CVE-2026-41091: Microsoft Defender Link Following Vulnerability
High severity, CVSS 7.8. Actively exploited: in CISA KEV since 2026-05-20. EPSS: 0.4% chance of exploitation in the next 30 days.
Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally.
Affected products
- Microsoft Malware Protection Engine: from 1.1.26030.3008, before 1.1.26040.8 (fixed in 1.1.26040.8)
Published 2026-05-20. Last modified 2026-07-24.