Summary

Microsoft has confirmed that two vulnerabilities in its Defender antivirus software are being actively exploited in the wild. The more severe of the two, CVE-2026-41091 (CVSS 7.8), is a privilege escalation flaw caused by improper link resolution in the Microsoft Malware Protection Engine. Successful exploitation grants attackers SYSTEM-level privileges on compromised machines. The second flaw, CVE-2026-45498 (CVSS 4.0), is a denial-of-service vulnerability that can effectively disable Defender entirely.

Both vulnerabilities have been added to CISA’s Known Exploited Vulnerabilities (KEV) catalog, with a mandatory remediation deadline of June 3, 2026 for federal agencies. Microsoft has released patches in Malware Protection Engine version 1.1.26040.8 and Antimalware Platform version 4.18.26040.7, which should auto-update for most users.

These flaws are part of a broader wave of Defender exploits stemming from proof-of-concept code released by a researcher known as “Nightmare Eclipse,” who previously published the BlueHammer, RedSun, and UnDefend exploits in April. Huntress incident responders have confirmed real-world attacks leveraging all three of those earlier exploits.

Source

The Hacker News · Help Net Security · Microsoft Security Response Center

Commentary

When your endpoint security product becomes the attack surface, you’ve got a problem. Defender ships enabled by default on every Windows machine — which means the blast radius here is effectively “all of Windows.” The auto-update mechanism should protect most consumers, but enterprise environments with controlled update policies need to act fast.

The Nightmare Eclipse saga is particularly concerning. A single disgruntled researcher has now dropped multiple weaponized PoCs for the security tool that hundreds of millions of endpoints rely on. Microsoft’s patch cadence has kept up so far, but the pattern suggests more are coming. If you’re running Defender in production, verify you’re on the latest engine version today — don’t assume auto-update handled it.

By Allan