Storyline

Microsoft patches two actively exploited zero-day vulnerabilities in Defender

Microsoft has released emergency patches for two zero-day vulnerabilities in Microsoft Defender that are actively exploited in the wild.

Published 2026-05-21 01:08 UTCUpdated 2026-05-21 22:05 UTC
Current brief openSource links open
This current storyline is open here with summary, metadata, source links, continuity context, and full evidence. Paid is for compare-over-time, alerts, exports, and workflow.
No card needed for the free brief.
Evidence trail (top sources)
top sources (4 domains)domains are deduped. counts indicate coverage, not truth.
4 top sources shown
Microsoft patches two zero-day flaws in Defender
CSO Online · News · csoonline.com · 2026-05-21 22:05 UTC
Microsoft Defender vulnerabilities are being exploited in the wild
Malwarebytes Threat Analysis · News · malwarebytes.com · 2026-05-21 17:36 UTC
Overview

Microsoft has released emergency patches for two zero-day vulnerabilities in Microsoft Defender that are actively exploited in the wild.

Score total
1.8
Momentum 24h
6
Posts
6
Origins
6
Source types
1
Duplicate ratio
0%
Why now
  • Microsoft has just released emergency patches addressing these zero-days.
  • Exploits linked to these flaws have been publicly published on GitHub.
  • CISA's recent KEV catalog update highlights the critical threat level and exploitation status.
Why it matters
  • These vulnerabilities allow attackers to gain full system control or disable Defender, increasing risk of undetected malware.
  • Active exploitation in the wild means unpatched systems are at immediate risk.
  • Inclusion in CISA's KEV catalog mandates urgent patching for federal and critical infrastructure systems.
Continuity snapshot
  • Trend status: insufficient_history.
  • Continuity stage: broad_confirmed.
  • Current status: open.
  • 6 current source-linked posts are attached to this storyline.
All evidence
All evidence
Microsoft patches two zero-day flaws in Defender
CSO Online · csoonline.com · 2026-05-21 22:05 UTC
Microsoft Defender vulnerabilities are being exploited in the wild
Malwarebytes Threat Analysis · malwarebytes.com · 2026-05-21 17:36 UTC
Microsoft Defender vulnerabilities exploited in the wild (CVE-2026-41091, CVE-2026-45498)
Help Net Security · helpnetsecurity.com · 2026-05-21 10:57 UTC
Microsoft Warns of Two Actively Exploited Defender Vulnerabilities
thehackernews · thehackernews.com · 2026-05-21 10:55 UTC
Microsoft Patches Exploited UnDefend and RedSun Defender Zero-Days
SecurityWeek · securityweek.com · 2026-05-21 09:52 UTC
Microsoft warns of new Defender zero-days exploited in attacks
bleepingcomputer_all · bleepingcomputer.com · 2026-05-21 07:49 UTC
Show filters & breakdown
Posts loaded: 0Publishers: 6Origin domains: 6Duplicates: -
Showing 6 / 0
Top publishers (this list)
  • CSO Online (1)
  • Malwarebytes Threat Analysis (1)
  • Help Net Security (1)
  • thehackernews (1)
  • SecurityWeek (1)
  • bleepingcomputer_all (1)
Top origin domains (this list)
  • csoonline.com (1)
  • malwarebytes.com (1)
  • helpnetsecurity.com (1)
  • thehackernews.com (1)
  • securityweek.com (1)
  • bleepingcomputer.com (1)