Microsoft patches two exploited Defender zero-day flaws (opens in new tab)
Microsoft released security fixes for two Microsoft Defender vulnerabilities that attackers exploited as zero-days, according to reports citing the company’s security advisories. The vulnerabilities are CVE-2026-41091, an elevation-of-privilege bug rated 7.8 on the CVSS scale, and CVE-2026-45498, a denial-of-service bug rated 4.0. CVE-2026-41091 could let a local attacker with existing access to a Windows machine gain SYSTEM privileges. CVE-2026-45498 can disrupt Defender’s normal operation. ...
Read the original article