Microsoft security patch release for CVE-2026-41091 and CVE-2026-45498
Security Patch Release
Summary
Hide ▲
Show ▼
Microsoft rolled out security updates for Defender and related malware protection components to address two zero-days: CVE-2026-41091 and CVE-2026-45498. The fixes cover affected Microsoft Malware Protection Engine and Microsoft Defender Antimalware Platform versions reported in the disclosures. Both vulnerabilities were described as exploited in the wild. CVE-2026-41091 is a local privilege-escalation flaw, while CVE-2026-45498 is a denial-of-service issue. CISA added both to its Known Exploited Vulnerabilities catalog and urged federal agencies to patch by June 3.
Related Happenings
Adobe security patch release for CVE-2026-48395
Security Patch Release
H score39
First: 01.08.2026 10:12
Last: 01.08.2026 10:12
Sources 1
About this happening:
Adobe shipped a security update for Adobe Bridge on 2026-08-01 that closes eight critical-rated flaws with risk of privilege escalation and arbitrary code execut...
Adobe security patch release for CVE-2026-48395
Security Patch ReleaseAbout this happening: Adobe shipped a security update for Adobe Bridge on 2026-08-01 that closes eight critical-rated flaws with risk of privilege escalation and arbitrary code execut...
Microsoft AD CS security update for CVE-2026-54121
Security Patch Release
H score34
First: 24.07.2026 17:15
Last: 24.07.2026 17:15
Sources 1
About this happening:
Certighost (CVE-2026-54121) is a Windows Active Directory Certificate Services (AD CS) vulnerability that can let an authenticated attacker manipulate certificate...
Microsoft AD CS security update for CVE-2026-54121
Security Patch ReleaseAbout this happening: Certighost (CVE-2026-54121) is a Windows Active Directory Certificate Services (AD CS) vulnerability that can let an authenticated attacker manipulate certificate...
ServiceNow security patch release for CVE-2026-6875
Security Patch Release
H score47
First: 20.07.2026 12:29
Last: 20.07.2026 12:29
Sources 1
About this happening:
ServiceNow released CVE-2026-6875 security updates for the ServiceNow AI Platform, covering hosted and self-hosted instances. The patch addresses a pre-auth sand...
ServiceNow security patch release for CVE-2026-6875
Security Patch ReleaseAbout this happening: ServiceNow released CVE-2026-6875 security updates for the ServiceNow AI Platform, covering hosted and self-hosted instances. The patch addresses a pre-auth sand...
7-Zip 26.02 security update (CVE-2026-14266)
Security Patch Release
H score24
First: 20.07.2026 12:10
Last: 20.07.2026 12:10
Sources 1
About this happening:
7-Zip 26.02 shipped on June 25, 2026 to fix CVE-2026-14266, a heap-based buffer overflow in XZ chunked data handling that could let a crafted archive run code...
7-Zip 26.02 security update (CVE-2026-14266)
Security Patch ReleaseAbout this happening: 7-Zip 26.02 shipped on June 25, 2026 to fix CVE-2026-14266, a heap-based buffer overflow in XZ chunked data handling that could let a crafted archive run code...
Microsoft SharePoint Server actively exploited multi-CVE wave
Exploitation Wave
H score79
First: 15.07.2026 12:44
Last: 15.07.2026 12:44
Sources 1
About this happening:
SharePoint Server exploitation wave remains active across internet-exposed on-premises instances, with CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164 used...
Microsoft SharePoint Server actively exploited multi-CVE wave
Exploitation WaveAbout this happening: SharePoint Server exploitation wave remains active across internet-exposed on-premises instances, with CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164 used...
Timeline
-
21.05.2026 12:52 3 articles · 2mo ago
Microsoft patches exploited Defender zero-days and CISA adds them to KEV
Initial DisclosureMicrosoft released patches for Microsoft Defender Antimalware Platform version 4.18.26040.7 to address CVE-2026-41091, a link-following privilege-escalation flaw that can let an authorized attacker elevate privileges locally to System, and CVE-2026-45498, a denial-of-service flaw. Microsoft said both vulnerabilities were publicly disclosed and exploited in the wild as zero-days. CISA added both flaws to its Known Exploited Vulnerabilities (KEV) list and urged federal agencies to patch them by June 3.
Show sources
- Microsoft Patches Exploited UnDefend and RedSun Defender Zero-Days — www.securityweek.com — 21.05.2026 12:52
- Microsoft Warns of Two Actively Exploited Defender Vulnerabilities — thehackernews.com — 21.05.2026 13:55
- Microsoft Warns of Two Actively Exploited Defender Vulnerabilities — thehackernews.com — 21.05.2026 13:55
-
21.05.2026 10:49 2 articles · 2mo ago
Microsoft rolls out patches for exploited Defender zero-days
Mitigation Patch UpdateMicrosoft started rolling out fixes for CVE-2026-41091 in Microsoft Malware Protection Engine 1.1.26030.3008 and earlier and CVE-2026-45498 in Microsoft Defender Antimalware Platform 4.18.26030.3011 and earlier after zero-day exploitation affected unpatched Windows devices; CISA also added both vulnerabilities to the KEV Catalog and ordered Federal Civilian Executive Branch agencies to secure Windows endpoints and servers within two weeks, by June 3, under Binding Operational Directive (BOD) 22-01.
Show sources
- Microsoft warns of new Defender zero-days exploited in attacks — www.bleepingcomputer.com — 21.05.2026 10:49
- Microsoft warns of new Defender zero-days exploited in attacks — www.bleepingcomputer.com — 21.05.2026 10:49