Microsoft patches Defender zero-days exploited in live attacks
… They had no CVEs and no fixes when first released. Endpoint security firm Huntress confirmed active exploitation before the patches existed. What the two zero-days do The more severe of the two, CVE-2026-41091 , carries a CVSS score of 7.8 and targets the Microsoft Malware Protection Engine. …