// Microsoft 365CRITICAL
Security researcher Nightmare Eclipse disclosed CVE-2026-69414, dubbed "ShieldBreak," a critical zero-day vulnerability in Microsoft Defender that allows attackers to bypass or disable the widely-deployed endpoint protection platform. Microsoft confirmed active exploitation and is working on a patch. The flaw potentially enables attackers to neutralize endpoint detection before deploying payloads, compromising organizations across all industries that rely on Defender as their primary security control.
- 44 Zero-Days in One Week: The Exploitation Surge Overwhelming En(opens in a new tab)
- CVE-2026-69414 ShieldBreak Zero-Day: No Patch, and CISA BOD 26-0(opens in a new tab)
// Get alerts for Microsoft 365