CVE-2026-69414 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender, publicly referred to as "ShieldBreak." We are working to provide a high-quality security update that addresses this vulnerability. We will provide information in this CVE when the update is available. EPSS estimates a 0.23% chance of exploitation in the next 30 days.

## Description

Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender, publicly referred to as "ShieldBreak." We are working to provide a high-quality security update that addresses this vulnerability. We will provide information in this CVE when the update is available.

## Metrics

- CVSS: 3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- CVSS Score: 7.8/10
- EPSS Probability: 0.23% (13.7th percentile) 
  Probability of exploitation in the next 30 days. [Learn more](https://www.first.org/epss/)

## Weakness Enumeration

- [CWE-284](https://cwe.mitre.org/data/definitions/284.html)
- [CWE-269](https://cwe.mitre.org/data/definitions/269.html)

## Affected Software

| Vendor   | Product                       | Versions         |
|----------|-------------------------------|------------------|
| Microsoft| Malware Protection Engine      | All versions     |

## References

- [Vendor Advisory](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69414)
- [GitHub Repository](https://github.com/MSNightmare/ShieldBreak)

## Timeline

- Published: Aug 14, 2026
- Last Modified: Aug 20, 2026
- Status: Modified

## Frequently Asked Questions

**What is CVE-2026-69414?**  
Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender, publicly referred to as "ShieldBreak." We are working to provide a high-quality security update that addresses this vulnerability. We will provide information in this CVE when the update is available.

**How severe is CVE-2026-69414?**  
CVE-2026-69414 has a CVSS score of 7.8/10 (HIGH severity). The EPSS model estimates a 0.23% probability of exploitation in the next 30 days.

**How do I fix CVE-2026-69414?**  
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also [run a Strix scan](https://app.strix.ai/) to test if your systems are affected.
