CVE-2026-69414ImportantDisclosedRevised 3 Sep
Microsoft Defender Elevation of Privilege Vulnerability
Assessment
Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "ShieldBreak ".
- Severity
- Important
- CVSS base score
- 7.8CVSS:3.1/
AV:L/ AC:L/ PR:L/ UI:N/ S:U/ C:H/ I:H/ A:H/ E:P/ RL:O/ RC:C - Impact
- Elevation of Privilege
- EPSS, next 30 days
- 0.3%Higher than 23.2% of scored CVEs · FIRST model run 26 Sep 2026 · about EPSS
- Exploitability
- Exploitation More Likely
- Publicly disclosed
- Yes
- Customer action
- Required: apply the update
- Component
- Microsoft Defender
- Weakness
- CWE-284: Improper Access Control
- Issued by
- Microsoft
- Published
- 14 Aug 2026 · August 2026
- Last revised
- 3 Sep 2026Microsoft has released an update to the Microsoft Malware Protection Engine that addresses the vulnerability identified by CVE-2026-69414. Please see the FAQ for more information on how to check if the new version has been installed.
Updates that fix it
0 KBsNo KB listed
MSRC lists no downloadable update, which usually means a service-side fix or a release-notes update. Check the MSRC advisory.
Affected products
System Center1 affected product
- Microsoft Malware Protection Engine