Overview
- Microsoft began rolling out the updates on Wednesday, May 21, to fix two Microsoft Defender flaws that have been observed exploited in the wild.
- CVE-2026-41091 is a link‑following bug in the Microsoft Malware Protection Engine that can allow a local attacker to elevate privileges to SYSTEM.
- CVE-2026-45498 is a denial‑of‑service flaw in the Defender Antimalware Platform that can crash or disable antivirus processes on affected Windows systems.
- The U.S. Cybersecurity and Infrastructure Security Agency added both CVEs to its Known Exploited Vulnerabilities catalog and directed federal civilian agencies to remediate by June 3 under BOD 22-01.
- Public proof‑of‑concept exploits released in April have been seen used by attackers, so administrators should verify Defender automatic updates or install Malware Protection Engine v1.1.26040.8 and Antimalware Platform v4.18.26040.7, and note that systems with Defender disabled are not exploitable by these flaws.