🔴
CISA KEV Alert — Active Real-World Exploitation Confirmed
This vulnerability is in the CISA Known Exploited Vulnerabilities catalog and is being actively exploited right now.
Microsoft Defender Malware Protection Engine Privilege Escalation (CVE-2026-41091) | MSSP Advisory
Critical🔴 KEV ALERTConfirmed
DateMay 21, 2026
CVECVE-2026-41091, CVE-2026-45498
CVSS Score7.8
Affectedmalware_protection_engine
📋Executive Summary
Two Microsoft Defender vulnerabilities are being exploited in the wild, with CISA adding them to its Known Exploited Vulnerabilities catalog. CVE-2026-41091 allows attackers to escalate privileges to SYSTEM level through improper link resolution in the Malware Protection Engine, while CVE-2026-45498 enables denial-of-service attacks. Both vulnerabilities target the core security engine that most Windows environments depend on for endpoint protection.
⚠️Why It Matters for MSSPs
Your RMM agents and remote access tools run with elevated privileges on client systems protected by Defender, making them prime targets if an attacker gains SYSTEM access through these vulnerabilities. Every client running Windows Defender becomes a potential entry point for lateral movement, and you need to advise them immediately since these are confirmed active exploits, not theoretical risks.
✅Recommended Action
Deploy Microsoft security updates for Defender immediately across your own infrastructure and client environments within 24 hours, then communicate the criticality to all clients running Windows Defender.
🔒Get your first advisory free →
Partner content — get access free
The recommended action is included in your white-labeled advisory — ready to send to clients under your name.
🏷️Threat Category
Zero-Day
Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.