0-DAY

ShieldCrash: Defender zero-day bypasses ShieldBreak on patched Windows.

Nightmare Eclipse published ShieldCrash after September Patch Tuesday — a bypass of Microsoft’s ShieldBreak (CVE-2026-69414) fix. PoC shows arbitrary file read as SYSTEM on fully patched Windows; researcher says the class can reach full SYSTEM.

Sep 10, 2026 · 3 min read

Security researcher Nightmare Eclipse (also tracked as Chaotic Eclipse / MSNightmare) released ShieldCrash, a new Microsoft Defender privilege-escalation proof-of-concept, shortly after Microsoft’s record September 2026 Patch Tuesday. SecurityWeek dated the writeup September 10, 2026 (3:09 AM ET); The Register covered the drop September 9. The researcher states the PoC works on Windows systems that already applied the September patches.

ShieldCrash is framed as a bypass of ShieldBreak (CVE-2026-69414) — itself a bypass of Microsoft’s July 19 patch for RoguePlanet (CVE-2026-50656). Microsoft acknowledged ShieldBreak August 14 and shipped fixes September 3. Per the researcher’s README (quoted by The Register), the current skeleton PoC demonstrates arbitrary file read as SYSTEM, not arbitrary write or a full SYSTEM shell; Nightmare Eclipse says the underlying defect can still be driven to full SYSTEM (e.g. dumping SAM) and that Microsoft “missed a spot” in the ShieldBreak fix.

As of SecurityWeek and The Register’s reporting, Microsoft had not issued a public statement or a named CVE for ShieldCrash. SOCRadar’s Ensar Seker (quoted by SecurityWeek) flags successive bypasses of RoguePlanet and ShieldBreak as a signal that the Defender security boundary may need a broader redesign — and advises monitoring Defender intelligence updates, enabling tamper protection, and restricting local admin / execution paths. ShieldCrash is described as Nightmare Eclipse’s eleventh Microsoft zero-day in this campaign cadence; in-wild victim counts: Undisclosed, and neither outlet reported confirmed mass exploitation.

Underwrite sheet — sourced only: ShieldCrash bypasses ShieldBreak CVE-2026-69414 on Sept-patched Windows; PoC = arbitrary SYSTEM file read; RoguePlanet CVE-2026-50656 is the prior link in the chain; no Microsoft CVE/statement yet in these reports. Primary press: SecurityWeek + The Register. Watch Microsoft Defender engine updates; patch ETA: Undisclosed.

Sources