DIRAS TAKE
Urgent: public exploit code is available, so prioritize updating to the fixed build 1.1.26080.3 or apply vendor guidance immediately.
What is CVE-2026-69414?
A local attacker with a low-privilege account can elevate privileges in Microsoft Malware Protection Engine (CVE-2026-69414). The flaw affects versions 1.1.0.0 through before 1.1.26080.3; 1.1.26080.3 contains the fix. Exploitation requires local access and does not require user interaction, allowing code or actions to run with higher privileges on affected hosts.
Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Which versions of Microsoft Microsoft Malware Protection Engine are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 1.x | 1.1.0.0 – before 1.1.26080.3 | 1.1.26080.3 |
Is CVE-2026-69414 being exploited?
Public exploit code is available.
How to fix CVE-2026-69414
- Install the fixed Microsoft Malware Protection Engine build 1.1.26080.3.
- If you cannot patch immediately, restrict local access to systems running the engine and limit accounts with local logon rights.
- Monitor endpoint logs and telemetry for suspicious privilege escalation behavior related to the engine.
- Follow Microsoft guidance for any additional configuration or mitigation steps.
Frequently asked questions
Is CVE-2026-69414 being actively exploited?
Public exploit code is available for CVE-2026-69414, increasing the risk of active exploitation.
Which Microsoft Malware Protection Engine versions are affected by CVE-2026-69414?
Versions 1.1.0.0 through before 1.1.26080.3 are affected; the fix is in 1.1.26080.3.
Is there a patch for CVE-2026-69414?
Yes. Microsoft released a fixed build: 1.1.26080.3.
Does CVE-2026-69414 require authentication?
Yes. Exploitation requires local access with a low-privilege account; no user interaction is required.
References
- nvd.nist.gov/vuln/detail/CVE-2026-69414
- cve.org/CVERecord?id=CVE-2026-69414
- msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69414
- All Microsoft CVEs on CVE Radar
- CVEs published in September 2026