasses MFA
August 10, 2026
Anthropic Claude: New Security Feature Automates Agent Access Approvals
August 10, 2026
Critical Vulnerability Lets Attackers Bypass MFA in Windows 11 and Entra ID
August 10, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us