CVE-2026-45498: Microsoft Defender Denial of Service Vulnerability

Added to the CISA Known Exploited Vulnerabilities catalog on 20 May 2026. Vendor: Microsoft. Product: Defender.

Microsoft Defender contains an unspecified vulnerability that allows for denial of service.

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. (due 03 Jun 2026)