Signal

Microsoft patches two actively exploited zero-day vulnerabilities in Defender

Evidence first: scan the strongest sources, then decide whether to go deeper.

Published 2026-05-21 07:49 UTCUpdated 2026-05-21 22:05 UTC
rss
cveexploitsmalwareincident_responsesecurity_policy
Trend in the last 24h
Source links open
Source links and full evidence are open here. Archive history, compare-over-time, alerts, exports, API, integrations, and workflow are paid.
No card needed for the free brief.
Evidence trail (top sources)
top sources (4 domains)domains are deduped. counts indicate coverage, not truth.
4 top sources shown
Microsoft patches two zero-day flaws in Defender
CSO Online · News · csoonline.com · 2026-05-21 22:05 UTC
Microsoft Defender vulnerabilities are being exploited in the wild
Malwarebytes Threat Analysis · News · malwarebytes.com · 2026-05-21 17:36 UTC
Overview

Microsoft has released emergency patches for two zero-day vulnerabilities in Microsoft Defender that are actively exploited in the wild.

Entities
MicrosoftUnDefendRedSunNightmare Eclipse
Score total
1.8
Momentum 24h
6
Posts
6
Origins
6
Source types
1
Duplicate ratio
0%
Why now
  • Microsoft has just released emergency patches addressing these zero-days.
  • Exploits linked to these flaws have been publicly published on GitHub.
  • CISA's recent KEV catalog update highlights the critical threat level and exploitation status.
Why it matters
  • These vulnerabilities allow attackers to gain full system control or disable Defender, increasing risk of undetected malware.
  • Active exploitation in the wild means unpatched systems are at immediate risk.
  • Inclusion in CISA's KEV catalog mandates urgent patching for federal and critical infrastructure systems.
LLM analysis
Topic mix: lowPromo risk: lowSource quality: high
Recurring claims
  • Two zero-day vulnerabilities in Microsoft Defender are actively exploited in the wild.
  • CVE-2026-41091 allows local privilege escalation to SYSTEM level via improper link resolution in Defender's malware engine.
  • CVE-2026-45498 causes denial-of-service, disrupting Defender's operation and enabling malware evasion.
How sources frame it
  • CSO Online: neutral
  • Help Net Security: neutral
  • Malwarebytes Threat Analysis: neutral
This briefing consolidates multiple reports on two critical Microsoft Defender zero-days actively exploited in the wild, emphasizing the urgency of patching.
All evidence
All evidence
Microsoft patches two zero-day flaws in Defender
CSO Online · csoonline.com · 2026-05-21 22:05 UTC
Microsoft Defender vulnerabilities are being exploited in the wild
Malwarebytes Threat Analysis · malwarebytes.com · 2026-05-21 17:36 UTC
Microsoft Defender vulnerabilities exploited in the wild (CVE-2026-41091, CVE-2026-45498)
Help Net Security · helpnetsecurity.com · 2026-05-21 10:57 UTC
Microsoft Warns of Two Actively Exploited Defender Vulnerabilities
thehackernews · thehackernews.com · 2026-05-21 10:55 UTC
Microsoft Patches Exploited UnDefend and RedSun Defender Zero-Days
SecurityWeek · securityweek.com · 2026-05-21 09:52 UTC
Microsoft warns of new Defender zero-days exploited in attacks
bleepingcomputer_all · bleepingcomputer.com · 2026-05-21 07:49 UTC
Show filters & breakdown
Posts loaded: 0Publishers: 6Origin domains: 6Duplicates: -
Showing 6 / 0
Top publishers (this list)
  • CSO Online (1)
  • Malwarebytes Threat Analysis (1)
  • Help Net Security (1)
  • thehackernews (1)
  • SecurityWeek (1)
  • bleepingcomputer_all (1)
Top origin domains (this list)
  • csoonline.com (1)
  • malwarebytes.com (1)
  • helpnetsecurity.com (1)
  • thehackernews.com (1)
  • securityweek.com (1)
  • bleepingcomputer.com (1)