CISA added seven known exploited vulnerabilities to its KEV catalog, including two Microsoft Defender flaws.

Microsoft has confirmed an emergency security update as CISA warns that two new Defender zero-days are being exploited by attackers.

On Wednesday, Microsoft started rolling out security patches for two Defender vulnerabilities that have been exploited in zero-day attacks.

Microsoft distribuisce patch urgenti per due gravi vulnerabilità di Defender già sfruttate in attacchi reali.

Microsoft has patched RedSun and UnDefend, two Defender zero-day vulnerabilities dropped publicly last month.

Active Defender exploits hit CVE-2026-41091 and CVE-2026-45498; June 3 fixes reduce SYSTEM and DoS risk.

It doesn't require a lot of effort.

CISA added seven known exploited vulnerabilities to its KEV catalog, including two Microsoft Defender flaws.

CISA added two exploited bugs to KEV, forcing federal agencies to patch Langflow and Apex One flaws by June 4, 2026.