Microsoft Defender for Endpoint release notes
发布时间:2026-08-31 | 浏览:1
Access to this page requires authorization. You can try signing in or changing directories .
Access to this page requires authorization. You can try changing directories .
This article describes releases of Microsoft Defender for Endpoint across Windows, macOS, Linux, Android, and iOS in the past six months.
To learn about Microsoft Defender for Endpoint features that aren't version-specific, see What's new in Microsoft Defender for Endpoint .
Microsoft Defender for Endpoint requires that you update your list of allowed URLs from time to time. To review recent changes in the list of allowed URLs, see Microsoft Defender for Endpoint streamlined connectivity URLs - commercial
All supported releases by date
This table includes supported releases for all supported platforms in the past six months. Each release includes a link to the full release details section.
Windows releases
This section covers Microsoft Defender for Endpoint EDR MsSense.exe versions. You can also check the file information section in the monthly cumulative rollup updates in the following articles:
Windows 11 release information
Windows 10 updates
Windows Server 2022 updates
Windows Server 2019 updates
Windows Server 2025 updates
Windows | February 2026 | Platform: 10.8821
Release details
Enhancements and features
Windows | September 2025 | Platform: 10.8804
Release details
Enhancements and features
Windows | July 2025 | Platform: 10.8798
Release details
Enhancements and features
Windows | May 2025 | Platform: 10.8797.25857.1000
Release details
Enhancements and features
Windows | July 2024 | Platform: 10.8760.27617.1006
Release details
Enhancements and features
Defender for Endpoint supports macOS version 14 (Sonoma) or newer. macOS 11 (Big Sur), 12 (Monterey), and 13 (Ventura) are no longer supported.
To share feedback, open Defender for Endpoint on macOS and go to Help > Send feedback .
To get latest features, configure your device for the Beta channel (formerly Insider-Fast) device.
For known issues, see macOS known issues .
macOS | August-2026 | 101.26062.0012
Enhancements and features
macOS | August-2026 | 101.26062.0011
Enhancements and features
macOS | July-2026 | 101.26062.0009
Enhancements and features
macOS | July-2026 | 101.26052.0016
Enhancements and features
macOS | June-2026 | 101.26042.0020
Enhancements and features
macOS | April-2026 | 101.26032.0016
Enhancements and features
macOS | April-2026 | 4.18.25040.1
Enhancements and features
macOS | April-2026 | 101.26022.0020
Enhancements and features
macOS | April-2026 | 101.26022.0018
Enhancements and features
macOS | March-2026 | 101.26012.0017
Enhancements and features
macOS | March-2026 | 101.26012.0015
Enhancements and features
macOS | February-2026 | 101.26012.0012
Enhancements and features
macOS | February 2026 | Platform: 101.25122.0008
Release details
Enhancements and features
Bug and performance fixes
macOS | January 2026 | Platform: 101.25122.0007
Release details
Enhancements and features
Bug and performance fixes
macOS | January 2026 | Platform: 101.25122.0006
Release details
Enhancements and features
macOS | December 2025 | Platform: 101.25102.0019
Release details
Enhancements and features
macOS | November 2025 | Platform: 101.25102.0016
Release details
Enhancements and features
macOS | October 2025 | Platform: 101.25082.0006
Release details
Enhancements and features
macOS | September 2025 | Platform: 101.25072.0011
Release details
Enhancements and features
macOS known issues
Microsoft Defender for Endpoint might experience issues on macOS (Build 101.26012.0015, Production ring). Affected devices may exhibit performance degradation, repeated Defender process crashes, and devices not waking from sleep. To resolve this issue, deploy one of the following updates: Hotfix (Production): Update to version 101.26012.0017. Insider Fast (2602): Update to version 101.26022.0015.
Microsoft Defender for Endpoint might experience issues on macOS (Build 101.26012.0015, Production ring). Affected devices may exhibit performance degradation, repeated Defender process crashes, and devices not waking from sleep. To resolve this issue, deploy one of the following updates:
Hotfix (Production): Update to version 101.26012.0017.
