Executive brief
CISA has added seven vulnerabilities to its Known Exploited Vulnerabilities catalog, including legacy flaws in Windows and Internet Explorer as well as modern issues in Microsoft Defender. These vulnerabilities are being actively used by attackers to gain unauthorized access, escalate privileges, or disrupt services. Organizations should prioritize patching these specific flaws to prevent potential data breaches or system outages.
Technical details
This advisory covers seven distinct vulnerabilities added to the CISA KEV catalog due to active exploitation. The flaws include a remote code execution buffer overflow in the Windows Server service (CVE-2008-4250), memory corruption issues in DirectX and Internet Explorer (CVE-2009-1537, CVE-2010-0249, CVE-2010-0806), and a heap overflow in Adobe Acrobat/Reader (CVE-2009-3459). Additionally, two modern vulnerabilities in Microsoft Defender allow for elevation of privilege (CVE-2026-41091) and denial of service (CVE-2026-45498). Attack vectors range from network-based remote exploitation to local privilege escalation. Remediation should follow vendor-specific security updates.
Affected products
- Microsoft Windows
- Microsoft DirectX
- Adobe Acrobat
- Adobe Reader
- Microsoft Internet Explorer
- Microsoft Defender
CVE identifiers
- CVE-2010-0806
- CVE-2009-1537
- CVE-2009-3459
- CVE-2008-4250
- CVE-2026-41091
- CVE-2010-0249
- CVE-2026-45498
Timeline
- 2026-05-20: advisory: CISA published the alert and added vulnerabilities to the KEV catalog.
- 2026-05-20: exploited: CISA confirmed evidence of active exploitation for these vulnerabilities.