CVE-2026-55011: Microsoft Malware Protection Engine

High severity, CVSS 7.8. EPSS: 0.5% chance of exploitation in the next 30 days.

Integer underflow (wrap or wraparound) in Microsoft Defender allows an unauthorized attacker to execute code locally.

Affected products

  • Microsoft Malware Protection Engine: before 1.1.26060.3008 (fixed in 1.1.26060.3008)

Published 2026-07-14. Last modified 2026-07-24.