Windows Defender Privilege Escalation Active Exploitation | MSSP Advisory

Critical
DateMay 21, 2026
📋Executive Summary
Microsoft disclosed two actively exploited vulnerabilities in Windows Defender, including CVE-2026-41091, a privilege escalation flaw rated 7.8 CVSS that allows attackers to gain SYSTEM privileges through improper link resolution. A second denial-of-service vulnerability is also under active exploitation but lacks specific details in the disclosure.
⚠️Why It Matters for MSSPs
Your RMM agents and remote access tools rely on Defender running properly on every endpoint you manage, and compromised SYSTEM privileges means attackers can disable your security stack entirely. Every client running Windows has Defender deployed by default, and active exploitation means this is happening right now across your client base.
Recommended Action
Deploy Microsoft's security updates through your RMM platform immediately and verify Defender is updated to the latest version on all managed endpoints within 24 hours.
🔒
Partner content — get access free
The recommended action is included in your white-labeled advisory — ready to send to clients under your name.
Get your first advisory free →
🏷️Threat Category
Zero-Day

Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.