CVE-2026-54123: Microsoft Defender for Endpoint for Mac Information Disclosure Vulnerability
Exposure of sensitive information to an unauthorized actor in Microsoft Defender for Endpoint allows an authorized attacker to disclose information locally.
CSIRTS triage
- What
- Information disclosure vulnerability in Microsoft Defender for Endpoint allows authorized attackers to access sensitive information locally.
- Who is affected
- macOS endpoints running Microsoft Defender for Endpoint where attackers have local access are affected.
- Urgency
- Medium severity (CVSS 5.5) requiring local access and authorization; patch during regular maintenance windows.
- Action
- Update Microsoft Defender for Endpoint on macOS to the latest version.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Defender for Endpoint for Mac
Get an email when a new Defender for Endpoint for Mac advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54123
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-541230.45% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 37% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-54123 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- medium[NEW] [medium] Microsoft Defender for Endpoint: Vulnerability enables Information Disclosurecert-bund
- unknownMultiple vulnerabilities in Microsoft products (August 12, 2026)cert-fr-avis
- mediumCVE-2026-54123: Exposure of sensitive information to an unauthorized actor in Microsoft Defender for Endpoint …nvd
Recent advisories for Microsoft Defender for
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- highCVE-2026-69414: Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in …nvd · 2026-08-14
- medium[NEW] [medium] Microsoft Defender for Endpoint: Vulnerability enables Information Disclosurecert-bund · 2026-08-12
- mediumCVE-2026-54123: Exposure of sensitive information to an unauthorized actor in Microsoft Defender for Endpoint …nvd · 2026-08-11
- highCVE-2026-69414: Microsoft Defender Elevation of Privilege Vulnerabilitymsrc · 2026-08-11
- medium[NEW] [medium] Microsoft Malware Protection Engine and Defender: Multiple vulnerabilitiescert-bund · 2026-07-15
- unknownNCSC-2026-0236 [1.00] [M/H] Vulnerabilities fixed in Microsoft Defenderncsc-nl · 2026-07-14
More from Microsoft Security Response Center
- highCVE-2026-70130: Microsoft Office Remote Code Execution Vulnerability2026-08-11
- highCVE-2026-70354: .NET Core Remote Code Execution Vulnerability2026-08-11
- highCVE-2026-68792: Microsoft Office Elevation of Privilege Vulnerability2026-08-11
- highCVE-2026-66807: Microsoft Office Graphics Component Remote Code Execution Vulnerability2026-08-11
- highCVE-2026-64909: Microsoft Office Remote Code Execution Vulnerability2026-08-11