Researcher’s Disclosures Spotlight Microsoft CVD Process
NEOSEC enrichment — no mirror of the original source
In April 2026, a security researcher styled “Nightmare Eclipse” began publishing proof-of-concept (PoC) exploits on GitHub for half a dozen previously unknown and undisclosed vulnerabilities in Microsoft products, described below. On May 27
Source: SANS NewsBites. For licensing reasons NEOSEC Intel does not mirror the full text verbatim. Full body and expert context live with the original.
Read the issue at SANS NewsBites →Linked advisories
- CVE-2026-20230Cisco Unified Communications Manager (CUCM): Schwachstelle ermöglicht Manipulation von Dateien
- CVE-2026-41091Microsoft Defender — Microsoft Defender Link Following Vulnerability
- CVE-2026-41091Microsoft Defender und Malware Protection Engine: Mehrere Schwachstellen
- CVE-2026-41091Microsoft Defender Elevation of Privilege Vulnerability
- CVE-2026-41091Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally.
- CVE-2026-45585Windows BitLocker Security Feature Bypass Vulnerability
- CVE-2026-45585microsoft windows_11_24h2: Improper Neutralization of Special Elements used in a Command ('Command Injection')
- CVE-2026-45585Microsoft is aware of a security feature bypass vulnerability in Windows publicly referred to as "YellowKey". The proof of concept for this vulnera…
- CVE-2026-33825Microsoft Defender — Microsoft Defender Insufficient Granularity of Access Control Vulnerability
- CVE-2026-33825Microsoft Defender Elevation of Privilege Vulnerability
- CVE-2026-33825Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally.
- CVE-2026-9614Ivanti Neurons for ITSM: Schwachstelle ermöglicht Privilegieneskalation
- CVE-2026-9614Ivanti Neurons for ITSM: unzureichende Zugriffskontrolle
- CVE-2026-45498Microsoft Defender — Microsoft Defender Denial of Service Vulnerability
- CVE-2026-45498Microsoft Defender Denial of Service Vulnerability
- CVE-2026-45498Microsoft Defender Denial of Service Vulnerability
Source: https://isc.sans.edu/podcastdetail/9960
ID