// Alert

Microsoft 365 threat report

CVE-2026-69414 ShieldBreak is a zero-day elevation-of-privilege vulnerability in the Microsoft Malware Protection Engine used by Microsoft Defender. A public proof-of-concept was released on August 12, 2026, allowing low-privileged local attackers to escalate to SYSTEM-level privileges. Microsoft assigned the CVE on August 14 but has not released a patch. CISA issued BOD 26-04 with a 14-day remediation deadline. The vulnerability exploits how Defender processes files during cloud-file hydration using the Cloud Filter API.

// Get alerts for Microsoft 365