Check Point Software has issued emergency hotfixes for CVE-2026-93616, a critical path traversal vulnerability in its Security Management Server that lets unauthenticated attackers upload and run arbitrary scripts. The company confirmed the flaw is being actively exploited, with a handful of customers already compromised, and released a fix in R82.20 Security Hotfix covering Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent.
bleepingcomputer.com
· 2026-09-22
Security researcher Abdelhamid Naceri published a new proof-of-concept exploit called BigDiskBuster that, when run in the background, prevents Microsoft Defender from installing platform or signature updates on any supported Windows version. Naceri describes it as similar to his earlier UnDefend exploit, and says the code is still buggy but demonstrates the concept clearly. This is the latest in a string of nearly a dozen Defender and Windows-related exploits he has released since April 2026 amid an ongoing dispute with Microsoft over his termination.
bleepingcomputer.com
· 2026-09-22
Security researcher Nightmare-Eclipse has published a new proof-of-concept exploit called ShieldCrash on GitHub, claiming it circumvents Microsoft's fix for CVE-2026-69414 (ShieldBreak), a privilege escalation bug in the Malware Protection Engine. The exploit reportedly allows arbitrary file reads as SYSTEM on all supported Windows versions, despite Microsoft's September patch. Microsoft has not yet responded to requests for comment on the claim.
darkreading.com
· 2026-09-10
A researcher using the alias Nightmare Eclipse publicly released details of a new zero-day exploit dubbed 'ShieldCrash' targeting Microsoft Defender, timed to appear right after Microsoft's September 2026 Patch Tuesday updates. The exploit reportedly allows attackers to gain SYSTEM-level access on affected Windows machines, the highest level of privilege on the system.
bleepingcomputer.com
· 2026-09-09