Skip to content
Actively exploitedCVSS 4.0 · MEDIUM

CVE-2026-45498

Microsoft Defender contains an unspecified vulnerability that allows for denial of service.

View on NVD

Analysis

Microsoft Defender is currently being targeted by active exploits in the wild that allow for a Denial of Service. While the severity score is moderate, its presence on the CISA KEV catalog makes it a priority for anyone managing Windows-based development environments or production servers.

Relevant roles

WindowsCyberSecurityCloud

Severity

Score: 4.0(MEDIUM)
Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
AV: LOCAL
AC: LOW
PR: NONE
UI: NONE
S: UNCHANGED
C: NONE
I: NONE
A: LOW
Weakness (CWE): NVD-CWE-noinfoCWE-400

CISA KEV

Added to KEV: 2026-05-20
Federal patch deadline: 2026-06-03
Known ransomware use: Unknown
Required action

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

EPSS

Probability of exploitation (next 30 days): 0.0372 (3.7%)
Percentile: 88.1%
EPSS: 2026-05-23

Affects

microsoft:defender_antimalware_platform

Technical description

Microsoft Defender Denial of Service Vulnerability

Published: 5/20/2026, 1:16:36 PM
Last modified: 5/20/2026, 7:05:46 PM

References

HomeEventsBlogResourcesTeam