A newly published ShieldCrash proof of concept from researcher MSNightmare claims that Microsoft Defender remains vulnerable to an arbitrary file-read flaw, despite Microsoft’s earlier fix for ShieldBreak, tracked as CVE-2026-69414.
The researcher says the issue could let a local attacker make Defender read files with SYSTEM-level privileges on fully updated, supported Windows systems.
According to the MSNightmare, Microsoft addressed several parts of the original ShieldBreak issue but left a specific attack path available. Under certain conditions, that remaining path allegedly recreates the core security impact of the prior vulnerability.
The reported impact is significant because the SYSTEM account has broader permissions than normal users and most administrator accounts. Windows services, security software components, and protected operating system processes often run under SYSTEM.
If an attacker can force a Defender component to access a protected file and expose its contents, they may obtain sensitive data that their existing account should not access.
Windows Defender ShieldCrash 0-Day Flaw
Potentially exposed data could include application configuration files, credential-related material, security product settings, private keys, browser or service secrets, or files belonging to other Windows users.
The exact impact depends on which files the attacker can target, whether they can reliably recover their contents, and what permissions the attacker already has before launching the attack.
The available proof of concept is described as a structure implementation rather than a complete SYSTEM privilege-escalation exploit.
The researcher says it demonstrates arbitrary file reading as SYSTEM after the September 2026 Windows security updates, while noting that a more complete proof of concept could be released later. Reading a file does not mean you can run code or system commands, but it can still weaken Windows security.
PoC (Source: MSNightmare)
The ShieldCrash repository includes C++ project files, a DLL named Warden.dll, resource files, and an EICAR test archive. The EICAR file suggests the research may involve Defender’s malware-detection or file-handling workflow.
However, organizations should avoid running untrusted public proof-of-concept code on production endpoints, especially code that interacts with antivirus services or privileged Windows components.
The GitHub ShieldCrash PoC claims Microsoft’s fix for ShieldBreak (CVE-2026-69414) failed to fully address the underlying issue, allowing arbitrary file reads as SYSTEM on patched Windows systems.
Microsoft has not publicly confirmed the newer bypass, which remains a researcher-reported claim pending independent reproduction or a Microsoft security advisory. The earlier issue is tracked as CVE-2026-69414, while the new bypass has not yet received a separate CVE assignment.
Defenders should monitor endpoints for suspicious local tools that interact with Microsoft Defender scanning paths, unexpected creation or loading of unsigned DLLs, abnormal access attempts involving protected files, and child processes or file operations associated with Defender services.
Security teams should also keep the Microsoft Defender platform and intelligence updates current, apply future Microsoft patches promptly, and restrict untrusted code execution through application control policies.
Microsoft's Patch Tuesday September 2026 rollout has broken previous records, with the company addressing 974 CVEs across its product lineup in a single release. Two of these vulnerabilities were already being exploited in the wild before fixes became available, prompting quick action from federal cybersecurity authorities.The sheer volume of this month's Patch Tuesday September 2026 release dwarfs recent months. Windows accounted for 723 of the fixed flaws, while the Office suite received patches for 222 issues, 111 of which affected Office 2016 specifically.
Scale of Patch Tuesday September 2026
SQL Server products saw 62 CVEs resolved, Developer Tools had 22, SharePoint Server received 16 fixes, Azure had 12, Skype for Business had 10, and Exchange Server accounted for 9. More than 110 of the vulnerabilities patched carry a critical severity rating, and nearly 90% of the total fall into three categories: privilege escalation, remote code execution, and information disclosure. Factoring in fixes for 25 non-Microsoft CVEs, the combined total for this Patch Tuesday September 2026 cycle reaches 999 resolved vulnerabilities.This release continues a pattern of escalating patch volumes from Microsoft in recent months — 457 CVEs were addressed in August, 663 in July, 220 in June, and 161 in May, making September's numbers a significant jump even against that backdrop.
The Two Exploited Zero-Days
Central to this month's Patch Tuesday September 2026 update are two CVEs that Microsoft confirmed had been exploited before patches were issued.The first, CVE-2026-85880 (CVSS 7.8), is a heap-based buffer overflow in the Windows Advanced Local Procedure Call (ALPC) component. It allows an attacker with local access to escalate privileges and obtain SYSTEM-level control. Microsoft's advisory states that an attacker who can execute code in a low-privilege AppContainer could exploit this vulnerability locally to escape the sandbox and elevate privileges on the affected system, with no additional user interaction required.The second actively exploited flaw, CVE-2026-81963 (CVSS 7.8), stems from improper link resolution within the Windows Update Stack. Like the ALPC bug, it enables a local, authorized attacker to escalate privileges and gain SYSTEM access.Both CVEs have since been added to the Known Exploited Vulnerabilities (KEV) catalog maintained by the U.S. Cybersecurity and Infrastructure Security Agency (CISA). Federal Civilian Executive Branch agencies now face a September 22, 2026 deadline to apply the relevant patches.
