CVE-2026-45498Medium· 4.0▾ Midnight⚠ Exploited in the wild0dayPoC availableMicrosoft Defender Denial of Service Vulnerability
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 22 · likelihood 12.6 · exploitation 25
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Jul 23.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Federal remediation due Jun 3, 2026
Last analysed / modified upstream
63%
1 GitHub repo
Added to the CISA catalog on May 20, 2026. Federal remediation due Jun 3, 2026. View catalog ↗
Microsoft Defender Denial of Service Vulnerability
defender_antimalware_platform < 4.18.26040.7Upgrade past the affected range:
defender_antimalware_platform 4.18.26040.7Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-85880High· 7.8Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.
CVE-2026-81963High· 7.8Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.
CVE-2026-83968High· 7.8Use after free in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-83991Medium· 5.5Missing authentication for critical function in Windows Cloud Files Mini Filter Driver allows an authorized attacker to perform tampering locally.
CVE-2020-3563High· 8.6A vulnerability in the packet processing functionality of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device
CVE-2020-3554High· 7.5A vulnerability in the TCP packet processing of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) conditi…