CISA KEV Catalog Adds Seven Vulnerabilities (May 20, 2026) — Microsoft Defender CVE-2026-41091 (EoP) and CVE-2026-45498 (DoS) Headline Active Exploitation Batch — Threadlinqs Intelligence
As of 2026-05-30, CISA KEV Catalog Adds Seven Vulnerabilities (May 20, 2026) — Microsoft Defender CVE-2026-41091 (EoP) and CVE-2026-45498 (DoS) Headline Active Exploitation Batch is a high-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 16 indicators of compromise.
Threat ID: TL-2026-0545 · Severity: HIGH · CVSS: 8.8 · Status: ACTIVE · Category: VULNERABILITY
On May 20, 2026, CISA added seven vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active in-the-wild exploitation. The batch includes two new Microsoft
On May 20, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) published a Known Exploited Vulnerabilities (KEV) Catalog update adding seven CVEs based on confirmed evidence of in-the-wild exploitation. Inclusion in the KEV catalog triggers Binding Operational Directive (BOD) 22-01 obligations: U.S. Federal Civilian Executive Branch (FCEB) agencies must remediate the listed vulnerabilities by the assigned due date, and the catalog is widely adopted as the de facto patch prioritization standard across critical infrastructure, private sector, and allied governments.
The two newly disclosed 2026 vulnerabilities — both affecting Microsoft Defender — represent the immediate operational priority. CVE-2026-41091 is an Elevation of Privilege flaw in the Microsoft Defender Antimalware Service (MsMpEng.exe / MpClient.dll) signature deserialization path. A locally authenticated, low-privileged user can stage a crafted on-disk artifact that, when consumed by the Defender real-time scanning engine, triggers a type-confusion condition in the signature parser. Because the scanning engine runs as NT AUTHORITY\SYSTEM, successful exploitation yields full SYSTEM privileges on the host. The technique is amenable to chaining with browser or Office sandbox escapes and has been observed used post-initial-access by intrusion sets operating against U.S. and EU enterprise targets.
CVE-2026-45498 is a Denial-of-Service in the same component reachable via a malformed scan request to the MpsSvc named-pipe interface or via crafted file content evaluated during synchronous on-access scanning. Triggering the bug crashes MsMpEng.exe; on hosts with Tamper Protection and watchdog recovery enabled the service restarts, but repeated triggering produces a sustained scan-evasion window during which attacker payloads execute without antimalware coverage. Observed tradecraft pairs CVE-2026-45498 with execution of secondary loaders (Cobalt Strike, Brute Ratel, SystemBC) immediately after the Defender crash window opens.
The five legacy CVEs reflect persistent exploitation against unpatched legacy estates and air-gapped or sanctioned-region networks where Microsoft Update has not been applied: CVE-2008-4250 (MS08-067 NetAPI32.dll path-canonicalization remote code execution — the Conficker worm vector, still observed against legacy Windows XP/2003 manufacturing and OT estates), CVE-2009-1537 (DirectX DirectShow QuickTime parser NULL-byte overwrite), CVE-2009-3459 (Adobe Acrobat/Reader U3D heap overflow), CVE-2010-0249 (Internet Explorer 'Aurora' use-after-free — original Operation Aurora vector attributed to APT17/Elderwood, still observed in commodity malware kits targeting legacy thin clients), and CVE-2010-0806 (Internet Explorer iepeers.dll use-after-free).
Exploit chain for the Defender EoP (CVE-2026-41091): (1) initial access via phishing or web exploit, (2) low-privileged code execution as a standard user, (3) attacker writes a crafted file to a path scanned by Defender real-time protection, (4) Defender's signature parser deserializes attacker-controlled type metadata, (5) type confusion permits arbitrary read/write within the Defender process, (6) attacker pivots to SYSTEM and disables further Defender protections, (7) follow-on tooling (C2 beacon, credential dump) executes without antimalware coverage.
For the Defender DoS (CVE-2026-45498): (1) attacker establishes any code execution context, (2) sends malformed IPC payload to MpsSvc or stages crafted content evaluated by synchronous scanning, (3) MsMpEng.exe crashes, (4) attacker race-executes secondary payload within the recovery window, (5) cycle repeats to sustain scan-evasion.
Remediation: apply Microsoft Defender platform updates (Defender Platform 4.18.26050.x and later) and signature build 1.421.x or higher; verify Tamper Protection is enabled; ensure ASR rules covering 'Block credential stealing' and 'Block process creations originating from PSExec/WMI' are in audit-then-enforce mo
Weaknesses (CWE)
CWE-269, CWE-400, CWE-416, CWE-122, CWE-119, CWE-843, CWE-502
Target sectors: government, defense industrial base, financial services, healthcare, energy, manufacturing, critical infrastructure
Target regions: North America, Europe, Asia-Pacific, Global
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 16 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, HIGH, threat intelligence, cybersecurity, CVE-2026-41091, CVE-2026-45498, CVE-2008-4250, CVE-2009-1537, CVE-2009-3459, CVE-2010-0249, CVE-2010-0806, T1190, T1189, T1203, T1204, T1547, T1068, T1548, T1562, T1562, T1070