A publicly disclosed zero-day dubbed ShieldBreak (CVE-2026-69414) affects the Microsoft Malware Protection Engine used by Microsoft Defender and allows an authenticated local attacker to escalate from a standard user account to NT AUTHORITY\SYSTEM. Researchers reported that the flaw bypasses Microsoft's earlier July fix for RoguePlanet (CVE-2026-50656), and a working proof-of-concept has been released. Microsoft acknowledged the issue and said it is developing a fix, but no patch was available at publication.
Reports say the vulnerability impacts modern Windows environments where Microsoft Defender is enabled, including Windows 11 25H2 and Windows Server 2025, with one source also listing Windows 10 as affected while another said Windows 10 exposure remained unconfirmed. The issue is not remote and requires prior code execution or authenticated local access, but defenders were urged to treat it as high risk because public exploit code lowers the barrier to abuse. Recommended interim actions include restricting local access, monitoring for privilege-escalation behavior and suspicious processes, validating EDR/EPP coverage, enabling protections such as Tamper Protection and Attack Surface Reduction where appropriate, and applying Microsoft's patch as soon as it becomes available.

Get the actors, campaigns, and ATT&CK mapping behind it.
6 events from the most recent confirmed update back to the earliest known activity.
Check Point Research attributed exploitation of the Windows WinSock driver privilege-escalation flaw CVE-2026-68820 to North Korea's Lazarus Group in Operation Dream Job. The campaign reportedly used a malicious PDF viewer named SecurityPDF with fake job-offer lures against aerospace and defense targets to gain SYSTEM privileges.
Microsoft acknowledged the issue as CVE-2026-69414 in the Microsoft Malware Protection Engine and said it was working on a security update. At the time of reporting, no patch had been released.
Independent researchers, including Will Dormann and Kevin Beaumont, reproduced the ShieldBreak proof of concept and confirmed it can elevate a low-privileged authenticated user to NT AUTHORITY\SYSTEM on fully patched affected systems.
A researcher using the alias Nightmare Eclipse published a working proof-of-concept exploit called ShieldBreak that bypasses Microsoft's July RoguePlanet fix and enables local privilege escalation to SYSTEM on affected Defender-enabled Windows systems.
Microsoft released a July 2026 fix for CVE-2026-50656, also called RoguePlanet, affecting the engine behind Windows Defender. Later reporting says this patch addressed only one access method and did not fully fix the underlying flaw.
CISA released Binding Operational Directive 26-04, which the reporting says requires 14-day remediation for vulnerabilities that have a public exploit and active exploitation risk but are not automatically exploitable.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
3 references tracked. Mallory keeps watching after this page renders.
cert.ug
Open sourcethreataft.com
Open sourcetriskelelabs.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.