logo

CVE-2026-69414 ShieldBreak Zero-Day: No Patch, and CISA BOD 26-04 Gives You 14 Days

ID: e28f40b6-e13a-5cae-a695-1f0c7ae3aaba

STIX ID: report--e28f40b6-e13a-5cae-a695-1f0c7ae3aaba

Feed Name: Qualys Blog

Threat Score
78/100

Date Published: 2026-08-25

Date Updated: 2026-08-25

Author: Vamika Sheel

...
...

ShieldBreak (CVE-2026-69414) is a zero-day elevation-of-privilege vulnerability in the Microsoft Malware Protection Engine for Microsoft Defender that can allow a low-privileged local attacker to escalate to NT AUTHORITY\SYSTEM; a public proof-of-concept was released on August 12, 2026 and Microsoft has not yet published a patch. The advisory explains the exploitation path (abusing Defender’s cloud-file hydration and CFAPI callbacks), impacted platforms (reported on Windows 11 25H2 and Windows Server 2025), and recommends detection via Qualys VMDR and temporary mitigation using Qualys TruRisk Eliminate until Microsoft issues a fix.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.