# Microsoft critical security vulnerability patches

> Live situation record from CLSTR: https://clstr.news/situations/microsoft-critical-security-vulnerability-patches
> Updated: 2026-08-14T11:38:10.000Z. Sources: 5. Developments: 2.

Microsoft has released patches for several critical security vulnerabilities affecting its software ecosystem.

In July 2026, the company addressed a high-severity Active Directory Certificate Services (AD CS) flaw known as ‘Certighost’ (CVE-2026-54121). This vulnerability allowed regular domain users to impersonate a Domain Controller by exploiting a fallback mechanism, potentially leading to full Windows domain compromise. 

By August 2026, Microsoft addressed additional critical flaws, including the ‘ShieldBreak’ zero-day and ‘LegacyHive’ (CVE-2026-62832). ShieldBreak targets Microsoft Defender, allowing local attackers to escalate privileges to the SYSTEM level via the cloud-hydration process. LegacyHive involves improper link resolution within the Windows User Profile Service, which could also grant local attackers administrator privileges.

## Claims

- The ShieldBreak exploit allows a non-admin user to gain SYSTEM-level privileges by modifying the classes registry hive. (corroborated by 2 sources)
- ShieldBreak affects Windows 11 25H2 and Windows Server 2025. (corroborated by 2 sources)
- The ShieldBreak vulnerability is a zero-day that can bypass previous patches for the RoguePlanet vulnerability. (single source)
- Microsoft has released security patches for the LegacyHive vulnerability, tracked as CVE-2026-62832. (single source)
- The ShieldBreak exploit was confirmed to work on the latest version of Windows 11. (single source)
- The LegacyHive vulnerability stems from improper link resolution in the Windows User Profile Service. (single source)

## Timeline

### 2026-08-14: Microsoft patches Windows zero-day vulnerabilities

Microsoft is patching multiple Windows vulnerabilities, including the ‘ShieldBreak’ zero-day in Defender, which allows local attackers to escalate privileges to SYSTEM level.

5 sources. https://clstr.news/cluster/windows-defender-zero-day-vulnerability-shieldbreak-disclosed

### 2026-07-27: Microsoft patches critical Certighost (CVE‑2026‑54121) AD CS flaw

Microsoft patched the Certighost (CVE‑2026‑54121) AD CS flaw that let ordinary users impersonate domain controllers and steal Kerberos tickets.

2 sources. https://clstr.news/cluster/microsoft-patches-critical-certighost-cve202654121-ad-cs-flaw

---
Cite as: Microsoft critical security vulnerability patches. CLSTR, https://clstr.news/situations/microsoft-critical-security-vulnerability-patches
