Microsoft Defender Antivirus false 'turned off' alerts after latest updates
Security Tool/Service
Summary
Hide ▲
Show ▼
Microsoft Defender Antivirus is showing false 'turned off' alerts after the latest updates, creating confusion on supported Windows client and server systems even though protection remains active. The warnings appear in the Windows Security app and can prompt users to click to turn Defender back on. The issue has been present in the Release Preview Channel since June and now includes Windows 11 26H1 and Windows Server 2025. Microsoft says a fix will ship in a future Microsoft Defender Antivirus update.
Related Happenings
Microsoft Defender signature update fixes scan-crash bug on Windows 10 and Windows 11
Security Tool/Service
H score11
First: 19.08.2026 14:14
Last: 19.08.2026 14:14
Sources 1
About this happening:
Microsoft Defender now has a fix for a crash bug that broke scans on some Windows 10 and Windows 11 systems, restoring malware protection after a recent security updat...
Microsoft Defender signature update fixes scan-crash bug on Windows 10 and Windows 11
Security Tool/ServiceAbout this happening: Microsoft Defender now has a fix for a crash bug that broke scans on some Windows 10 and Windows 11 systems, restoring malware protection after a recent security updat...
Microsoft Defender BlueHammer (CVE-2026-33825) ransomware exploitation wave
Exploitation Wave
H score41
First: 30.06.2026 11:53
Last: 30.06.2026 11:53
Sources 1
About this happening:
CISA has flagged BlueHammer (CVE-2026-33825) as exploited in ransomware campaigns, expanding the risk to Windows devices exposed to privilege escalation. The flaw in *...
Microsoft Defender BlueHammer (CVE-2026-33825) ransomware exploitation wave
Exploitation WaveAbout this happening: CISA has flagged BlueHammer (CVE-2026-33825) as exploited in ransomware campaigns, expanding the risk to Windows devices exposed to privilege escalation. The flaw in *...
Microsoft releases RoguePlanet Defender security update for CVE-2026-50656
Security Patch Release
H score32
First: 17.06.2026 20:36
Last: 17.06.2026 20:36
Sources 1
About this happening:
Microsoft Defender security updates for CVE-2026-50656 remediated RoguePlanet, a privilege-escalation flaw in the Microsoft Malware Protection Engine (mpengine.d...
Microsoft releases RoguePlanet Defender security update for CVE-2026-50656
Security Patch ReleaseAbout this happening: Microsoft Defender security updates for CVE-2026-50656 remediated RoguePlanet, a privilege-escalation flaw in the Microsoft Malware Protection Engine (mpengine.d...
Latest development: 09.07.2026 11:48
Microsoft released security updates for CVE-2026-50656, remediating the RoguePlanet privilege-escalation flaw in Microsoft Malware Protection Engine (mpengine.dll) with version 1.1.26060.3008 and additional defense-in-depth updates. Microsoft said no customer action is required to install the update.
Microsoft Malware Protection Engine race-condition elevation-of-privilege remote code execution flaw (CVE-2026-50656)
Vulnerability
H score32
First: 17.06.2026 11:32
Last: 17.06.2026 11:32
Sources 1
About this happening:
Microsoft has released a security update for CVE-2026-50656 after public disclosure of RoguePlanet, a privilege-escalation flaw in the Microsoft Malware Protecti...
Microsoft Malware Protection Engine race-condition elevation-of-privilege remote code execution flaw (CVE-2026-50656)
VulnerabilityAbout this happening: Microsoft has released a security update for CVE-2026-50656 after public disclosure of RoguePlanet, a privilege-escalation flaw in the Microsoft Malware Protecti...
Microsoft Defender RoguePlanet race-condition zero-day remote code execution flaw
Vulnerability
H score39
First: 10.06.2026 02:11
Last: 10.06.2026 02:11
Sources 1
About this happening:
Microsoft Defender zero-day RoguePlanet is a race-condition flaw affecting fully patched Windows 10 and Windows 11 systems. A public proof-of-concept exploit was released shortly...
Microsoft Defender RoguePlanet race-condition zero-day remote code execution flaw
VulnerabilityAbout this happening: Microsoft Defender zero-day RoguePlanet is a race-condition flaw affecting fully patched Windows 10 and Windows 11 systems. A public proof-of-concept exploit was released shortly...
Latest development: 10.06.2026 08:22
The anonymous security researcher Chaotic Eclipse, also known as Nightmare-Eclipse, released a proof-of-concept (PoC) exploit for the Microsoft Defender zero-day RoguePlanet under a new GitHub account named MSNightmare. The race-condition exploit can yield a SYSTEM-level shell and arbitrary code execution when it succeeds, has been tested on Windows 11 and Windows 10 with the June 2026 Patch Tuesday updates installed, and currently does not work on Windows Server without redesign because standard users cannot mount an ISO image.
Timeline
-
31.08.2026 11:29 2 articles · 1h ago
Microsoft warns that Defender Antivirus status alerts are false
Initial DisclosureMicrosoft asked customers to ignore false Windows Security app alerts stating that Microsoft Defender Antivirus is turned off after the latest Defender updates; the antivirus is still functioning correctly, the notifications can appear when Windows starts and intermittently afterward, and the issue has affected Windows Insider Release Preview Channel users since June and supported Windows client and server versions including Windows 11 26H1 and Windows Server 2025, with Microsoft planning a future Microsoft Defender Antivirus update to fix it.
Show sources
- Microsoft asks users to ignore 'Antivirus is turned off' errors — www.bleepingcomputer.com — 31.08.2026 11:29
- Microsoft asks users to ignore 'Antivirus is turned off' errors — www.bleepingcomputer.com — 31.08.2026 11:29