Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Microsoft Fixes Two Exploited Defender Vulnerabilities

Microsoft Fixes Two Exploited Defender Vulnerabilities

Posted on May 21, 2026 By CWS

Microsoft has recently issued patches addressing two critical vulnerabilities within its Defender software, both of which have been actively exploited as zero-day threats. These vulnerabilities, if left unpatched, could potentially lead to severe security breaches.

Details of the Vulnerabilities

The first vulnerability, identified as CVE-2026-41091 with a CVSS score of 7.8, involves a link-following flaw. This issue allows unauthorized users to gain elevated privileges on a system, posing a significant risk to affected machines. Microsoft has noted that this vulnerability results from improper link resolution practices before file access.

The second flaw, CVE-2026-45498, holds a CVSS score of 4.0 and is classified as a denial-of-service (DoS) vulnerability. Both vulnerabilities are addressed in the Microsoft Defender Antimalware Platform version 4.18.26040.7. It is important to note that systems with Defender disabled remain unaffected by these exploits.

Public Disclosure and Exploitation

Both vulnerabilities have been publicly disclosed, and there is evidence of their exploitation in the wild. Security researcher Chaos Eclipse publicly revealed these issues last month, naming them UnDefend and RedSun, variants of the BlueHammer exploit. Following these revelations, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has included these vulnerabilities in its Known Exploited Vulnerabilities (KEV) list.

CISA has mandated federal agencies to patch these vulnerabilities by June 3. Alongside the Defender vulnerabilities, five other security issues were added to the KEV list. These include older vulnerabilities such as CVE-2008-4250, which affects the Server service of older Windows versions, and others like CVE-2009-1537 and CVE-2009-3459, affecting Microsoft DirectX and Adobe Acrobat respectively.

Urgency and Recommendations

With the deadline set by CISA approaching, it is critical for organizations, particularly federal agencies, to update their systems promptly to mitigate potential risks. CISA has emphasized the importance of reviewing the KEV list and addressing these vulnerabilities without delay.

The proactive fixing of these vulnerabilities is essential in safeguarding against potential attacks. Organizations are encouraged to regularly update their systems and review security advisories to protect their networks from ongoing threats.

As cybersecurity risks continue to evolve, staying informed and prepared is crucial. The updates from Microsoft serve as a reminder of the ever-present need for vigilance in the digital landscape.

Security Week News Tags:CISA, CVE-2026-41091, CVE-2026-45498, Cybersecurity, Defender, Microsoft, Security, Updates, Vulnerabilities, zero-day

Post navigation

Previous Post: Critical Linux Kernel Bug Risks SSH Key Theft
Next Post: Microsoft Defender Vulnerabilities Exposed, Actively Exploited

Related Posts

Exposed Docker APIs Likely Exploited to Build Botnet Exposed Docker APIs Likely Exploited to Build Botnet Security Week News
Amazon Details Iran’s Cyber-Enabled Kinetic Attacks Linking Digital Spying to Physical Strikes Amazon Details Iran’s Cyber-Enabled Kinetic Attacks Linking Digital Spying to Physical Strikes Security Week News
Analysis of 6 Billion Passwords Shows Stagnant User Behavior Analysis of 6 Billion Passwords Shows Stagnant User Behavior Security Week News
Progress Releases Vital Patches for MOVEit and LoadMaster Progress Releases Vital Patches for MOVEit and LoadMaster Security Week News
Organizations Warned of Exploited PaperCut Flaw Organizations Warned of Exploited PaperCut Flaw Security Week News
Chrome 137, Firefox 139 Patch High-Severity Vulnerabilities Chrome 137, Firefox 139 Patch High-Severity Vulnerabilities Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Apple Blocks 2 Million App Store Apps for Security in 2025
  • Linux Rootkits and AI Intrusions: Key Security Threats
  • Flipper One: New Modular Linux Cyberdeck Unveiled
  • Ocean Secures $28M for Advanced Email Security Platform
  • BadIIS Malware Exploits IIS Servers for Illicit Redirects

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Apple Blocks 2 Million App Store Apps for Security in 2025
  • Linux Rootkits and AI Intrusions: Key Security Threats
  • Flipper One: New Modular Linux Cyberdeck Unveiled
  • Ocean Secures $28M for Advanced Email Security Platform
  • BadIIS Malware Exploits IIS Servers for Illicit Redirects

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark