CVE-2026-54123: Microsoft Defender For Endpoint

Medium severity, CVSS 5.5. EPSS: 0.5% chance of exploitation in the next 30 days.

Exposure of sensitive information to an unauthorized actor in Microsoft Defender for Endpoint allows an authorized attacker to disclose information locally.

Affected products

  • Microsoft Defender For Endpoint: from 101.0.0, before 101.26042.0020 (fixed in 101.26042.0020)

Published 2026-08-11. Last modified 2026-08-17.