🔴
CISA KEV Alert — Active Real-World Exploitation Confirmed
This vulnerability is in the CISA Known Exploited Vulnerabilities catalog and is being actively exploited right now.

Microsoft Defender Privilege Escalation LPE (CVE-2026-41091) | MSSP Advisory

High🔴 KEV ALERTConfirmed
DateMay 20, 2026
CVECVE-2026-41091
📋Executive Summary
CISA added CVE-2026-41091 to the Known Exploited Vulnerabilities catalog, flagging a privilege escalation flaw in Microsoft Defender that lets authorized attackers gain local admin rights. Your RMM agents and client endpoints running Defender are exposed to attackers who already have initial access turning that foothold into full system control.
⚠️Why It Matters for MSSPs
Your management stack likely runs Defender across dozens of client networks, creating a pathway for attackers to escalate from limited user access to domain admin privileges. Client environments expect you to flag critical security tool vulnerabilities before they become breach vectors, and missing this creates both technical risk and contract liability.
Recommended Action
Audit all client environments for Defender versions within 24 hours and apply Microsoft patches immediately where available. For any systems where patches are not yet released, document the risk in client communications and consider temporary endpoint protection alternatives for high-value assets.
🔒
Partner content — get access free
The recommended action is included in your white-labeled advisory — ready to send to clients under your name.
Get your first advisory free →
🏷️Threat Category
Vulnerability Disclosure

Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.