Insider Fast (2602): Update to version 101.26022.0015.
In version 2506 (101.25062.0005), attempts to upgrade Microsoft Defender for Endpoint on macOS consistently failed. Other versions of Defender are not impacted. To overcome this issue, there is a supported workaround for supported macOS versions and beta versions of macOS 26. The instructions for the workaround can be found here .
In version 2506 (101.25062.0005), attempts to upgrade Microsoft Defender for Endpoint on macOS consistently failed. Other versions of Defender are not impacted. To overcome this issue, there is a supported workaround for supported macOS versions and beta versions of macOS 26. The instructions for the workaround can be found here .
Apple fixed an issue on macOS Ventura upgrade and macOS Sonoma upgrade with the latest OS update. The issue impacts Defender for Endpoint security extensions, and might result in losing Full Disk Access Authorization, impacting the ability of Defender for Endpoint to function properly.
Apple fixed an issue on macOS Ventura upgrade and macOS Sonoma upgrade with the latest OS update. The issue impacts Defender for Endpoint security extensions, and might result in losing Full Disk Access Authorization, impacting the ability of Defender for Endpoint to function properly.
In macOS Sonoma 14.3.1 , Apple made a change to the handling of Bluetooth devices that impacts Defender for Endpoint device control's ability to intercept and block access to Bluetooth devices. At this time, the recommended mitigation is to use a version of macOS earlier than 14.3.1.
In macOS Sonoma 14.3.1 , Apple made a change to the handling of Bluetooth devices that impacts Defender for Endpoint device control's ability to intercept and block access to Bluetooth devices. At this time, the recommended mitigation is to use a version of macOS earlier than 14.3.1.
In macOS Sequoia (version 15.0), if you have Network Protection enabled, you might see crashes of the network extension (NetExt). This issue results in intermittent network connectivity issues for end users. Upgrade to macOS Sequoia version 15.1 or newer.
In macOS Sequoia (version 15.0), if you have Network Protection enabled, you might see crashes of the network extension (NetExt). This issue results in intermittent network connectivity issues for end users. Upgrade to macOS Sequoia version 15.1 or newer.
On macOS Sequoia (Version 15.0 - 15.1.1), users might encounter prompts about incoming network connections from applications when the native firewall is active.
On macOS Sequoia (Version 15.0 - 15.1.1), users might encounter prompts about incoming network connections from applications when the native firewall is active.
If an end user encounters a prompt for Defender for Endpoint on macOS processes such as wdavdaemon_enterprise or Microsoft Defender Helper , the end user can safely choose the Deny option. This selection doesn't affect Defender for Endpoint's functionality. Enterprises can also add Microsoft Defender to allow incoming connections . This issue is fixed in macOS Sequoia 15.2.
Defender for Endpoint on Linux is updated regularly. While security fixes are included as part of monthly releases, the fixes aren't always listed as a separate Security Patch item in these notes. If a release contains security-related updates, the updates are listed in this article in the specific version section.
For detailed information on Microsoft security updates, see the Microsoft Security Update Guide .
Each Defender for Endpoint on Linux version expires automatically after nine months. Expired versions continue to receive security intelligence updates, but you should install the latest version to receive all available fixes and enhancements.
To check your client expiration date, run the following command:
mdatp health --field product_expiration
The previous RHEL 6 exception for version 101.23082.0011 was time-bound through June 30, 2024 and is no longer active.
Starting with version 101.24082.0004 , Defender for Endpoint on Linux no longer supports the Auditd event provider. We're transitioning completely to the more efficient eBPF technology. This change allows for better performance, reduced resource consumption, and overall improved stability. eBPF support is available since August 2023, and is fully integrated into all updates of Defender for Endpoint on Linux (version 101.23082.0006 and later). We strongly encourage you to adopt the eBPF build, as it provides significant enhancements over Auditd. If eBPF isn't supported on your machines, or if there are specific requirements to remain on Auditd, you have the following options:
Continue to use Defender for Endpoint on Linux build 101.24072.0000 with Auditd. This build continues to be supported for several months, so you have time to plan and execute your migration to eBPF.
