Five legacy Microsoft flaws from 2008-2010 join two current Microsoft Defender vulnerabilities on federal remediation list
- CISA added seven vulnerabilities to its Known Exploited Vulnerabilities catalog based on evidence of active exploitation
- Five vulnerabilities date from 2008-2010, affecting Windows, Internet Explorer, and DirectX components
- Two current vulnerabilities affect Microsoft Defender, including privilege escalation and denial of service flaws
The US Cybersecurity and Infrastructure Security Agency has added seven vulnerabilities to its Known Exploited Vulnerabilities catalog based on evidence that threat actors are actively exploiting them.
Five of the newly catalogued vulnerabilities are legacy Microsoft flaws from 2008 to 2010. These include CVE-2008-4250, a Windows buffer overflow vulnerability, and CVE-2009-1537, a DirectX null byte overwrite flaw. Three Internet Explorer use-after-free vulnerabilities round out the older entries: CVE-2009-3459 affecting Adobe Acrobat and Reader, plus CVE-2010-0249 and CVE-2010-0806 in Internet Explorer itself.
Two current vulnerabilities affecting Microsoft Defender complete the list. CVE-2026-41091 allows elevation of privilege attacks, whilst CVE-2026-45498 enables denial of service attacks against the security software.
CISA’s Known Exploited Vulnerabilities catalog serves as a prioritised list for federal agencies under Binding Operational Directive 22-01. The directive requires Federal Civilian Executive Branch agencies to remediate catalogued vulnerabilities by specified due dates.
The catalog operates as what CISA describes as “a living list of known Common Vulnerabilities and Exposures that carry significant risk to the federal enterprise”. Vulnerabilities earn catalog inclusion when CISA finds evidence of active exploitation by malicious actors.
Whilst the binding directive applies only to federal agencies, CISA urges all organisations to use the catalog for vulnerability management prioritisation. The agency continues adding vulnerabilities that meet its specified criteria for active exploitation evidence.
Why It Matters
The mix of legacy and current vulnerabilities highlights persistent patching challenges that CISOs face across enterprise environments. Legacy systems running decades-old software remain attractive targets for attackers, whilst current security tools like Microsoft Defender show that even protective software requires ongoing security maintenance.
For CISOs, the catalog provides evidence-based prioritisation for patch management programmes. Unlike theoretical vulnerability scoring, KEV catalog entries represent active threats that adversaries are exploiting in the wild, making them suitable for board reporting on immediate security risks.
What To Do Now
- Review your environment for affected Microsoft Windows, DirectX, Internet Explorer, Adobe Acrobat/Reader, and Microsoft Defender installations against the newly catalogued vulnerabilities
- Prioritise patching for any identified instances, particularly the current Microsoft Defender flaws CVE-2026-41091 and CVE-2026-45498
- Use CISA’s KEV catalog as a prioritisation framework for vulnerability management programmes beyond federal compliance requirements
