Ethical Hacking News
Microsoft has disclosed two major issues with its Defender for Endpoint security solution on Linux platforms, leaving some boxes vulnerable to attacks. The issues include a bug that disables security services after reboot and another that blocks installation of updates on hardened systems.
The Microsoft Defender for Endpoint security solution on Linux platforms has two major issues: a bug that disables security after reboot and another that blocks update installation on hardened systems.The bug affects versions 101.26042.0000 through 101.26042.0009 across all supported Linux operating systems.On RHEL 8 and 9 systems running in FIPS mode, the 101.26042.x update fails to install.The issues have left some Linux boxes vulnerable to attacks and raised concerns among IT administrators.Microsoft is providing remediation steps for users affected by these issues.
Microsoft, a leading technology giant, has recently disclosed two major issues with its Defender for Endpoint security solution on Linux platforms. The first issue involves a bug that disables the security service after a reboot, while the second issue blocks the installation of updates on hardened RHEL systems. These problems have left some Linux boxes vulnerable to attacks and have raised concerns among IT administrators.
The bug in question affects versions 101.26042.0000 through 101.26042.0009 across all supported Linux operating systems. According to Microsoft, after an upgrade or reinstall followed by a reboot, "the Defender service might be disabled on some devices." This can lead to compromised security and exposed devices until remediation steps are taken.
Furthermore, a separate problem affects RHEL 8 and 9 systems running in FIPS mode: the 101.26042.x update fails to install, leaving devices on their previous version. FIPS refers to US Federal Information Processing Standards, which impose requirements on cryptography used by government and other regulated systems. Microsoft's alert did not mention an available update, but its release notes direct users affected by the disabled-service bug to build 101.26042.0011.
This latest development in the patching cycle of Microsoft Defender for Endpoint has raised questions about the stability and reliability of the software. It also highlights the importance of ensuring that security solutions are compatible with different Linux distributions and configurations.
In recent years, Microsoft has faced criticism for shipping broken updates for its flagship operating system, Windows. An update that breaks software designed to protect a device takes things to another level, particularly given the relentless rise in attacks and the need to fend them off and monitor activity. However, an update that disables security services or blocks installation on hardened systems is less than ideal.
The appeal of unified visibility through Microsoft Defender for Endpoint on Linux lies in its ability to provide a single management platform for endpoint security. This can be particularly valuable for organizations that have invested heavily in Microsoft's ecosystem and want to leverage the company's expertise and resources. Nevertheless, issues like these underscore the need for careful testing and validation before releasing software updates.
As the threat landscape continues to evolve, it is essential for IT administrators and developers to stay vigilant and address potential vulnerabilities early on. This includes not only ensuring that security solutions are compatible with different platforms but also providing clear guidance and support for users affected by issues like these.
In conclusion, Microsoft's recent announcement about Defender for Endpoint on Linux highlights the delicate balance between security and compliance in the world of IT. While the company's solution offers significant benefits, it is crucial to address potential vulnerabilities and provide users with timely updates and support.
Related Information:
https://www.ethicalhackingnews.com/articles/MICROSOFT-DEFENDER-FOR-Endpoint-LEAVES-SOME-Linux-BOXES-DEFENSELESS-AFTER-UPDATE-A-DELICATE-BALANCE-BETWEEN-SECURITY-AND-COMPLIANCE-ehn.shtml
https://www.theregister.com/patches/2026/07/27/microsoft-defender-for-endpoint-leaves-some-linux-boxes-defenseless-after-update/5278914
Published: Mon Jul 27 09:23:01 2026 by llama3.2 3B Q4_K_M