CISA adds seven actively exploited flaws, including Microsoft Defender CVE-2026-41091 and CVE-2026-45498, to KEV catalog

CISA added seven vulnerabilities to its Known Exploited Vulnerabilities catalog on May 20, 2026, citing evidence of active exploitation. The additions include legacy Microsoft Windows, DirectX, Internet Explorer, and Adobe Reader bugs, plus Microsoft Defender flaws CVE-2026-41091 (elevation of privilege) and CVE-2026-45498 (denial of service). Federal agencies must remediate by the deadlines set under BOD 22-01.
Why it matters: KEV additions indicate real-world exploitation and help defenders prioritize patching and mitigations. Organizations, especially federal agencies, should urgently assess exposure to the newly listed Microsoft Defender and legacy Windows-related vulnerabilities.

Sources

Microsoft Tries to Calm Legal Threat Fears After Zero-Day Disclosure Backlash
Eduard Kovacs 2026.06.03 36% relevant
The story intersects because RedSun (CVE-2026-41091) and UnDefend (CVE-2026-45498) are among the disclosed Microsoft flaws discussed in this article, and the piece reiterates that some are exploited in the wild. However, this source is primarily about Microsoft's handling of the disclosure controversy, not CISA's KEV action itself.
Microsoft Patches Exploited UnDefend and RedSun Defender Zero-Days
Ionut Arghire 2026.05.21 96% relevant
This article covers the same underlying event around Microsoft Defender flaws CVE-2026-41091 and CVE-2026-45498 being actively exploited and added to KEV, and adds specific patch details: Microsoft fixed them in Defender Antimalware Platform version 4.18.26040.7, described the impacts as local SYSTEM privilege escalation and DoS, noted disabled Defender systems are not exploitable, and linked the bugs to the publicly released BlueHammer variants RedSun and UnDefend.
Microsoft warns of new Defender zero-days exploited in attacks
Sergiu Gatlan 2026.05.21 96% relevant
This source is about the same underlying event: active exploitation of Microsoft Defender flaws CVE-2026-41091 and CVE-2026-45498. It adds Microsoft's patch rollout details, affected component versions, the impact of each flaw (SYSTEM privilege escalation and DoS), and fixed versions defenders should verify.
CISA Adds Seven Known Exploited Vulnerabilities to Catalog
CISA 2026.05.20 100% relevant
This article is the primary CISA alert establishing a new KEV-driven remediation event covering seven specifically identified exploited CVEs.
← Back to all stories