CVE-2026-69414 ShieldBreak Zero-Day: No Patch, and CISA BOD 26-04 Gives You 14 Days

2026-08-25T08:51:44Zc429b1a51084f566da86acf9f7c8c37a3961a0a43b9165dccb78eb4551c5f72c
CVE-2026-68820CVE-2026-69414API discoveryCISA BOD 26-04CISA KEVCSPMMicrosoft DefenderMicrosoft Malware Protection EngineMicrosoft Patch TuesdayOracle Critical Patch UpdateWindowsactively exploitedelevation of privilegelocal privilege escalationpatch managementpublic PoCunpatchedvulnerability managementzero-day

What happened

Qualys security intelligence highlights CVE-2026-69414 (ShieldBreak), a publicly disclosed, unpatched zero-day elevation-of-privilege vulnerability in the Microsoft Malware Protection Engine used by Microsoft Defender. A low-privilege local attacker may escalate privileges to SYSTEM; a public proof of concept was reportedly released on August 12, 2026. The feed also covers CVE-2026-68820, an actively exploited Windows vulnerability listed in CISA KEV, with accelerated remediation expectations under CISA BOD 26-04, plus broad August 2026 Microsoft, Adobe, and Oracle security updates.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
qualys_blog
Record identifier
c429b1a51084f566da86acf9f7c8c37a3961a0a43b9165dccb78eb4551c5f72c
Enrichment time
2026-08-25T08:51:44Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.