Microsoft Defender for Endpoint Update Leaves Linux Systems Vulnerable

Microsoft Defender for Endpoint Update Leaves Linux Systems Vulnerable

First seen 27 Jul 2026, 14:34 UTC Theregistermc.merill.netlearn.microsoft.com 82% similarity 69.0

Article Content

Browse articles
ThreatCluster

Microsoft disclosed two significant issues with the Defender for Endpoint on Linux. One bug disables the security service after a reboot, affecting versions 101.26042.0000 through 101.26042.0009. Another issue prevents installation on FIPS-enabled Red Hat Enterprise Linux (RHEL) 8 and 9 systems. The disabled service bug could leave devices unprotected until remediation steps are taken. Microsoft has paused the rollout of build 101.26052.0009 and is working on a revised version expected by late July 2026. Affected users are advised to upgrade to build 101.26042.0011 or later for fixes. The issues highlight the risks associated with automatic updates in critical security software. Organizations relying on Microsoft Defender for Endpoint should monitor their systems closely.

Key Points: • Two critical bugs in Microsoft Defender for Endpoint on Linux affect security functionality. • The update may disable protection on reboot for many devices, risking unprotected status. • Installation issues on FIPS-enabled RHEL systems prevent successful updates, prompting a rollout pause.

ThreatCluster AI How this analysis works

Timeline

2026-07-27
Microsoft discloses Defender issues
Two bugs in Defender for Endpoint on Linux were revealed, affecting security on reboot and FIPS-enabled RHEL systems.
Theregister
2026-07-27
Rollout of build 101.26052.0009 paused
Microsoft paused the rollout of the problematic Defender build due to installation issues on RHEL 8 and 9.
mc.merill.net
2026-07-27
Remediation steps provided
Microsoft advised users to upgrade to build 101.26042.0011 or later to address the disabled service issue.
Theregister

Community

Browse all →