Skip to content

security_identifier

CVE-2026-69414

Identifier for the reported unpatched Microsoft Defender local privilege escalation to SYSTEM, nicknamed ShieldBreak.

Known aliases

  • ShieldBreak

Relationships

No evidence-backed relationships are recorded.

Current stories

security5 publishers

Six 10.0s in the control plane, and nothing in your patch queue to show for it

Microsoft shipped 22 updates, six of them scored 10.0, mostly in Entra ID, Exchange Online and Azure. Fixed server-side is not the same as verified in your tenant.

Perspective Coverage

5 publishers
Builder
Builder 20%
Operator
Operator 65%
Investor
Investor 15%

Reality

Evidence62
Adoption
Insufficient
Hype gap+40
Incentives55
Confidence55
security5 publishers

FalconFlank PoC turns CrowdStrike's macro cleanup into a local privilege escalation

Chaotic Eclipse published working code that abuses Falcon's Office macro removal on fully patched Windows 11 25H2 and Server 2025. It is the fourth endpoint product the researcher has dropped exploit code for, and no CrowdStrike response is on record.

Perspective Coverage

5 publishers
Builder
Builder 36%
Operator
Operator 51%
Investor
Investor 13%

Reality

Evidence70
Adoption
Insufficient
Hype gap+10
Incentives55
Confidence68