CVE-2026-69414

Published Aug 14, 2026

Last updated a month ago

Overview

Description
Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "ShieldBreak ".
Source
secure@microsoft.com
NVD status
Modified
Products
malware_protection_engine

Risk scores

CVSS 3.1

Type
Secondary
Base score
7.8
Impact score
5.9
Exploitability score
1.8
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

secure@microsoft.com
CWE-284
nvd@nist.gov
NVD-CWE-noinfo
134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-269

Social media

Hype score
Not currently trending
  1. 🚨 𝗛𝗜𝗚𝗛 𝗦𝗘𝗩𝗘𝗥𝗜𝗧𝗬 𝗩𝗨𝗟𝗡𝗘𝗥𝗔𝗕𝗜𝗟𝗜𝗧𝗬 𝗔𝗟𝗘𝗥𝗧 | 𝗖𝗩𝗘-𝟮𝟬𝟮𝟲-𝟲𝟵𝟰𝟭𝟰 🚨 🔗 Learn More CVE: CVE-2026-69414 CERT-In: CERT-In Vulnerability Note CIVN-2026-0453 Micr

    @rootniklabs

    15 Sept 2026

    51 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. Currently no official patch for ShieldCrash CVE-2026-69414

    @0xShekhar

    14 Sept 2026

    52 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  3. Araştırmacı, Microsoft Defender'daki Yamalanmış Bir Açığı Atlatan Yeni Bir Sıfır Gün Ortaya Çıkardı: ShieldCrash! Nightmare Eclipse takma adlı araştırmacı, daha önce yamalanan CVE-2026-69414 (ShieldBreak) açığını atlatan ve SYSTEM yetkisiyle rastgele dos

    @BTHaberler

    14 Sept 2026

    7 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 🔒 CYBERSECURITY, PRIVACY & OPEN SOURCE ROUNDUP — September 13, 2026 1️⃣ WINDOWS DEFENDER ZERO-DAY STILL BYPASSABLE Microsoft's fix for the "ShieldBreak" zero-day (CVE-2026-69414) in Windows Defender has not fully closed the door: researcher Nightmare-Eclipse publis

    @TraffAlex

    13 Sept 2026

    338 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  5. باحث أمني نشر استغلالاً لثغرة جديدة في ديفندر مايكروسوفت تتيح قراءة الملفات بصلاحيات النظام. الاستغلال : ShieldCrash PoC - bypass CVE-2026-69414 المنصة : Windows 10 / 11 / Server (Sep 2

    @KasperskyDev

    12 Sept 2026

    161 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. Recent zero-days: WinSock AFD.sys (CVE-2026-68820) actively exploited, Defender (CVE-2026-69414) unpatched EoP. NatJack attacks hijack TCP/DNS. Data privacy/integrity severely impacted. (Aug 2026) #Cybersecurity #Vulnerabilities #News

    @YourAnon_irc

    1 Sept 2026

    45 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. 🚨High - Microsoft Defender Malware Protection Engine EoP ("ShieldBreak") (CVE-2026-69414) Microsoft Malware Protection Engine (mpengine.dll) in Microsoft Defender has an elevation of privilege flaw. Exploitation is triggered via local interaction with Defender’s scanning/en

    @UpwindMDR

    24 Aug 2026

    70 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. 🚨 August 19, 2026 Patch Advisories Today's advisories target these CVEs; - Microsoft Defender ShieldBreak (CVE-2026-69414) - SharePoint full RCE chain (CVE-2026-55040 and CVE-2026-63520 - Windows DNS Server (CVE-2026-62878, CVSS 9.8) https://t.co/fR71dyoG2H | #CyberSafeUG h

    @CERT_UG

    19 Aug 2026

    151 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. Microsoft is racing to patch "ShieldBreak" (CVE-2026-69414), a Defender zero-day letting local attackers reach SYSTEM privileges on fully patched Windows 10/11 25H2 and Server 2025. PoC is public; no fix yet. https://t.co/0AqEC1bzbE

    @ianbishop2021

    17 Aug 2026

    79 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations