What happened: CISA confirmed that two flaws in Microsoft Defender — the antivirus built into Windows — are being actively exploited. One (CVE-2026-41091) lets an attacker who already has a foothold escalate to full SYSTEM control of the machine. The other (CVE-2026-45498) lets them crash or disable Defender on demand, clearing the way for malware to run unnoticed.

Why it matters to your business

If Microsoft Defender is the only thing protecting your Windows machines — which is the default for most small businesses — this is your problem, not just Microsoft’s. It’s worse anywhere staff share a computer, log into a terminal server, or run older Windows systems. The attack pattern is the one we see constantly: get in through a phishing click, switch off the alarm, then move freely.

What to do this week

Confirm Windows Update is on and set to update Microsoft products, then check that your Defender Antimalware Platform is version 4.18.26040.7 or newer (Windows Security → Virus & threat protection → Settings → About). Don’t assume auto-update already handled it — these platform updates routinely lag days behind.

The bigger picture

This is a textbook case for why one layer of defense isn’t a strategy. When a single tool is both your lock and your alarm, disabling it ends the fight. We wrote about why real protection is built in layers — and why prevention, not recovery, is the only ransomware plan that works: Why the Only True Recovery from Ransomware Is Prevention.