Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [QUIET] · [TECHNOLOGY]
2 clusters · 5 sources · 18 days · First seen · Last updated
Microsoft critical security vulnerability patches
Overview
Microsoft has released patches for several critical security vulnerabilities affecting its software ecosystem.
In July 2026, the company addressed a high-severity Active Directory Certificate Services (AD CS) flaw known as ‘Certighost’ (CVE-2026-54121). This vulnerability allowed regular domain users to impersonate a Domain Controller by exploiting a fallback mechanism, potentially leading to full Windows domain compromise.
By August 2026, Microsoft addressed additional critical flaws, including the ‘ShieldBreak’ zero-day and ‘LegacyHive’ (CVE-2026-62832). ShieldBreak targets Microsoft Defender, allowing local attackers to escalate privileges to the SYSTEM level via the cloud-hydration process. LegacyHive involves improper link resolution within the Windows User Profile Service, which could also grant local attackers administrator privileges.
Entities
Microsoft · Nightmare Eclipse · Windows Server 2025 · Aniq Fakhrul · Windows 11
Claims
What the coverage asserts, and how many sources carry each claim.
- [● 2 SOURCES] The ShieldBreak exploit allows a non-admin user to gain SYSTEM-level privileges by modifying the classes registry hive.
- [● 2 SOURCES] ShieldBreak affects Windows 11 25H2 and Windows Server 2025.
- [○ 1 SOURCE] The ShieldBreak vulnerability is a zero-day that can bypass previous patches for the RoguePlanet vulnerability.
- [○ 1 SOURCE] Microsoft has released security patches for the LegacyHive vulnerability, tracked as CVE-2026-62832.
- [○ 1 SOURCE] The ShieldBreak exploit was confirmed to work on the latest version of Windows 11.
- [○ 1 SOURCE] The LegacyHive vulnerability stems from improper link resolution in the Windows User Profile Service.
Timeline
-
29 days ago
[TECHNOLOGY] 5 sourcesMicrosoft patches Windows zero-day vulnerabilitiesMicrosoft is patching multiple Windows vulnerabilities, including the ‘ShieldBreak’ zero-day in Defender, which allows local attackers to escalate privileges to SYSTEM level.
-
about 2 months ago
[TECHNOLOGY] 2 sourcesMicrosoft patches critical Certighost (CVE‑2026‑54121) AD CS flawMicrosoft patched the Certighost (CVE‑2026‑54121) AD CS flaw that let ordinary users impersonate domain controllers and steal Kerberos tickets.
Sources
borncity.com · cybernoz.com · gr.pcmag.com · memesita.com · technews.bg