Dell’s US$95 billion AI-server backlog and US$74 billion revenue outlook show the AI boom moving beyond a few cloud giants into enterprise, sovereign and neocloud infrastructure procurement.
Meta has come back to the consumer, and it has come back armed. Muse reads inboxes, drives a browser, books travel and pays. Meta has not led with intelligence. It has led with containment. A model that says the wrong thing is an embarrassment. An agent that does the wrong thing is now an incident.
OpenAI's Astra can develop zero-day exploits, while a US$1 billion defence push seeks to give critical infrastructure teams the same machine-speed advantage.
21st May 2026 Cyber Update: CISA’s Latest KEV Batch Shows Old Bugs Still Have a Long Tail
CISA’s latest KEV update mixes new Microsoft Defender flaws with legacy Windows and Adobe bugs, showing why exploited risk often sits in forgotten systems.
The US Cybersecurity and Infrastructure Security Agency has added seven vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalogue, reinforcing a consistent theme in cyber risk: exposure is often driven as much by ageing systems as by newly disclosed flaws.
The latest additions include two recent Microsoft Defender vulnerabilities alongside several legacy issues affecting Windows, Internet Explorer, DirectX, and Adobe Acrobat and Reader, originally identified between 2008 and 2010. The mix of old and new underscores the long tail of unpatched risk across enterprise environments.
What has changed?
CISA confirmed that all seven vulnerabilities were added on the basis of observed active exploitation. The two Microsoft entries are CVE-2026-41091 , an elevation-of-privilege flaw in Microsoft Defender, and CVE-2026-45498, a denial-of-service vulnerability affecting the same product.
Both vulnerabilities are now listed in the KEV catalogue, which many security teams treat as a prioritisation tool rather than a passive advisory source.
The Canadian Centre for Cyber Security has also issued guidance on the Microsoft vulnerabilities, identifying exposure in Microsoft Defender versions prior to 4.18.26040.7 and Microsoft Malware Protection Engine versions prior to 1.1.26040.8. This alignment across agencies elevates the issue from routine patching to an active exploitation priority.
Why it matters
The broader takeaway is that material risk does not always originate from newly disclosed vulnerabilities. Several issues in this update are more than 15 years old, highlighting persistent visibility and remediation gaps.
These gaps often sit in overlooked areas of the environment, including legacy endpoints, outdated system images, dormant applications, unmanaged software, and assets that fall outside standard patching processes.
KEV updates are increasingly viewed as a practical benchmark for vulnerability management maturity. The challenge is no longer the ability to generate extensive scan results, but the capacity to identify actively exploited vulnerabilities, map them accurately to internal systems, and remediate them within a meaningful timeframe.
While artificial intelligence does not directly feature in this update, the implications for AI-supported security operations are clear. The key question is whether AI-driven triage can meaningfully reduce noise and prioritise exploited vulnerabilities, or whether it simply accelerates the processing of existing backlogs without improving outcomes.
For boards and executive teams, the implications are direct. Organisations should confirm that KEV monitoring is embedded as a standing control, ensure Microsoft Defender deployments are current, assess any residual exposure to legacy Windows and Adobe systems, and verify that remediation reporting demonstrates closure rather than activity.
Get the stories that matter to you. Subscribe to Cyber News Centre and update your preferences to follow our Daily 4min Cyber Update, Innovative AI Startups, The AI Diplomat series, or the main Cyber News Centre newsletter — featuring in-depth analysis on major cyber incidents, tech breakthroughs, global policy, and AI developments.
Sign up for Cyber News Centre
Where cybersecurity meets innovation, the CNC team delivers AI and tech breakthroughs for our digital future. We analyze incidents, data, and insights to keep you informed, secure, and ahead.
OpenAI's Astra can develop zero-day exploits, while a US$1 billion defence push seeks to give critical infrastructure teams the same machine-speed advantage.
US authorities have dismantled QTFY’s QScan and QTRouter platforms, exposing a China-linked service model that blended exploit trading, automated scanning and hijacked IoT devices to reach critical infrastructure while concealing where attacks began.
Australia’s cyber agency is warning that attackers are exploiting two N-able N-central authentication bypass flaws locally. For MSPs and enterprise IT teams, a trusted management console can become a route across hundreds of customer endpoints.
A record close on Wall Street and the AI names that were meant to lead it taken apart in the same session. Beijing is now drafting export controls on its own models. The labs keep finding their systems outside the box. Read one at a time, it is a normal week. Read together, something else entirely.
Where cybersecurity meets innovation, the CNC team delivers AI and tech breakthroughs for our digital future. We analyze incidents, data, and insights to keep you informed, secure, and ahead. Sign up for free!