www.securityweek.com 10 Sept 2026, 07:09 UTC

Microsoft Defender Zero Day Bypasses Patches to Expose Windows Systems

Microsoft Defender Zero Day Bypasses Patches to Expose Windows Systems
CyberSIXT Evidence Panel Source marked as original reporting
CISA KEV Not in KEV
Patch Patch Available
Threat Actor
Nightmare Eclipse

SECURITY researchers have disclosed a new Microsoft Defender zero-day exploit, dubbed ShieldCrash, that can achieve full System privileges on fully patched Windows systems. The PoC reportedly demonstrates arbitrary file read at System level, with the underlying flaw capable of dropping the SAM database, according to the researcher behind the tool, Nightmare Eclipse (also known as Chaotic Eclipse, Infinite Nightmare and MSNightmare).

ShieldCrash appears to bypass prior mitigations introduced by the ShieldBreak family of Defender exploits, which were issued as patches for RoguePlanet and other chain-attack pathways.

The disclosure follows Microsoft’s Patch Tuesday cycle in September 2026, after RoguePlanet (CVE-2026-50656) was addressed in July and ShieldBreak (patched in September 2026; CVE-2026-69414) with incomplete fixes, according to Nightmare Eclipse. Security researchers, including SOCRadar’s Ensar Seker, warn that ShieldCrash highlights weaknesses in patching attack paths rather than isolated flaws.

They advise defenders to monitor Microsoft guidance and Defender intelligence updates, enable tamper protections, restrict administrative and local execution paths, and watch for suspicious Defender-related process activity. Microsoft has not yet publicly commented at press time.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline