CVE-2026-69414 ShieldBreak Zero-Day: No Patch, and CISA BOD 26-04 Gives You 14 Days
A proof-of-concept exploit has become available for CVE-2026-69414, a zero-day elevation-of-privilege vulnerability in the Microsoft Malware Protection Engine within Microsoft Defender. This flaw enables local attackers with low privileges to execute code as NT AUTHORITY\SYSTEM on affected systems, including Windows 11 25H2 and Windows Server 2025.
Microsoft assigned the CVE identifier on August 14, 2026, but no security update is currently available. Organizations relying on CISA Binding Operational Directive (BOD) 26-04 must address this risk within 14 days, necessitating immediate mitigation strategies until the vendor releases a formal patch.
Executive Summary
ShieldBreak (CVE-2026-69414) is a zero-day elevation-of-privilege vulnerability in the Microsoft Malware Protection Engine used by Microsoft Defender, allowing a low-privilege local attacker to escalate to SYSTEM. A public PoC was released on August 12, 2026, and Microsoft assigned the CVE on August 14, and no patch is available yet. Qualys VMDR provides detection across Windows environments, and Qualys TruRisk Eliminate offers a mitigation that teams can apply now, with affected assets reassessable in VMDR to verify remediation.…