Microsoft security patch release for CVE-2026-41091 and CVE-2026-45498
Security Patch Release
Summary
Hide ▲
Show ▼
Microsoft rolled out security updates for Defender and related malware protection components to address two zero-days: CVE-2026-41091 and CVE-2026-45498. The fixes cover affected Microsoft Malware Protection Engine and Microsoft Defender Antimalware Platform versions reported in the disclosures. Both vulnerabilities were described as exploited in the wild. CVE-2026-41091 is a local privilege-escalation flaw, while CVE-2026-45498 is a denial-of-service issue. CISA added both to its Known Exploited Vulnerabilities catalog and urged federal agencies to patch by June 3.
Related Happenings
Citrix security patch release for CVE-2026-88779
Security Patch Release
H score46
First: 05.10.2026 00:58
Last: 05.10.2026 00:58
Sources 1
About this happening:
Citrix released emergency NetScaler updates for CVE-2026-88779, closing an actively exploited flaw across NetScaler ADC, NetScaler Gateway, and affected FIPS...
Citrix security patch release for CVE-2026-88779
Security Patch ReleaseAbout this happening: Citrix released emergency NetScaler updates for CVE-2026-88779, closing an actively exploited flaw across NetScaler ADC, NetScaler Gateway, and affected FIPS...
Microsoft security patch release for CVE-2026-65660
Security Patch Release
H score38
First: 22.09.2026 14:17
Last: 22.09.2026 14:17
Sources 1
About this happening:
Microsoft's August 11 security updates shipped a fix for CVE-2026-65660 across SharePoint Server 2016, 2019, and Subscription Edition, reducing exposure to a flaw...
Microsoft security patch release for CVE-2026-65660
Security Patch ReleaseAbout this happening: Microsoft's August 11 security updates shipped a fix for CVE-2026-65660 across SharePoint Server 2016, 2019, and Subscription Edition, reducing exposure to a flaw...
Microsoft September 2026 Patch Tuesday security updates (966 flaws)
Security Patch Release
H score54
First: 08.09.2026 21:18
Last: 08.09.2026 21:18
Sources 1
About this happening:
Microsoft released its September 2026 Patch Tuesday updates for a record 966 flaws, including two actively exploited zero-days that can enable local SYSTEM privi...
Microsoft September 2026 Patch Tuesday security updates (966 flaws)
Security Patch ReleaseAbout this happening: Microsoft released its September 2026 Patch Tuesday updates for a record 966 flaws, including two actively exploited zero-days that can enable local SYSTEM privi...
Microsoft Defender for Office 365 Safe Links blocks legitimate Google search links
Service Disruption
H score0
First: 02.09.2026 13:29
Last: 02.09.2026 13:29
Sources 1
About this happening:
Microsoft Defender for Office 365 Safe Links is blocking legitimate Google search links as malicious, preventing users from opening them normally and triggering warning pr...
Microsoft Defender for Office 365 Safe Links blocks legitimate Google search links
Service DisruptionAbout this happening: Microsoft Defender for Office 365 Safe Links is blocking legitimate Google search links as malicious, preventing users from opening them normally and triggering warning pr...
Latest development: 02.09.2026 13:30
Microsoft is investigating a Defender for Office 365 Safe Links issue in which legitimate Google search links are incorrectly classified as malicious, causing users to see "Opening this website might not be safe" warnings when opening the blocked URLs. Microsoft also says IT administrators may see related alerts and incidents in Microsoft Sentinel and the Defender portal while it works to correct the misclassification.
Microsoft security patch release for CVE-2026-62911
Security Patch Release
H score32
First: 01.09.2026 15:38
Last: 01.09.2026 15:38
Sources 1
About this happening:
Microsoft patched CVE-2026-62911 in Exchange Server 2016, Exchange Server 2019, and Exchange Server Subscription Edition (SE) during the August 2026 Patch Tu...
Microsoft security patch release for CVE-2026-62911
Security Patch ReleaseAbout this happening: Microsoft patched CVE-2026-62911 in Exchange Server 2016, Exchange Server 2019, and Exchange Server Subscription Edition (SE) during the August 2026 Patch Tu...
Timeline
-
21.05.2026 12:52 3 articles · 4mo ago
Microsoft patches exploited Defender zero-days and CISA adds them to KEV
Initial DisclosureMicrosoft released patches for Microsoft Defender Antimalware Platform version 4.18.26040.7 to address CVE-2026-41091, a link-following privilege-escalation flaw that can let an authorized attacker elevate privileges locally to System, and CVE-2026-45498, a denial-of-service flaw. Microsoft said both vulnerabilities were publicly disclosed and exploited in the wild as zero-days. CISA added both flaws to its Known Exploited Vulnerabilities (KEV) list and urged federal agencies to patch them by June 3.
Show sources
- Microsoft Patches Exploited UnDefend and RedSun Defender Zero-Days — www.securityweek.com — 21.05.2026 12:52
- Microsoft Warns of Two Actively Exploited Defender Vulnerabilities — thehackernews.com — 21.05.2026 13:55
- Microsoft Warns of Two Actively Exploited Defender Vulnerabilities — thehackernews.com — 21.05.2026 13:55
-
21.05.2026 10:49 2 articles · 4mo ago
Microsoft rolls out patches for exploited Defender zero-days
Mitigation Patch UpdateMicrosoft started rolling out fixes for CVE-2026-41091 in Microsoft Malware Protection Engine 1.1.26030.3008 and earlier and CVE-2026-45498 in Microsoft Defender Antimalware Platform 4.18.26030.3011 and earlier after zero-day exploitation affected unpatched Windows devices; CISA also added both vulnerabilities to the KEV Catalog and ordered Federal Civilian Executive Branch agencies to secure Windows endpoints and servers within two weeks, by June 3, under Binding Operational Directive (BOD) 22-01.
Show sources
- Microsoft warns of new Defender zero-days exploited in attacks — www.bleepingcomputer.com — 21.05.2026 10:49
- Microsoft warns of new Defender zero-days exploited in attacks — www.bleepingcomputer.com — 21.05.2026 10:49