Executive Summary ShieldBreak (CVE-2026-69414) is a zero-day elevation-of-privilege vulnerability in the Microsoft Malware Protection Engine used by Microsoft Defender, allowing a low-privilege local attacker to escalate to SYSTEM. A public PoC was released on August 12, 2026, and Microsoft assigned the CVE on August 14, and no patch is available yet. Qualys VMDR provides detection […]

A zero-day elevation-of-privilege vulnerability, tracked as CVE-2026-69414 and dubbed "ShieldBreak," has been discovered in the Microsoft Malware Protection Engine, which is integral to Microsoft Defender. This flaw allows a local attacker with low privileges to escalate to SYSTEM-level access on affected Windows systems.
A public proof-of-concept (PoC) demonstrating the vulnerability was released on August 12, 2026. Microsoft acknowledged the issue and assigned the CVE identifier on August 14, 2026, but a security update or patch is not yet available.
ShieldBreak exploits how Microsoft Defender processes files during cloud-file hydration. The attack vector involves a user-mode callback that interferes with file data received by Defender through the Cloud Filter API (CFAPI). By manipulating Windows filesystem and Object Manager mechanisms, an attacker can influence which files Defender ultimately scans. This manipulation allows attacker-controlled content to be processed by Defender's elevated privileges, leading to code execution as NT AUTHORITY\SYSTEM.
The publicly available PoC has been confirmed to work on Windows 11 25H2 and Windows Server 2025. This vulnerability follows closely on the heels of another Microsoft Defender privilege-escalation flaw, CVE-2026-50656, known as RoguePlanet, for which Microsoft recently released a fix.
Given the absence of an official patch from Microsoft, organizations are currently exposed to this critical vulnerability. Cybersecurity experts emphasize the urgency of implementing temporary mitigations to reduce risk while awaiting a permanent fix. These mitigations typically involve restricting user privileges and monitoring for suspicious activity that might indicate an attempted exploitation.
The Cybersecurity and Infrastructure Security Agency (CISA) has issued Binding Operational Directive (BOD) 26-04, which mandates federal civilian executive branch agencies to address known exploited vulnerabilities within a specific timeframe. While the directive's exact requirements for this specific zero-day are not detailed, such critical vulnerabilities typically fall under its purview, often requiring remediation within 14 days of identification.
Security researchers have provided detection methods for ShieldBreak, including specific queries for vulnerability management platforms to identify affected assets within an environment. These tools can help organizations gain visibility into their exposure and verify the effectiveness of any applied mitigations.
Until Microsoft releases an official security update, organizations are advised to implement available workarounds and monitor their systems closely. The potential for a low-privileged local attacker to gain SYSTEM-level access underscores the severity of ShieldBreak and the immediate need for protective measures.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.