LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-45498: Microsoft Defender Denial of Service Vulnerability

RBRecent Breaches Vulnerability Intelligence·May 20, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jun 3, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-45498 to its Known Exploited Vulnerabilities catalog on May 20, 2026, with a federal patch deadline of Jun 3, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Microsoft Defender contains an unspecified vulnerability that allows for denial of service.

Microsoft Defender is an endpoint security product used to detect and block threats on Windows systems. CVE-2026-45498 is an unspecified vulnerability that permits denial of service against this product, which can interrupt protective functions and leave systems exposed to other attacks.

How it works

This weakness belongs to the denial-of-service class. An attacker can trigger conditions that render Microsoft Defender unavailable or unresponsive. The CISA summary provides no further technical detail on the trigger or affected component, so the precise abuse path must be confirmed against the vendor advisory.

Am I affected? How to find it in your systems

Microsoft Defender runs on Windows endpoints, servers, and some cloud-managed deployments. Inventory all systems running Microsoft Defender through standard endpoint management tools or Microsoft Defender for Endpoint consoles. Compare installed builds against the versions listed in the vendor advisory. Monitor security logs and service health telemetry for unexpected Defender process terminations or repeated restarts that could indicate attempted exploitation.

How to remediate

Apply mitigations per the vendor instructions referenced in the CISA advisory. Where Microsoft Defender is delivered as a cloud service, follow applicable BOD 22-01 guidance. If no effective mitigation is available, discontinue use of the affected product.

If you can't patch immediately

If your data may have been exposed

Actively exploited vulnerabilities lead to breaches. You can run a free exposure scan of your email to check known breach data.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Defender
Added to CISA KEVMay 20, 2026
Federal patch deadlineJun 3, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities