Microsoft discloses that two vulnerabilities in Microsoft Defender are being actively exploited in the wild, and both are confirmed by U.S. authorities to be under real-world attack. The first, CVE-2026-41091, involves how the Microsoft Malware Protection Engine resolves links before accessing files. Microsoft describes the issue as improper “link following,” where an attacker can exploit the behavior to obtain elevated privileges. Successful exploitation can allow an attacker to gain SYSTEM privileges, according to Microsoft.
The second vulnerability, CVE-2026-45498, can lead to a denial-of-service condition. Reports indicate it is being used to disrupt Defender’s operation, though the exact mechanism is described only in general terms across coverage.
CISA adds both issues to its Known Exploited Vulnerabilities (KEV) catalog, which signals that exploitation is observed in the field. The reporting from multiple outlets aligns on the affected product area (Microsoft Defender/Microsoft Malware Protection Engine), the threat impact of privilege escalation versus denial of service, and the active exploitation confirmation through Microsoft’s advisories and CISA’s catalog update.