Microsoft Defender Antivirus false 'turned off' alerts after latest updates
Security Tool/Service
Summary
Hide ▲
Show ▼
Microsoft Defender Antivirus is showing false 'turned off' alerts after the latest updates, creating confusion on supported Windows client and server systems even though protection remains active. The warnings appear in the Windows Security app and can prompt users to click to turn Defender back on. The issue has been present in the Release Preview Channel since June and now includes Windows 11 26H1 and Windows Server 2025. Microsoft says a fix will ship in a future Microsoft Defender Antivirus update.
Related Happenings
Microsoft Defender SYSTEM privilege escalation bypass (CVE-2026-69414)
Vulnerability
H score28
First: 09.09.2026 10:30
Last: 09.09.2026 10:30
Sources 1
About this happening:
Microsoft Defender vulnerability CVE-2026-69414 is back in focus after Chaotic Eclipse released ShieldCrash, a patch bypass for ShieldBreak. The PoC shows...
Microsoft Defender SYSTEM privilege escalation bypass (CVE-2026-69414)
VulnerabilityAbout this happening: Microsoft Defender vulnerability CVE-2026-69414 is back in focus after Chaotic Eclipse released ShieldCrash, a patch bypass for ShieldBreak. The PoC shows...
Microsoft Defender for Office 365 Safe Links blocks legitimate Google search links
Service Disruption
H score0
First: 02.09.2026 13:29
Last: 02.09.2026 13:29
Sources 1
About this happening:
Microsoft Defender for Office 365 Safe Links is blocking legitimate Google search links as malicious, preventing users from opening them normally and triggering warning pr...
Microsoft Defender for Office 365 Safe Links blocks legitimate Google search links
Service DisruptionAbout this happening: Microsoft Defender for Office 365 Safe Links is blocking legitimate Google search links as malicious, preventing users from opening them normally and triggering warning pr...
Latest development: 02.09.2026 13:30
Microsoft is investigating a Defender for Office 365 Safe Links issue in which legitimate Google search links are incorrectly classified as malicious, causing users to see "Opening this website might not be safe" warnings when opening the blocked URLs. Microsoft also says IT administrators may see related alerts and incidents in Microsoft Sentinel and the Defender portal while it works to correct the misclassification.
Microsoft Defender signature update fixes scan-crash bug on Windows 10 and Windows 11
Security Tool/Service
H score11
First: 19.08.2026 14:14
Last: 19.08.2026 14:14
Sources 1
About this happening:
Microsoft Defender now has a fix for a crash bug that broke scans on some Windows 10 and Windows 11 systems, restoring malware protection after a recent security updat...
Microsoft Defender signature update fixes scan-crash bug on Windows 10 and Windows 11
Security Tool/ServiceAbout this happening: Microsoft Defender now has a fix for a crash bug that broke scans on some Windows 10 and Windows 11 systems, restoring malware protection after a recent security updat...
Microsoft Defender BlueHammer (CVE-2026-33825) ransomware exploitation wave
Exploitation Wave
H score41
First: 30.06.2026 11:53
Last: 30.06.2026 11:53
Sources 1
About this happening:
CISA has flagged BlueHammer (CVE-2026-33825) as exploited in ransomware campaigns, expanding the risk to Windows devices exposed to privilege escalation. The flaw in *...
Microsoft Defender BlueHammer (CVE-2026-33825) ransomware exploitation wave
Exploitation WaveAbout this happening: CISA has flagged BlueHammer (CVE-2026-33825) as exploited in ransomware campaigns, expanding the risk to Windows devices exposed to privilege escalation. The flaw in *...
Microsoft releases RoguePlanet Defender security update for CVE-2026-50656
Security Patch Release
H score32
First: 17.06.2026 20:36
Last: 17.06.2026 20:36
Sources 1
About this happening:
Microsoft Defender security updates for CVE-2026-50656 remediated RoguePlanet, a privilege-escalation flaw in the Microsoft Malware Protection Engine (mpengine.d...
Microsoft releases RoguePlanet Defender security update for CVE-2026-50656
Security Patch ReleaseAbout this happening: Microsoft Defender security updates for CVE-2026-50656 remediated RoguePlanet, a privilege-escalation flaw in the Microsoft Malware Protection Engine (mpengine.d...
Latest development: 09.07.2026 11:48
Microsoft released security updates for CVE-2026-50656, remediating the RoguePlanet privilege-escalation flaw in Microsoft Malware Protection Engine (mpengine.dll) with version 1.1.26060.3008 and additional defense-in-depth updates. Microsoft said no customer action is required to install the update.
Timeline
-
31.08.2026 11:29 2 articles · 13d ago
Microsoft warns that Defender Antivirus status alerts are false
Initial DisclosureMicrosoft asked customers to ignore false Windows Security app alerts stating that Microsoft Defender Antivirus is turned off after the latest Defender updates; the antivirus is still functioning correctly, the notifications can appear when Windows starts and intermittently afterward, and the issue has affected Windows Insider Release Preview Channel users since June and supported Windows client and server versions including Windows 11 26H1 and Windows Server 2025, with Microsoft planning a future Microsoft Defender Antivirus update to fix it.
Show sources
- Microsoft asks users to ignore 'Antivirus is turned off' errors — www.bleepingcomputer.com — 31.08.2026 11:29
- Microsoft asks users to ignore 'Antivirus is turned off' errors — www.bleepingcomputer.com — 31.08.2026 11:29