Latest Updates
Last checked: August 17, 2026.
- August 2026 – Windows Defender’s virus and spyware definitions have continued shipping on their normal cadence, with definition updates released August 10, August 14, and August 16, 2026, plus a security intelligence update on August 15, 2026.
- These definitions build on the Malware Protection Engine update (version 1.1.26040.8) that fixed CVE-2026-45584, a critical remote code execution vulnerability, and CVE-2026-50656, an elevation-of-privilege flaw.
We’ll keep this section updated as Microsoft ships new Defender definitions and engine updates.
What the Recent Security Patches Fix
Two vulnerabilities are worth knowing about if you rely on Windows Defender as your primary antivirus:
- CVE-2026-45584 – A heap-based buffer overflow in the Microsoft Malware Protection Engine, rated Critical with a CVSS score of 8.1. Because Defender runs with SYSTEM privileges and scans files automatically, a successful exploit could lead to full system compromise. It was added to CISA’s Known Exploited Vulnerabilities catalog, meaning it had already been used in real attacks.
- CVE-2026-50656 – An elevation-of-privilege vulnerability that improves protection against local privilege escalation on affected systems.
Both are fixed by the updated Malware Protection Engine (1.1.26040.8) and the Defender Antimalware Platform (4.18.26040.7), which install automatically alongside regular definition updates on most systems.
How to Check Windows Defender Is Up to Date
- Open Windows Security from the Start menu.
- Select Virus & threat protection.
- Under Virus & threat protection updates, click Check for updates.
- Confirm the Antimalware Client Version is 4.18.26040.7 or later, and the engine version is 1.1.26040.8 or later. Both are listed under Virus & threat protection > Virus & threat protection updates > Protection updates.
- If you’re behind, click Check for updates again or run Windows Update, since engine updates are sometimes delivered that way.
Why This Matters Even If You Use Third-Party Antivirus
Windows Defender runs in the background on most Windows 10 and 11 machines even when a third-party antivirus like Malwarebytes or Panda is installed for real-time protection, since some of its scanning components stay active. Keeping both your primary antivirus (see our guide on fixing Malwarebytes error code 20025 if you run into issues) and Defender’s engine updated closes gaps that either one alone might miss.
FAQ
What does CVE-2026-45584 affect?
It’s a critical heap-based buffer overflow in the Microsoft Malware Protection Engine used by Windows Defender, which could allow remote code execution if exploited.
Do I need to manually install the Defender security patch?
Usually not. The Malware Protection Engine and definition updates install automatically, but you can force a check under Windows Security > Virus & threat protection > Check for updates.
How do I know if my Defender engine is patched?
Open Windows Security, go to Virus & threat protection updates, and check that the Antimalware Client Version is 4.18.26040.7 or later.
Was CVE-2026-45584 actively exploited?
Yes. It was added to CISA’s Known Exploited Vulnerabilities catalog, which only lists flaws confirmed to have been used in real-world attacks.
Conclusion
Windows Defender’s August 2026 updates close out a critical remote code execution flaw and an elevation-of-privilege bug, both delivered quietly through routine definition updates. Since Defender updates mostly happen automatically, a quick manual check is enough to confirm you’re protected.