- Microsoft patches two actively exploited zero‑day flaws in Defender, tracked as CVE‑2026‑41091 (privilege escalation) and CVE‑2026‑45498 (denial of service)
- Updates were shipped automatically via Malware Protection Engine 1.1.26040.8 and Antimalware Platform 4.18.26040.7, though users are advised to manually verify versions
- CISA added both bugs to its KEV catalog, giving federal agencies until June 3 to patch or discontinue vulnerable software
Microsoft has released patches for two zero-day vulnerabilities affecting its Defender antivirus tool.