mc.merill.net Microsoft Defender for Endpoint Update Leaves Linux Servers Vulnerable
Article Content
- •Microsoft Defender for Endpoint on Linux disabled protection after reboot for certain builds.
- •The issue affects RHEL 8 and 9 systems, particularly those in FIPS mode.
- •Microsoft has paused the rollout and is working on a revised build expected by late July 2026.
A recent update to Microsoft Defender for Endpoint on Linux has caused significant issues, disabling the antivirus protection on affected devices after reboot. Specifically, builds 101.26042.0000 through 101.26042.0009 are impacted, leaving Linux servers exposed to threats. The problem primarily affects systems running Red Hat Enterprise Linux (RHEL) 8 and 9 in FIPS mode, where installation of the update may fail entirely. Microsoft has paused the rollout of the problematic update and is working on a revised build expected to be released by late July 2026. Users are advised to avoid upgrading to the affected build until further notice. The issues could lead to a lapse in active protection, raising concerns among system administrators. Microsoft has provided guidance for remediation, directing users to specific builds that address the vulnerabilities.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track Microsoft in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…
Critical Zero-Day Exploits in Citrix NetScaler Confirmed by CISA On September 26, 2026, CISA confirmed the active exploitation of two critical zero-day vulnerabilities in Citrix NetScaler, identified as CVE-2026-88771 and CVE-2026-88772, both with a CVSS score of 9.5. These vulnerabilities allow remote code execution and affect all default configurations of NetScaler ADC and…