← Blog
🛡️ Vulnerability15 July 2026

CVE-2026-45498: denial-of-service vulnerability in Microsoft Defender, on the radar for active exploitation

CVE-2026-45498 affects Microsoft Defender with confirmed active exploitation. What it is, who it affects, and how to protect yourself.

OCIRIA security team

CVE-2026-45498: denial-of-service vulnerability in Microsoft Defender, on the radar for active exploitation

In short

CVE-2026-45498 is a denial-of-service (DoS) vulnerability in Microsoft Defender [1], rated medium severity with a CVSS score of 4.0 [1]. Its active exploitation is confirmed, as it appears in the CISA KEV catalog of known exploited vulnerabilities [2]. It affects Microsoft as the vendor [1]. If your organization uses Windows with Microsoft Defender, what needs to be done today is verify that Defender patches are applied and that the antimalware service status is being monitored normally.

What it is and why it matters

According to the official description, this is a denial-of-service vulnerability in Microsoft Defender [1]. In business terms, this means an attacker could cause Defender itself to stop working correctly [1], reducing active antimalware protection on the affected machine. The vulnerability is registered with medium severity and CVSS 4.0 according to NVD [1], a relatively low score on the technical scale. However, the reason it deserves attention is not its score, but the fact that it is already listed as actively exploited in the CISA KEV catalog [2]: that is, it is not a theoretical risk, but something that is already being used in the real world. Our OCIRIA intelligence radar classifies this case with a high priority precisely because of that combination of confirmed exploitation and impact on Windows' primary security tool.

Who it affects

The affected vendor is Microsoft [1], and the vulnerability is located in Microsoft Defender. Defender comes integrated by default in Windows, so any organization using this operating system should check whether it applies to them, although we do not have an official figure for the specific number of machines or organizations affected. The recorded publication date is May 20, 2026 [1].

How to know if you are vulnerable

We do not have public data detailing the exact Defender versions affected or technical indicators of compromise beyond what has been published. Therefore, the general and prudent recommendation is:

  • Review the update status of Microsoft Defender on the organization's machines, especially those handling sensitive data or critical infrastructure.
  • Check that the Defender service is active and running normally, not just installed.
  • Review your internet-facing attack surface to identify publicly visible Windows systems that could be an easier entry point for attempting this type of attack.

How to protect yourself

1. Apply the Microsoft Defender and Windows updates available through Microsoft's official channels as soon as possible.

2. Monitor the availability of the antimalware service on your machines: if Defender stops or fails unexpectedly, treat it as a signal to investigate, not just a one-off error.

3. Prioritize the most exposed machines, such as those with direct internet access or that manage critical business operations.

4. Document the patching process so you can demonstrate, if a client, auditor, or insurer requests it, that the organization acted diligently in response to a vulnerability with confirmed active exploitation [2].

5. Maintain an additional layer of security (firewall, complementary EDR, tested backups) so as not to rely on a single protection tool.

FAQ

Is this a critical vulnerability?

According to NVD, its severity is medium and its CVSS is 4.0 [1], a moderate technical score. What makes it relevant is not the score, but the fact that it is already being actively exploited according to CISA KEV [2].

What does it mean that it causes a denial of service in Defender?

It means an attacker can cause Microsoft Defender to stop working correctly [1]. There is no official data on whether this occurs in a way that is noticeable to the user or not, so no additional unconfirmed behavior should be assumed.

Do I need to act even if my CVSS score seems low?

Yes. Being listed in the CISA KEV catalog [2] indicates confirmed active exploitation, a criterion that many organizations use to prioritize patching above the numerical score.

How do I know if my systems are exposed?

Reviewing which Windows and Defender assets are visible from the internet is a good starting point for assessing your organization's real risk.

Sources

  • [1] https://nvd.nist.gov/vuln/detail/CVE-2026-45498
  • [2] https://raw.githubusercontent.com/cisagov/kev-data/develop/known_exploited_vulnerabilities.json
OCIRIA security team Threat monitoring & response · data from our real-time radar Live radar