If you are on versions later than 101.24072.0000 , Defender for Endpoint on Linux relies on netlink as a backup supplementary event provider. If a fallback occurs, all operations continue to flow seamlessly.
Review your current Defender for Endpoint on Linux deployment, and begin planning your migration to the eBPF-supported build. For more information on eBPF and how it works, see Use eBPF-based sensor for Microsoft Defender for Endpoint on Linux .
If you have any concerns or need assistance during this transition, contact support.
Linux known issues
Issues have been found with versions 101.26042.0000–101.26042.0009
Issues have been found with versions 101.26042.0000–101.26042.0009 , where the Defender service might be disabled on some devices that were upgraded and rebooted. For all supported Linux operating systems, affected versions have been removed from the production channel, and are no longer available for installation.
If you use Defender for Servers (Plan 1 or 2) with Defender for Cloud and have the MDE integration enabled, automatic updates for the MDE.Linux extension are enabled by default, which means your machines could have received an affected version automatically. If an affected version was installed, the issue might impact active protection on rebooted devices until remediation steps are taken.
If you haven't upgraded yet, we recommend upgrading to the following build version: 101.26042.0011.
Update may fail on FIPS-enabled RHEL 8/9 devices
We are investigating an issue where some devices running Red Hat Enterprise Linux (RHEL) 8 or 9 with FIPS mode enabled may fail to install Microsoft Defender for Endpoint on Linux platform version 101.26042.x.
Affected devices may be unable to complete the platform update and may remain on their previously installed platform version until a corrected package is available.
Fixed in platform version 101.26052.0011 and later. FIPS-enabled RHEL 8/9 devices that were affected by this issue can now install/update to 101.26052.0011 or later successfully.
Linux | Aug 2026 | 101.26062.0007
Release details
Enhancements and features
Linux | July 2026 | 101.26052.0012
Release details
Enhancements and features
Linux | June 2026 | 101.26042.0011
Release details
Enhancements and features
Linux | April 2026 | 101.26032.0000
Release details
Enhancements and features
Linux | March 24, 2026 | Update: post-release fix
Fixed an issue in the January 2026 release, where real-time scanning of the /dev/watchdog device could trigger unexpected system reboots on systems with hardware watchdog enabled. For more information, see Linux | January 2026 | Platform: 101.25102.0005 .
Linux | March 2026 | 101.26021.0002
Release details
Enhancements and features
Linux | March 2026 | 101.26012.0007
Release details
Enhancements and features
Issues have been found with versions 101.26042.0000–101.26042.0009
Issues have been found with versions 101.26042.0000–101.26042.0009 , where the Defender service might be disabled on some devices that were upgraded and rebooted. For all supported Linux operating systems, affected versions have been removed from the production channel, and are no longer available for installation.
If you use Defender for Servers (Plan 1 or 2) with Defender for Cloud and have the MDE integration enabled, automatic updates for the MDE.Linux extension are enabled by default, which means your machines could have received an affected version automatically. If an affected version was installed, the issue might impact active protection on rebooted devices until remediation steps are taken.
If you haven't upgraded yet, we recommend upgrading to the following build version: 101.26042.0011.
Update may fail on FIPS-enabled RHEL 8/9 devices
We are investigating an issue where some devices running Red Hat Enterprise Linux (RHEL) 8 or 9 with FIPS mode enabled may fail to install Microsoft Defender for Endpoint on Linux platform version 101.26042.x.
Affected devices may be unable to complete the platform update and may remain on their previously installed platform version until a corrected package is available.
Fixed in platform version 101.26052.0011 and later. FIPS-enabled RHEL 8/9 devices that were affected by this issue can now install/update to 101.26052.0011 or later successfully.
