NCSC-2026-0236 [1.00] [M/H] Vulnerabilities fixed in Microsoft Defender
Microsoft has fixed vulnerabilities in Defender. An attacker can exploit the vulnerabilities to grant themselves elevated privileges, execute arbitrary code with system rights, and/or gain access to sensitive data. The attacker must deceive the victim into downloading and opening a malicious file.
CSIRTS triage
- What
- Vulnerabilities allow an attacker to grant themselves elevated privileges, execute arbitrary code, and access sensitive data.
- Who is affected
- Users of Microsoft Defender.
- Urgency
- Remediation is necessary as these vulnerabilities could lead to severe impacts, although no exploitation has been reported.
- Action
- Update Microsoft Defender to the latest version to address the vulnerabilities.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Defender
Get an email when a new Defender advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0236
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-550110.37% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 30% of all scored CVEs.
- Low exploitation riskCVE-2026-550120.37% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 30% of all scored CVEs.
- Low exploitation riskCVE-2026-506570.44% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 36% of all scored CVEs.
- Low exploitation riskCVE-2026-506580.19% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 9% of all scored CVEs.
- Low exploitation riskCVE-2026-561780.17% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 6% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-55011 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-55012 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-50657 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-50658 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-56178 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- medium[NEW] [medium] Microsoft Malware Protection Engine and Defender: Multiple vulnerabilitiescert-bund
- unknownMultiple vulnerabilities in Microsoft products (July 15, 2026)cert-fr-avis
- mediumCVE-2026-56178: Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Endpoint allows an…nvd
- highCVE-2026-50658: Time-of-check time-of-use (toctou) race condition in Microsoft Defender allows an authorized a…nvd
- mediumCVE-2026-50657: Exposure of private personal information to an unauthorized actor in Microsoft Defender allows…nvd
- highCVE-2026-55012: Integer overflow or wraparound in Microsoft Defender allows an unauthorized attacker to execut…nvd
- highCVE-2026-55011: Integer underflow (wrap or wraparound) in Microsoft Defender allows an unauthorized attacker t…nvd
- mediumCVE-2026-50657: Microsoft Defender for Endpoint for Mac Information Disclosure Vulnerabilitymsrc
- mediumCVE-2026-56178: Microsoft Defender for Endpoint for Mac Elevation of Privilege Vulnerabilitymsrc
- highCVE-2026-55012: Microsoft Defender Remote Code Execution Vulnerabilitymsrc
- highCVE-2026-50658: Microsoft Defender for Endpoint for Mac Elevation of Privilege Vulnerabilitymsrc
- highCVE-2026-55011: Microsoft Defender Remote Code Execution Vulnerabilitymsrc
Recent advisories for Microsoft Defender
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- medium[NEW] [medium] Microsoft Malware Protection Engine and Defender: Multiple vulnerabilitiescert-bund · 2026-07-15
- mediumCVE-2026-56178: Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Endpoint allows an…nvd · 2026-07-14
- highCVE-2026-50658: Time-of-check time-of-use (toctou) race condition in Microsoft Defender allows an authorized a…nvd · 2026-07-14
- mediumCVE-2026-50657: Exposure of private personal information to an unauthorized actor in Microsoft Defender allows…nvd · 2026-07-14
- highCVE-2026-55012: Integer overflow or wraparound in Microsoft Defender allows an unauthorized attacker to execut…nvd · 2026-07-14
- highCVE-2026-55011: Integer underflow (wrap or wraparound) in Microsoft Defender allows an unauthorized attacker t…nvd · 2026-07-14
More from NCSC-NL Advisories
- unknownNCSC-2026-0274 [1.00] [M/H] Kwetsbaarheid verholpen in SolarWinds Web Help Desk2026-07-31
- unknownNCSC-2026-0273 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Campaign Classic2026-07-31
- unknownNCSC-2026-0272 [1.00] [M/H] Kwetsbaarheden verholpen in JFrog Artifactory2026-07-31
- unknownNCSC-2026-0271 [1.00] [M/H] Vulnerability fixed in Cisco Secure Firewall Management Center2026-07-30
- unknownNCSC-2026-0270 [1.00] [M/M] Vulnerabilities fixed in GitLab by GitLab Inc.2026-07-30