Actively exploitedCVSS 4.0 · MEDIUM
CVE-2026-45498
Microsoft Defender contains an unspecified vulnerability that allows for denial of service.
View on NVDAnalysis
Microsoft Defender is currently being targeted by active exploits in the wild that allow for a Denial of Service. While the severity score is moderate, its presence on the CISA KEV catalog makes it a priority for anyone managing Windows-based development environments or production servers.
Relevant roles
WindowsCyberSecurityCloud
Severity
Score: 4.0(MEDIUM)
Vector:
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:LAV: LOCAL
AC: LOW
PR: NONE
UI: NONE
S: UNCHANGED
C: NONE
I: NONE
A: LOW
Weakness (CWE):
NVD-CWE-noinfoCWE-400CISA KEV
Added to KEV: 2026-05-20
Federal patch deadline: 2026-06-03
Known ransomware use: Unknown
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
EPSS
Probability of exploitation (next 30 days): 0.0372 (3.7%)
Percentile: 88.1%
EPSS: 2026-05-23
Affects
microsoft:defender_antimalware_platformTechnical description
Microsoft Defender Denial of Service Vulnerability
Published: 5/20/2026, 1:16:36 PM
Last modified: 5/20/2026, 7:05:46 PM