{"id":15803,"date":"2026-05-29T10:28:59","date_gmt":"2026-05-29T10:28:59","guid":{"rendered":"https:\/\/www.securitytoday.de\/2026\/05\/29\/microsoft-defender-cve-2026-41091-aktiv-ausgenutzt-cisa-kev\/"},"modified":"2026-07-04T11:53:26","modified_gmt":"2026-07-04T11:53:26","slug":"microsoft-defender-cve-2026-41091-aktiv-ausgenutzt-cisa-kev","status":"publish","type":"post","link":"https:\/\/www.securitytoday.de\/en\/2026\/05\/29\/microsoft-defender-cve-2026-41091-aktiv-ausgenutzt-cisa-kev\/","title":{"rendered":"Defender under fire: Two actively exploited vulnerabilities and the blind spot in the SOC"},"content":{"rendered":"<p style=\"color:#69d8ed;font-size:0.9em;margin:0 0 16px;padding:0;\">7 min read<\/p>\n<p><strong>Microsoft Defender, which runs as a protective layer on millions of Windows systems, has two actively exploited vulnerabilities. One allows for local privilege escalation. CISA has added both to its catalogue of exploited vulnerabilities and set a deadline of 3 June for federal agencies. For DACH-SOCs, the case is less an alarm bell and more a reminder: even the tool that protects can become an attack surface.<\/strong><\/p>\n<div style=\"background:#003340;color:#fff;padding:32px 36px;margin:32px 0;border-radius:8px;\">\n<p style=\"margin:0 0 18px 0;font-size:0.95em;font-weight:800;text-transform:uppercase;letter-spacing:0.2em;color:#69d8ed;border-bottom:2px solid rgba(105,216,237,0.25);padding-bottom:12px;\">Key Takeaways<\/p>\n<ul style=\"margin:0;padding-left:22px;color:rgba(255,255,255,0.92);line-height:1.6;\">\n<li style=\"margin-bottom:12px;\"><strong style=\"color:#69d8ed;\">Two Defender flaws are being exploited.<\/strong> CVE-2026-41091 enables local privilege escalation, while CVE-2026-45498 allows a Denial of Service.<\/li>\n<li style=\"margin-bottom:12px;\"><strong style=\"color:#69d8ed;\">CISA deadline 3 June.<\/strong> The US authority lists both in the KEV catalogue, a strong signal for DACH operators as well.<\/li>\n<li><strong style=\"color:#69d8ed;\">Updates usually run automatically.<\/strong> Defender pulls fixes via definition updates. Relying on this without verification is risky.<\/li>\n<\/ul>\n<\/div>\n<p style=\"font-size:0.88em;color:#b8c5ce;margin:20px 0 32px 0;border-top:1px solid rgba(230,227,218,0.12);border-bottom:1px solid rgba(230,227,218,0.12);padding:10px 0;\"><span style=\"color:#69d8ed;font-weight:700;text-transform:uppercase;font-size:0.72em;letter-spacing:0.14em;margin-right:14px;\">Related:<\/span><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/05\/27\/fortinet-2026-time-to-exploit-24-48-stunden-dach-soc\/\" style=\"color:#333;text-decoration:underline;\">Time-to-exploit drops to 24\u201348 hours<\/a>&nbsp;&nbsp;<span style=\"color:#ccc;\">\/<\/span>&nbsp;&nbsp;<a href=\"https:\/\/www.securitytoday.de\/en\/2026\/05\/26\/cyber-liability-in-administration-three-levels-no-plan\/\" style=\"color:#333;text-decoration:underline;\">Cyber liability in public administration<\/a><\/p>\n<h2 style=\"padding-top:64px;margin-bottom:20px;\">What is being exploited<\/h2>\n<p><strong>What is a privilege-escalation flaw?<\/strong> A vulnerability that permits privilege escalation allows an attacker who already has limited system access to gain higher privileges \u2013 up to full control in extreme cases. It is rarely the first step in an attack, but almost always the decisive one.<\/p>\n<p>The more severe of the two flaws is tracked as CVE-2026-41091 and carries a CVSS score of 7.8. It is a link-following error: under certain conditions, Defender follows a tampered shortcut and accesses a file the attacker should not have privileged access to. The result is local privilege escalation. Anyone who already has a foothold \u2013 via phishing or another flaw \u2013 can leverage it to seize full control.<\/p>\n<p>The second flaw, CVE-2026-45498, is far less dangerous with a CVSS score of 4.0. It enables a Denial of Service, effectively crippling the service. Unpleasant, but not an entry point for takeover. Microsoft states that both vulnerabilities overlap with zero-days disclosed in April \u2013 codenamed RedSun and UnDefend.