CVE-2026-41091CISA KEV
Microsoft Defender Link Following Vulnerability
CISA lists this Microsoft vulnerability as known exploited. Its MSRC release detail is outside this installation's collected history.
CISA catalog record
Microsoft Defender contains a link following vulnerability that allows an authorized attacker to elevate privileges locally.
- Product
- Defender
- Added to KEV
- 20 May 2026
- Federal remediation due
- 3 Jun 2026
- Known ransomware use
- Not reported