Microsoft Fixes Windows Defender Bug That Crashed Virus Scans
A stability issue triggering access violation errors during malware checks has been resolved via new Security Intelligence updates.
Microsoft has resolved a critical bug that caused Windows Defender to crash during virus scans, leaving millions of systems unable to complete essential malware checks. The stability issue emerged following a series of updates in August 2026, affecting Quick, Full, and Offline scanning modes.
The crashes were characterized by exception code 0xC0000005, a known access violation error occurring within the MsMpEng.exe process inside the mpengine.dll. According to reports from BleepingComputer and Cyber Security News, the failure specifically impacted Microsoft Malware Protection Engine versions 1.1.26070.7 and 1.1.26080.2. Users attempting to run scans encountered immediate process failures, effectively disabling the primary defense mechanism for their operating systems.
The ShieldBreak Connection
The timing of these crashes coincided with Microsoft's August 2026 Patch Tuesday and the public release of "ShieldBreak," a local privilege-escalation proof of concept targeting Windows Defender. While Microsoft did not officially confirm a direct link, the stability issues appeared immediately after the publication of the exploit. This led to widespread community speculation that the crashes were collateral damage resulting from rapid, hurried changes to the engine's signatures or logic intended to block the ShieldBreak vulnerability.
Industry Implications
Because Windows Defender serves as the default security layer for a vast majority of Windows users and enterprise endpoints, any failure in the scanning engine creates a significant security gap. When the engine crashes, systems are left vulnerable to undetected malware, and the reliability of automated security updates is called into question. The risk was further compounded for some users when fallback tools, such as the Microsoft Safety Scanner, were also reported to be affected by the same underlying instability.
Path to Recovery
Microsoft has since deployed fixes to stabilize the protection engine. Recovery has been observed for users who update to Security Intelligence Update 1.457.236.0 or later versions. Administrators and home users are encouraged to verify their current engine version and ensure that all pending Security Intelligence updates are applied to restore full scanning functionality. While the immediate crash loop has been halted, security researchers continue to monitor the engine for any lingering side effects from the rapid patching cycle.