<\/p>\n<p>The key difference is active exploitation. A theoretical flaw is a paper risk. An exploited flaw means code already exists in the wild that triggers it. CISA does not add a vulnerability to its catalogue because it could be dangerous; it does so because it is demonstrably abused. That distinction should drive prioritisation in your own environment. A 7.8-rated flaw without an exploit can wait; the same flaw with active abuse cannot.<\/p>\n<div style=\"background:#003340;color:#fff;text-align:center;padding:40px 24px;margin:32px 0;border-radius:8px;\">\n<div style=\"font-size:3.4em;font-weight:800;color:#69d8ed;letter-spacing:-0.03em;line-height:1;\">7.8<\/div>\n<div style=\"font-size:1em;color:rgba(255,255,255,0.88);margin-top:12px;max-width:520px;margin-left:auto;margin-right:auto;line-height:1.5;\">CVSS score of the more severe Defender flaw CVE-2026-41091, a local privilege-escalation issue via a link-following error.<\/div>\n<div style=\"font-size:0.78em;color:rgba(255,255,255,0.5);margin-top:12px;\">Source: Microsoft Security Update Guide, CISA KEV catalogue, May 2026<\/div>\n<\/div>\n<h2 style=\"padding-top:64px;margin-bottom:20px;\">Why Automatic Patches Aren\u2019t a Free Pass<\/h2>\n<p>Microsoft stresses that both vulnerabilities are being rolled out via Defender\u2019s definition updates. For most systems, no manual intervention is required. That\u2019s the good news. And it\u2019s true. But it\u2019s also where complacency begins.<\/p>\n<p>Automatic updates only work if the mechanism functions. In practice, there are plenty of systems where it doesn\u2019t: air-gapped production networks without internet access, machines locked to specific versions, devices whose update services have been throttled for performance reasons. These are often the most critical systems. Relying on silent updates without verification confuses probability with certainty.<\/p>\n<p>The relevant version numbers are documented. The patch for the privilege escalation is platform version 1.1.26040.8, while the fix for the denial of service is engine version 4.18.26040.7. A quick inventory check reveals whether the entire fleet is protected or if some systems are lagging behind.<\/p>\n<div style=\"display:grid;grid-template-columns:repeat(auto-fit,minmax(280px,1fr));gap:16px;margin:28px 0;\">\n<div style=\"background:#fafafa;border-top:3px solid #c0392b;padding:18px 20px;border-radius:4px;\">\n<p style=\"margin:0 0 10px 0;font-size:0.78em;font-weight:700;text-transform:uppercase;letter-spacing:0.12em;color:#c0392b;\">False Sense of Security<\/p>\n<ul style=\"margin:0;padding-left:18px;color:#333;line-height:1.55;font-size:0.95em;\">\n<li style=\"margin-bottom:6px;\">Defender updates itself automatically<\/li>\n<li style=\"margin-bottom:6px;\">A 7.8 vulnerability isn\u2019t critical<\/li>\n<li>Local vulnerabilities require access anyway<\/li>\n<\/ul>\n<\/div>\n<div style=\"background:#fafafa;border-top:3px solid #2d7a3e;padding:18px 20px;border-radius:4px;\">\n<p style=\"margin:0 0 10px 0;font-size:0.78em;font-weight:700;text-transform:uppercase;letter-spacing:0.12em;color:#2d7a3e;\">Reliable Approach<\/p>\n<ul style=\"margin:0;padding-left:18px;color:#333;line-height:1.55;font-size:0.95em;\">\n<li style=\"margin-bottom:6px;\">Actively verify version status across your inventory<\/li>\n<li style=\"margin-bottom:6px;\">Manually update offline systems<\/li>\n<li>Take privilege escalation seriously as part of the attack chain<\/li>\n<\/ul>\n<\/div>\n<\/div>\n<h2 style=\"padding-top:64px;margin-bottom:20px;\">The Blind Spot Is Trust<\/h2>\n<p>The real lesson isn\u2019t in the two CVE numbers. It\u2019s in the unspoken assumption many organizations make: that the security product itself is secure. Endpoint protection runs with high privileges, deep in the system, with access to nearly everything. That\u2019s precisely what makes it a prime target. A vulnerability in the guardian is far more severe than one in any random application.<\/p>\n<p>This isn\u2019t an argument against Defender or endpoint protection in general. It\u2019s an argument for a clear-eyed inventory. Security software belongs in the same patch and monitoring cycle as any other critical component. It doesn\u2019t deserve blind trust just because its purpose is to protect. Excluding it from vulnerability management creates a blind spot in the most sensitive area.