Other Notable CVEs Worth Tracking
Beyond the zero-days, several other CVEs patched in this Patch Tuesday September 2026 batch carry high severity scores and warrant prompt attention from Microsoft administrators:
CVE-2026-55007 (CVSS 8.1) — a double-free flaw in Microsoft Exchange Server enabling remote code execution
CVE-2026-80097 (CVSS 8.6) — improper authentication in Microsoft Authenticator allowing local privilege escalation
CVE-2026-69465 (CVSS 8.8) — missing authorization in Microsoft Office SharePoint permitting remote code execution
CVE-2026-65669 (CVSS 9.6) — an injection flaw in SQL Server enabling remote privilege escalation
CVE-2026-69525 (CVSS 9.8) — use-after-free in Windows Remote Desktop Services allowing remote code execution
CVE-2026-69595 (CVSS 9.8) — use-after-free in the Windows Services for NFS ONCRPC XDR Driver
CVE-2026-69730 (CVSS 9.8) — use-after-free in the Windows DNS server
CVE-2026-69829 (CVSS 9.8) — heap-based buffer overflow in Windows Shell
CVE-2026-72979 (CVSS 9.8) — use-after-free in the Windows DHCP Server
Alongside the CVE fixes, Microsoft's Patch Tuesday September 2026 release also included new Servicing Stack Updates (SSUs), classified as critical, covering Windows Server 2012, Windows Server 2012 R2, and Windows 10 Version 1607/Server 2016.Given the number of critical-severity CVEs and the confirmed exploitation of two privilege-escalation bugs, security teams are expected to prioritize this Patch Tuesday September 2026 rollout above routine monthly cycles, particularly for internet-facing Windows and Exchange deployments.
Microsoft disclosed CVE-2026-69449, an Important-severity vulnerability in Windows BitLocker. This issue is classified as a heap-based buffer overflow (CWE-122) and may allow remote code execution (RCE). Microsoft released details about this vulnerability on September 8, 2026. The CVSS 3.1 base score is 6.7, with a temporal score of 5.8. Windows BitLocker Flaw The vulnerability uses […]
An anonymous security researcher known as Nightmare Eclipse has released a new Microsoft Defender zero-day exploit named "ShieldCrash" right after Microsoft rolled out its September 2026 Patch Tuesday security updates. [...]
Microsoft is adding new age-awareness APIs to Windows 11 that will allow apps to determine whether someone is a child, teenager, or adult without exposing their exact date of birth. [...]
Microsoft has released the Windows 10 KB5122878 extended security update, which includes this month's record-breaking September 2026 Patch Tuesday fixes, along with a few bug fixes. [...]
Today is Microsoft's September 2026 Patch Tuesday, with security updates released for a record-breaking 966 flaws, including two actively exploited zero-day vulnerabilities. [...]
Microsoft has released Windows 11 KB5124008 and KB5122880 cumulative updates for versions 25H2/24H2 and 23H2 to fix security vulnerabilities, bugs, and add new features. [...]
Microsoft says the August 2026 security update may trigger 0xc0000409 errors on Windows Server 2016 systems where the Compatibility Appraiser diagnostic service is enabled. [...]
Microsoft warned customers last week that they may experience application crashes on some Windows Server 2025 due to recent memory management changes. [...]
Microsoft is working to resolve a known issue that causes delays or blocks some users from opening the Microsoft Teams desktop client on Windows systems. [...]
Microsoft is developing a new security feature for Teams messaging that will obscure QR codes sent by external users. This measure aims to help organizations reduce phishing and fraud risks associated with malicious QR code campaigns. Listed under Microsoft 365 Roadmap ID 570439, this feature is currently in development and is scheduled for rollout in […]
A Microsoft 365 email security-control bypass that lets attackers submit unauthenticated messages posing as internal users by leaving one SMTP field blank. The technique targets Exchange Online’s RejectDirectSend setting and does not represent a vulnerability in Microsoft software or in ReliaQuest systems; instead, it exposes a limitation in how the control evaluates Direct Send traffic. […]
Microsoft says a known issue that reverts mouse settings after installing the KB5120998 August 2026 preview update affects only non-English Windows 11 systems. [...]
Microsoft will start automatically enabling Memory Integrity protection on eligible Windows devices through quality updates beginning in October 2026. This change aims to strengthen defenses against kernel-level attacks by ensuring that only trusted kernel-mode code and drivers can run on supported systems. Memory Integrity is a security feature built on Virtualization-based Security (VBS), a Windows […]