// Alert

Microsoft Azure threat report

Microsoft patched CVE-2026-50656, a high-severity local privilege escalation flaw in the Malware Protection Engine (mpengine.dll) used by Windows Defender. The vulnerability exploits a race condition to grant SYSTEM-level privileges. A proof-of-concept exploit was published in June 2026 by researcher Nightmare-Eclipse and was confirmed to work on fully patched Windows 10 and 11 systems, demonstrating the urgency of patching.

// Get alerts for Microsoft Azure