<\/p>\n<p>The CISA deadline of June 3 formally applies only to U.S. federal agencies. But its signal is universal. When an agency with a mandate to act prioritizes a vulnerability, it\u2019s a useful benchmark for any DACH organization. The question isn\u2019t whether your organization *must* meet the deadline. The question is whether it *could*.<\/p>\n<h2 style=\"padding-top:64px;margin-bottom:20px;\">What SOCs Should Verify Now<\/h2>\n<p>The first step is an inventory check, not a knee-jerk patch. A SOC should know which Defender platform and engine versions are currently deployed. Only this overview reveals whether automatic updates have taken effect across the board or if certain segments are lagging. Without this visibility, patching is done blind \u2013 and a gap won\u2019t be noticed until it\u2019s exploited.<\/p>\n<p>The second step involves telemetry. Local privilege escalation leaves traces: unusual access to Defender components, manipulated links, processes running with unexpectedly high privileges. These signals belong in detection rules \u2013 not after an incident, but now. An EDR that doesn\u2019t monitor its own integrity is blind at its most critical point.<\/p>\n<p>The third step is organizational. Security software needs a designated owner for its patch status, just like a database server or web gateway. As long as no one is explicitly accountable for ensuring Defender itself is up to date, this task gets lost in the assumption that the system handles it automatically. That assumption is convenient. It\u2019s also why such vulnerabilities persist for weeks.<\/p>\n<h2 style=\"padding-top:64px;margin-bottom:20px;\">Frequently Asked Questions<\/h2>\n<p class=\"st-faq-hint\">Every question is locked. A tap unlocks the answer.<\/p>\n<details>\n<summary><strong>Do I need to manually patch as a Defender user?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">In most cases, no. Microsoft distributes fixes via definition updates. However, you should only rely on this after verifying the actual version status, especially on systems without continuous internet connectivity.<\/p>\n<\/details>\n<details>\n<summary><strong>How dangerous is CVE-2026-41091 really?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">With a CVSS score of 7.8, it is classified as high, but not critical. It does not allow initial infection, but rather the escalation of existing privileges. In a multi-stage attack chain, this is often the decisive step toward full system takeover.<\/p>\n<\/details>\n<details>\n<summary><strong>Which version statuses close the gaps?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">The privilege escalation is fixed with platform version 1.1.26040.8, and the Denial of Service with engine version 4.18.26040.7. Comparing these versions in your inventory shows whether a system is protected.<\/p>\n<\/details>\n<details>\n<summary><strong>What\u2019s the deal with RedSun and UnDefend?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">These are zero-days disclosed in April that, according to Microsoft, overlap with the current vulnerabilities. They indicate that Defender was already a target beforehand. Its inclusion in the KEV catalog now confirms active exploitation.<\/p>\n<\/details>\n<details>\n<summary><strong>Should we switch endpoint protection because of such vulnerabilities?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">No. Every complex security software has vulnerabilities. What matters is integrating them into regular vulnerability management rather than treating them as infallible. Switching shifts the problem \u2013 it doesn\u2019t solve it.<\/p>\n<\/details>\n<div style=\"margin:40px 0 24px 0;\">\n<p style=\"font-weight:700;color:#e6e3da;font-size:1.05em;margin:48px 0 16px;\">More from the MBF Media Network<\/p>\n<div style=\"display:flex;flex-direction:column;gap:14px;margin-bottom:40px;\"><a href=\"https:\/\/www.cloudmagazin.com\/2026\/05\/29\/nvidia-800-vdc-gleichstrom-rechenzentrum-power-architektur-dach\/\" class=\"st-net-card\" style=\"display:block;padding:16px 18px;background:#23261f;border:1px solid rgba(105,216,237,0.22);border-radius:10px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 2px 10px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;\"><span style=\"display:block;margin-bottom:6px;font-size:0.72em;font-weight:700;letter-spacing:0.06em;text-transform:uppercase;color:#0bb7fd;\">cloudmagazin<\/span><span style=\"display:block;color:#e6e3da;line-height:1.45;\">800-V DC in the data center: NVIDIA\u2019s power paradigm shift<\/span><\/a><a href=\"https:\/\/mybusinessfuture.com\/generative-ki-mittelstand-78-prozent-nutzung-wirkung-dihk\/\" class=\"st-net-card\" style=\"display:block;padding:16px 18px;background:#23261f;border:1px solid rgba(105,216,237,0.22);border-radius:10px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 2px 10px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;\"><span style=\"display:block;margin-bottom:6px;font-size:0.72em;font-weight:700;letter-spacing:0.06em;text-transform:uppercase;color:#aa8ac2;\">MyBusinessFuture<\/span><span style=\"display:block;color:#e6e3da;line-height:1.45;\">Generative AI in SMEs: Why the 78-percent figure is misleading<\/span><\/a><a href=\"https:\/\/www.digital-chiefs.de\/hyperscaler-capex-725-milliarden-dach-cio-budget-cloud\/\" class=\"st-net-card\" style=\"display:block;padding:16px 18px;background:#23261f;border:1px solid rgba(105,216,237,0.22);border-radius:10px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 2px 10px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;\"><span style=\"display:block;margin-bottom:6px;font-size:0.72em;font-weight:700;letter-spacing:0.06em;text-transform:uppercase;color:#d65663;\">Digital Chiefs<\/span><span style=\"display:block;color:#e6e3da;line-height:1.45;\">The hyperscaler CapEx gamble and what it means for DACH CIOs<\/span><\/a><\/div>\n","protected":false},"excerpt":{"rendered":"Microsoft Defender has two actively exploited vulnerabilities-one enabling privilege escalation-with a CISA deadline of June 3.","protected":false},"author":50,"featured_media":16389,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_yoast_wpseo_focuskw":"Microsoft Defender vulnerability","_yoast_wpseo_title":"Defender under fire: Two actively exploited vulnerabilities and the blind spot in the SOC","_yoast_wpseo_metadesc":"**\"Microsoft Defender flaws exploited! CISA deadline June 3. Don\u2019t trust unchecked security\u2014act now!\"** (149 chars)","_yoast_wpseo_meta-robots-noindex":"","_yoast_wpseo_meta-robots-nofollow":"","_yoast_wpseo_meta-robots-adv":"","_yoast_wpseo_canonical":"","_yoast_wpseo_opengraph-title":"","_yoast_wpseo_opengraph-description":"","_yoast_wpseo_opengraph-image":"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/06\/microsoft-defender-cve-2026-41091-aktiv-ausgenutzt-cisa-kev-soc-cover-hero.jpg","_yoast_wpseo_opengraph-image-id":0,"_yoast_wpseo_twitter-title":"","_yoast_wpseo_twitter-description":"","_yoast_wpseo_twitter-image":"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/06\/microsoft-defender-cve-2026-41091-aktiv-ausgenutzt-cisa-kev-soc-cover-hero.jpg","_yoast_wpseo_twitter-image-id":0,"_evm_slot_owner":"","evm_cvss":0,"evm_risk":0,"evm_casefile":"","evm_primary_cve":"","evm_pin_until":0,"evm_external_preview_token":"","evm_external_preview_expires":"","_evm_translation_lang":"","featured_post":0,"featured_post_sortierung":0,"_wp_old_slug":[],"footnotes":""},"categories":[255],"tags":[],"class_list":["post-15803","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-praxis-umsetzung-en"],"evm_reading_time_minutes":7,"wpml_language":"en","wpml_translation_of":15794,"_links":{"self":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/15803","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/users\/50"}],"replies":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/comments?post=15803"}],"version-history":[{"count":4,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/15803\/revisions"}],"predecessor-version":[{"id":19600,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/15803\/revisions\/19600"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media\/16389"}],"wp:attachment":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media?parent=15803"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/categories?post=15803"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/tags?post=15803"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}