TechNewsReel
Live

Microsoft Defender Linux Bugs Leave Systems Unprotected After Update

Two separate defects disabled security service or blocked patches on hardened servers.

TechNewsReel Newsroom · July 27, 2026

Microsoft disclosed two bugs in Defender for Endpoint on Linux that left systems without active protection or unable to receive security updates.

Service Disabled After Reboot

The first issue disabled the Defender service after a system reboot across all supported Linux operating systems. The bug affected versions 101.26042.0000 through 101.26042.0009.

Microsoft remediated the service-disabling bug in build 101.26042.0011. The company paused the rollout and advised users to delay upgrading until the revised build was released.

FIPS Systems Blocked From Updating

A second bug prevented updates from installing on Red Hat Enterprise Linux 8 and 9 systems running in FIPS mode. This issue affected build 101.26052.0009.

The FIPS installation failure is fixed in version 101.26052.0011 and later.

FIPS (Federal Information Processing Standards) mode is a security requirement for US government and regulated systems, imposing strict rules on the cryptography used by the operating system. The inability to update security software on hardened systems undermines the security posture those configurations are intended to maintain.

Two Distinct Issues

The service-disabling bug and FIPS update failure are separate issues affecting different build cycles. The first impacted the 101.26042.x series; the FIPS problem occurred in 101.26052.0009.

Defender for Endpoint on Linux provides unified visibility and threat response for server workloads on-premises and in the cloud. A security product failing to remain active after reboot creates a critical vulnerability window where systems are left undefended.

Administrators should verify their deployed versions and upgrade to the patched builds to restore full protection.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.