Action Required: Defer Upgrade to Microsoft Defender for Endpoint on Linux Build 101.26052.0009

🚨 The Signal: Microsoft Defender for Endpoint on Linux build 101.26052.0009 has a critical bug on FIPS-enabled RHEL 8/9, causing installation failures. Microsoft has paused the rollout, requiring organisations to defer upgrades to maintain endpoint protection.

The Impact

Security teams are affected by a critical bug in Defender for Endpoint on Linux, risking unpatched systems and reduced endpoint protection.

  • Security Teams: Risk of unpatched Linux endpoints due to failed Defender updates.
  • Security Teams: Potential for reduced visibility and protection on FIPS-enabled RHEL 8/9 systems.
  • Admins: Must actively prevent deployment of the problematic Defender for Endpoint build.

The Action

  1. Do not upgrade Microsoft Defender for Endpoint on Linux to build 101.26052.0009.
  2. Monitor the Microsoft 365 Message Center for updates on the revised build release.
  3. Review existing deployment pipelines to ensure this specific build is blocked for FIPS-enabled RHEL 8 and RHEL 9 devices.

Domain: Defender · Impact: high · Workload: Microsoft Defender · Essential Eight: Patch Applications, Patch Operating Systems · ISM: ISM-0304, ISM-1407, ISM-1501, ISM-1621, ISM-1622, ISM-1623, ISM-1654, ISM-1655, ISM-1690, ISM-1691, ISM-1692, ISM-1693, ISM-1694, ISM-1695, ISM-1696, ISM-1698, ISM-1699, ISM-1700, ISM-1701, ISM-1702, ISM-1704, ISM-1807, ISM-1808, ISM-1876, ISM-1877, ISM-1889, ISM-1901, ISM-1902, ISM-1905