Skip to main content
institutional access

You are connecting from
Lake Geneva Public Library,
please login or register to take advantage of your institution's Ground News Plan.

Published loading...Updated

2 New Microsoft Defender Zero-Days Exploited—Patch Now Rolling Out

Microsoft said the flaws can grant SYSTEM privileges or trigger denial-of-service states, while CISA gave federal agencies 14 days to mitigate them.

  • On Wednesday, Microsoft released patches for two Microsoft Defender zero-day vulnerabilities, CVE-2026-41091 and CVE-2026-45498, which are currently being exploited in the wild.
  • CVE-2026-41091 allows privilege escalation within the Microsoft Malware Protection Engine, while CVE-2026-45498 enables denial-of-service attacks on unpatched Windows devices.
  • The Cybersecurity and Infrastructure Security Agency added the flaws to its Known Exploited Vulnerabilities Catalog, ordering Federal Civilian Executive Branch agencies to mitigate threats within 14 days, by June 3.
  • Microsoft stated most customers require no action due to automatic updates, though users can verify their status via the Windows Security program's 'Protection Updates' section.
  • Recent security alerts include the Windows BitLocker YellowKey zero-day, and CISA warned these vulnerabilities pose "significant risks to the federal enterprise.
Insights by Ground AI
Podcasts & Opinions

15 Articles

Microsoft has closed two critical vulnerabilities in virus protection Defender, which already actively exploit attackers. Particularly explosive: One of the vulnerabilities provides hacker groups with full system rights on affected computers. The US agency CISA reacted immediately and set federal authorities a deadline of two weeks for installing the updates.

Read Full Article
Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 67% of the sources are Center
67% Center

Factuality Info Icon

To view factuality data please Upgrade to Premium

Ownership

Info Icon

To view ownership data please Upgrade to Vantage

BleepingComputer broke the news on Thursday, May 21, 2026.
Too Big Arrow Icon
Sources are mostly out of (0)

Similar News Topics

News
Feed Dots Icon
For You
Search Icon
Search
Blindspot LogoBlindspotLocal