Signal
Microsoft patches two actively exploited zero-day vulnerabilities in Defender
Evidence first: scan the strongest sources, then decide whether to go deeper.
Published 2026-05-21 07:49 UTCUpdated 2026-05-21 22:05 UTC
rss
cveexploitsmalwareincident_responsesecurity_policy
Trend in the last 24h
Source links open
Source links and full evidence are open here. Archive history, compare-over-time, alerts, exports, API, integrations, and workflow are paid.
No card needed for the free brief.
Evidence trail (top sources)
top sources (4 domains)domains are deduped. counts indicate coverage, not truth.4 top sources shown
Overview
Microsoft has released emergency patches for two zero-day vulnerabilities in Microsoft Defender that are actively exploited in the wild.
Entities
MicrosoftUnDefendRedSunNightmare Eclipse
Score total
1.8
Momentum 24h
6
Posts
6
Origins
6
Source types
1
Duplicate ratio
0%
Why now
- Microsoft has just released emergency patches addressing these zero-days.
- Exploits linked to these flaws have been publicly published on GitHub.
- CISA's recent KEV catalog update highlights the critical threat level and exploitation status.
Why it matters
- These vulnerabilities allow attackers to gain full system control or disable Defender, increasing risk of undetected malware.
- Active exploitation in the wild means unpatched systems are at immediate risk.
- Inclusion in CISA's KEV catalog mandates urgent patching for federal and critical infrastructure systems.
LLM analysis
Topic mix: lowPromo risk: lowSource quality: high
Recurring claims
- Two zero-day vulnerabilities in Microsoft Defender are actively exploited in the wild.
- CVE-2026-41091 allows local privilege escalation to SYSTEM level via improper link resolution in Defender's malware engine.
- CVE-2026-45498 causes denial-of-service, disrupting Defender's operation and enabling malware evasion.
How sources frame it
- CSO Online: neutral
- Help Net Security: neutral
- Malwarebytes Threat Analysis: neutral
This briefing consolidates multiple reports on two critical Microsoft Defender zero-days actively exploited in the wild, emphasizing the urgency of patching.
All evidence
All evidence
Microsoft patches two zero-day flaws in Defender
CSO Online · csoonline.com · 2026-05-21 22:05 UTC
Microsoft Defender vulnerabilities are being exploited in the wild
Malwarebytes Threat Analysis · malwarebytes.com · 2026-05-21 17:36 UTC
Microsoft Defender vulnerabilities exploited in the wild (CVE-2026-41091, CVE-2026-45498)
Help Net Security · helpnetsecurity.com · 2026-05-21 10:57 UTC
Microsoft Warns of Two Actively Exploited Defender Vulnerabilities
thehackernews · thehackernews.com · 2026-05-21 10:55 UTC
Microsoft Patches Exploited UnDefend and RedSun Defender Zero-Days
SecurityWeek · securityweek.com · 2026-05-21 09:52 UTC
Microsoft warns of new Defender zero-days exploited in attacks
bleepingcomputer_all · bleepingcomputer.com · 2026-05-21 07:49 UTC
Show filters & breakdown
Posts loaded: 0Publishers: 6Origin domains: 6Duplicates: -
Showing 6 / 0
Top publishers (this list)
- CSO Online (1)
- Malwarebytes Threat Analysis (1)
- Help Net Security (1)
- thehackernews (1)
- SecurityWeek (1)
- bleepingcomputer_all (1)
Top origin domains (this list)
- csoonline.com (1)
- malwarebytes.com (1)
- helpnetsecurity.com (1)
- thehackernews.com (1)
- securityweek.com (1)
- bleepingcomputer.com (1)