Sploitus

CVE-2026-41091

3 known exploits for CVE-2026-41091

Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally.

Affected products
Defender
Microsoft Malware Protection Engine
< 1.1.26040.8
Fix
Available
CVSS 3.1
7.8 HIGH
EPSS
9.6% (95th percentile)
Weakness
CWE-59
NVD status
Analyzed
Published
2026-05-20
CVE-2026-41091 at NVD
Authoritative description, scoring and affected products

3 known exploits for CVE-2026-41091

Proof-of-concept code and exploit modules indexed by Sploitus