PatchDay Alert

CVE

CVE-2026-45584

0field notes · 1digest CVSS 8.1


Daily digests

A heap-based buffer overflow in the Microsoft Malware Protection Engine lets an attacker run code over the network without any authentication. Because Defender's engine auto-scans incoming files and network content, a specially crafted payload could trigger this just by being received. No user click needed.

Get the digest

Free. Weekday mornings. Plain English CVE triage.

Check your inbox to confirm.