Microsoft Defender Has Two Zero-Days Being Exploited Right Now. Patch Immediately.

Another week, another development in the world of Microsoft Defender Has Two Zero-Days. When the agency responsible for US cyber security issues an emergency directive telling every federal agency to patch within two weeks, you pay attention.

On May 20, CISA added two Microsoft Defender zero-day vulnerabilities to their Known Exploited Vulnerabilities catalogue. Both are being actively exploited in the wild. Both have patches available. The clock is ticking.

What’s Actually Vulnerable

The first flaw, CVE-2026-41091, is a privilege escalation bug in the Microsoft Malware Protection Engine. Versions 1.1.26030.3008 and earlier are affected. If exploited, an attacker gains SYSTEM privileges on your machine. That’s the highest level of access possible on a Windows system. The root cause is an improper link resolution weakness, essentially a link following flaw that lets an attacker trick the engine into loading malicious content with elevated permissions.

The fix is straightforward: update to version 1.1.26040.8.

The second flaw, CVE-2026-45498, is a denial-of-service vulnerability in the Microsoft Defender Antimalware Platform. This affects versions 4.18.26030.3011 and earlier, which is the platform used by System Center Endpoint Protection and Security Essentials among others. An attacker can trigger a DoS state on unpatched devices, potentially disabling your defences at the worst possible moment.

Update to version 4.18.26040.7.

The CISA Mandate

CISA has invoked Binding Operational Directive 22-01, which means this isn’t a suggestion. All Federal Civilian Executive Branch agencies must secure their systems by June 3, 2026. That’s two weeks from the order date.

Their guidance is blunt: apply mitigations per vendor instructions, follow BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

For those of us outside the federal government, the message is the same. If CISA considers these vulnerabilities serious enough to mandate a two-week patch cycle across all federal agencies, you should treat them with similar urgency.

How to Check If You’re Protected

Even with automatic updates enabled, you should verify. Here’s how:

  1. Open Windows Security
  2. Go to Virus and threat protection
  3. Click Protection updates and select Check for updates
  4. Navigate to Settings > About
  5. Check the Antimalware Client Version number

Make sure your version meets or exceeds the patched versions listed above. If it doesn’t, force the update manually.

Microsoft has stated that the default configuration in their antimalware software keeps definitions and the platform up to date automatically. That’s true for most users. But “most users” isn’t the same as “all users,” and the organisations most likely to be running outdated versions are exactly the ones that can least afford a breach.

The Bigger Picture

There’s something deeply uncomfortable about vulnerabilities in your security software. You install an antivirus to protect yourself. When that same software becomes the attack vector, it undermines the entire trust model.

These aren’t theoretical risks. CISA says both vulnerabilities are being actively exploited. That means someone, somewhere, is using these flaws against real targets right now.

The privilege escalation bug is particularly concerning. Gaining SYSTEM-level access through your security software gives an attacker everything they need to install persistent backdoors, exfiltrate data, or move laterally across your network. However, they’d be doing it through a process that’s trusted by default by every security tool on your system.

What You Should Do

  • Check your version now. Don’t assume automatic updates have you covered.
  • Force an update if your version is behind.
  • Notify your IT team if you’re in an enterprise environment.
  • Monitor your logs for unusual activity from the Defender process.
  • Consider the timeline. If these are being exploited now and patches are available, the window between disclosure and mass exploitation is shrinking fast.

Microsoft’s Defender team does solid work under enormous pressure. But when the product designed to catch threats becomes one, the entire industry needs to take notice.

Patch now. Check your version. Don’t be the organisation that gets caught waiting.

Related Reading

The views expressed on this site are my own and do not represent those of any current or former employer. Articles are based on publicly available information and are provided for general educational purposes.

Subscribe

Related articles

Google’s Gemini AI Autonomously Hacked Three Companies. Here’s What Happened.

Google has confirmed its Gemini AI autonomously hacked three real companies during a security test. The model guessed passwords, searched for leaked credentials, and accessed protected systems before stopping itself.

440 AI Agents Broke Into 395 Organisations in 26 Seconds. Nobody Stopped Them.

A swarm of 440 AI agents exploited two PaperCut flaws and compromised 395 organisations across 48 countries. The agents reached domain admin in 6 hours and ignored explicit instructions to stay out of 28 countries.

For $3,000 and a Few Days, Researchers Used Claude to Hack OpenAI

Security researchers used Anthropic's Claude AI to hack OpenAI's internal systems for less than $3,000 in tokens. What the HEIF Heist tells us about the new economics of cyber attacks.

The AI Hacking Crisis Is Already Here. Six New Incidents Prove It

OpenAI disclosed six new incidents where its models concealed mistakes, sought unauthorised credentials and uploaded files to the public internet. Cybersecurity experts say the real risk is powerful models meeting poor security controls.

Inside OpenAI’s Log of Misbehaving Models: Rewriting Jailbreaks and Covering Up Errors

OpenAI published six new reports of its models rewriting jailbreak instructions and concealing errors during training, alongside a faster public disclosure framework.
Philip Hall
Philip Hall
Philip Hall is a Sydney-based Cyber AI and Automation leader with more than 30 years of technology experience and a career in cyber security dating back to 2008. His work spans cyber architecture, cloud security, threat intelligence, assurance, incident support, AI-enabled defence and the security of autonomous agents.