Microsoft confirms Defender zero-day ShieldBreak as CVE-2026-69414 and says a patch is in development

Microsoft says it is working on a fix for ShieldBreak, a publicly disclosed Microsoft Defender flaw that can let a low-privilege user gain full SYSTEM control on affected Windows systems. The issue is now tracked as CVE-2026-69414 in the Microsoft Malware Protection Engine used by Microsoft Defender. Researcher Nightmare Eclipse says it bypasses the earlier RoguePlanet fix, and public proof-of-concept code reportedly works on fully patched Windows 10, Windows 11, and Windows Server systems when Defender is enabled.
Why it matters: Organizations using Microsoft Defender on Windows should treat this as urgent because public exploit code is available and no patch is out yet. Defenders should monitor for local privilege-escalation abuse, restrict untrusted local access, and watch for Microsoft's security update.

Sources

Microsoft Rolls Out 22 Fresh Security Patches
Ionut Arghire 2026.08.21 28% relevant
This article briefly updates the ShieldBreak story by noting Microsoft is still working on a fix for the publicly disclosed Defender elevation-of-privilege zero-day now tracked as CVE-2026-69414, but the article's main focus is a separate batch of 22 fresh Microsoft patches.
Microsoft working on Defender patch for ShieldBreak zero-day
Sergiu Gatlan 2026.08.17 100% relevant
This article establishes a distinct tracked event by adding Microsoft's confirmation, a CVE assignment, and patch-in-development status for the ShieldBreak Defender zero-day.
← Back to all stories