[NEW] [medium] Microsoft Malware Protection Engine and Defender: Multiple vulnerabilities
An attacker can exploit multiple vulnerabilities in Microsoft Malware Protection Engine and Microsoft Defender to execute arbitrary code, gain elevated permissions, or disclose sensitive information.
CSIRTS triage
- What
- Multiple vulnerabilities can be exploited to execute arbitrary code and disclose sensitive information.
- Who is affected
- Users of Microsoft Malware Protection Engine and Microsoft Defender are affected.
- Urgency
- Remediation is medium priority due to the potential for exploitation.
- Action
- Update Microsoft Malware Protection Engine and Defender to the latest versions.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Malware Protection Engine and Defender
Get an email when a new Malware Protection Engine and Defender advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2322
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-550110.37% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 30% of all scored CVEs.
- Low exploitation riskCVE-2026-550120.37% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 30% of all scored CVEs.
- Low exploitation riskCVE-2026-506580.19% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 9% of all scored CVEs.
- Low exploitation riskCVE-2026-561780.17% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 6% of all scored CVEs.
- Low exploitation riskCVE-2026-506570.44% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 36% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-55011 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-55012 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-50658 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-56178 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-50657 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownMultiple vulnerabilities in Microsoft products (July 15, 2026)cert-fr-avis
- unknownNCSC-2026-0236 [1.00] [M/H] Vulnerabilities fixed in Microsoft Defenderncsc-nl
- mediumCVE-2026-56178: Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Endpoint allows an…nvd
- highCVE-2026-50658: Time-of-check time-of-use (toctou) race condition in Microsoft Defender allows an authorized a…nvd
- mediumCVE-2026-50657: Exposure of private personal information to an unauthorized actor in Microsoft Defender allows…nvd
- highCVE-2026-55012: Integer overflow or wraparound in Microsoft Defender allows an unauthorized attacker to execut…nvd
- highCVE-2026-55011: Integer underflow (wrap or wraparound) in Microsoft Defender allows an unauthorized attacker t…nvd
- highCVE-2026-55011: Microsoft Defender Remote Code Execution Vulnerabilitymsrc
- mediumCVE-2026-56178: Microsoft Defender for Endpoint for Mac Elevation of Privilege Vulnerabilitymsrc
- mediumCVE-2026-50657: Microsoft Defender for Endpoint for Mac Information Disclosure Vulnerabilitymsrc
- highCVE-2026-55012: Microsoft Defender Remote Code Execution Vulnerabilitymsrc
- highCVE-2026-50658: Microsoft Defender for Endpoint for Mac Elevation of Privilege Vulnerabilitymsrc
Recent advisories for Microsoft Malware Protection
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- high[UPDATE] [high] Microsoft Malware Protection Engine: Vulnerability allows privilege escalationcert-bund · 2026-07-10
- criticalexploitedCVE-2017-8540: Microsoft Malware Protection Engine Improper Restriction of Operations Vulnerabilitycisa-kev · 2022-03-03
More from CERT-Bund (BSI) Security Advisories
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow denial of service2026-07-31
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow Denial of Service2026-07-31
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow denial of service2026-07-31
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities2026-07-31
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow unspecified attack2026-07-31