type: cve ยท created: 2026-09-10 ยท updated: 2026-09-10 ยท tags: [cve, microsoft, defender, privilege-escalation, bypass] ยท confidence: high ยท severity: high ยท affected_sectors: [technology] ยท au_impact: true
CVE-2026-69414 is the Microsoft Defender privilege-escalation vulnerability patched as "ShieldBreak" and referenced as the target of a subsequent bypass. On 9 September 2026, an anonymous researcher (Nightmare Eclipse) released a follow-up zero-day exploit named "ShieldCrash" asserting that Microsoft "missed a spot" and that the exact ShieldBreak problem can still be re-triggered under specific conditions, granting arbitrary file read as SYSTEM on fully patched Windows 10, Windows 11 and Windows Server (without write access). The disclosure continued an ongoing public dispute between the researcher and Microsoft over bug-bounty and coordinated-disclosure practices; no confirmed in-the-wild exploitation of the bypass has been cited.
| Attribute | Detail |
|---|---|
| CVE | CVE-2026-69414 |
| Type | Local privilege escalation (Defender) |
| Patched | ShieldBreak patch (Sep 2026); bypass "ShieldCrash" disclosed 2026-09-09 |
| Severity | High |
| Source | BleepingComputer โ Tier 2/4 |