Vulnerability intelligence
CVE-2026-69414
Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "ShieldBreak ".
CVSS Score
7.8
High
EPSS — Exploit Probability
0.3%
Riskier than 23% of all CVEs · checked 2026-10-01
Exploitation
Not in CISA KEV
KEV does not include every exploited vulnerability
Remediation
Patch available
Vendor fix published
7 articles across 7 outlets · first covered Aug 17, 2026 · latest Sep 10, 2026
Associated threat actors
Coverage timeline
-
Windows Defender Patch Bypass Exposes SYSTEM Files to Attackerswww.darkreading.com · Sep 10, 2026
-
Public ShieldCrash PoC Claims to Bypass Microsoft Defender Fixsocradar.io · Sep 10, 2026
-
Microsoft Defender Zero Day Bypasses Patches to Expose Windows Systemswww.securityweek.com · Sep 10, 2026
-
Microsoft Defender Zero Day Bypasses Patch to Read Windows Files as SYSTEMthehackernews.com · Sep 9, 2026
-
ShieldCrash PoC Revives Microsoft Defender SYSTEM File Read Flawsecurityaffairs.com · Sep 9, 2026
-
Microsoft Defender 0day PoC Exposes SYSTEM Files on Windowssecurityonline.info · Sep 9, 2026
-
ShieldBreak bypasses Microsoft’s patch for earlier Defender flawwww.malwarebytes.com · Aug 17, 2026