Back to advisories

CVE-2026-69414 ShieldBreak Zero-Day: No Patch, and CISA BOD 26-04 Gives You 14 Days

CVE-2026-69414 ShieldBreak is a zero-day privilege escalation in Microsoft Malware Protection Engine affecting Microsoft Defender. A public PoC exists and no patch is available. Any low-privilege attacker on Windows systems running Defender can escalate to SYSTEM.

CRITICALAdvisoryAug 26, 2026
Action required
Immediately implement mitigation guidance from Qualys or Microsoft. Hunt for exploitation attempts by monitoring Malware Protection Engine process anomalies, parent-child relationships involving MsMpEng.exe, and any SYSTEM-level privilege escalations from low-privilege accounts. Enable enhanced logging on Defender.
Affected products
Microsoft DefenderMicrosoft Malware Protection EngineMicrosoftQualys