Author
Guardian Research Team

Critical macOS Screen Sharing Authentication Bypass — Under Active Exploitation (CVE-2026-65400)
CVE-2026-65400 is a pre-authentication vulnerability in the macOS Screen Sharing daemon (screensharingd) that lets a network attacker authenticate without valid credentials and gain root-level remote code execution. Apple patched the flaw on August 6, 2026, in macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9, but after reports of active exploitation, CISA rescored it from 7.1 to 9.8 (Critical) on August 14 and added it to the Known Exploited Vulnerabilities (KEV) catalog on August 18, giving federal agencies until August 21, 2026 to remediate.

ShieldBreak: The Windows Defender 0-Day with No Patch — And What to Do About It.
A public proof-of-concept called ShieldBreak fully bypasses Microsoft's patch for the Windows Defender privilege-escalation flaw known as RoguePlanet (CVE-2026-50656, CVSS 7.8), letting an attacker who already has local code execution reach a SYSTEM-level shell on Windows 11 25H2 and Windows Server 2025 with a reported 100% success rate. No Microsoft fix currently closes this bypass. Deploy the interim mitigation in the Guardian dashboard and hunt for the associated exploitation indicators until one ships.

Critical Netlogon RCE on domain controllers (CVE-2026-41089)
A critical, unauthenticated remote code execution vulnerability in Windows Netlogon (CVE-2026-41089, CVSS 9.8) lets a remote attacker run code as SYSTEM on a domain controller. Patch all domain controllers in the same maintenance window with the May 2026 security updates.

A Supply Chain Attack in Notepad++
The Notepad++ update process was compromised by a supply chain attack, and users are strongly advised to upgrade to version 8.8.9 or later to ensure their security.