Linux | February 2026 | 101.25122.0004
Release details
Enhancements and features
Linux | January 2026 | Platform: 101.25102.0005
Release details
Enhancements and features
Linux | December 2025 | Platform: 101.25092.0005
Release details
Enhancements and features
Linux | December 2025 | Platform: 101.25092.0002
Release details
Enhancements and features
Linux | November 2025 | Platform: 101.25102.0003
Release details
Enhancements and features
Linux | October 2025 | Platform: 101.25092.0001
Release details
Enhancements and features
Linux | September 2025 | Platform: 101.25082.0003 (Build 1)
Release details
Enhancements and features
Linux | September 2025 | Platform: 101.25072.0003 (Build 2)
Release details
Enhancements and features
Linux | August 2025 | Platform: 101.25062.0003
Release details
Enhancements and features
Android releases
See the full list of Android UX improvements .
Android | Aug 2026 | Platform: 1.0.9212.0102
Release details
Enhancements and features
Android | Aug 2026 | Platform: 1.0.9129.0101
Release details
Enhancements and features
Android | July 2026 | Platform: 1.0.9107.0101
Release details
Enhancements and features
Android | June 2026 | Platform: 1.0.9029.0101
Release details
Enhancements and features
Android | June 2026 | Platform: 1.0.9014.0101
Release details
Enhancements and features
Android | June 2026 | Platform: 1.0.9003.0101
Release details
Enhancements and features
Android | May 2026 | Platform: 1.0.8913.0101
Release details
Enhancements and features
Android | April 2026 | Platform: 1.0.8805.0103
Release details
Enhancements and features
Android | December 2025 | Platform: 1.0.8412.0101
Release details
Enhancements and features
Android | December 2025 | Platform: 1.0.8321.0101
Release details
Enhancements and features
Android | November 2025 | Platform: 1.0.8315.0101
Release details
Enhancements and features
Android | November 2025 | Platform: 1.0.8303.0101
Release details
Enhancements and features
Android | October 2025 | Platform: 1.0.8217.0101
Release details
Enhancements and features
Android | October 2025 | Platform: 1.0.8201.0101
Release details
Enhancements and features
Android | September 2025 | Platform: 1.0.8102.0101
Release details
Enhancements and features
Android | August 2025 | Platform: 1.0.8018.0103
Release details
Enhancements and features
Android | July 2025 | Platform: 1.0.7901.0101
Release details
Enhancements and features
For the latest UX improvements, see iOS UX improvements .
iOS | Aug 2026 | Platform Version: 1.1.80120102
Release details
Enhancements and features
iOS | Aug 2026 | Platform Version: 1.1.79210103
Release details
Enhancements and features
iOS | July 2026 | Platform Version: 1.1.79080103
Release details
Enhancements and features
iOS | July 2026 | Platform Version: 1.1.78290102
Release details
Enhancements and features
iOS | June 2026 | Platform Version: 1.1.78020101
Release details
Enhancements and features
iOS | June 2026 | Platform Version: 1.1.77280101
Release details
Enhancements and features
iOS | May 2026 | Platform Version: 1.1.77130101
Release details
Enhancements and features
iOS | November 2025 | Platform: 1.1.70290103
Release details
Enhancements and features
iOS | October 2025 | Platform: 1.1.70230101, 1.1.69250104
Release details
Enhancements and features
iOS | September 2025 | Platform: 1.1.68200103
Release details
Enhancements and features
iOS | August 2025 | Platform: 1.1.68140102
Release details
Enhancements and features
iOS | July 2025 | Platform: 1.1.67040101
Release details
Enhancements and features
Microsoft Defender Antivirus releases
For more information about Microsoft Defender Antivirus updates, see Microsoft Defender Antivirus security intelligence product updates and support .
Windows Antivirus | July 2026 | Platform 4.18.26070.9 | Engine 1.1.26070.7
Release details
1 The security intelligence version listed here is relevant to the listed engine release. Newer versions of security intelligence are released regularly. For more information, see Security intelligence updates for Microsoft Defender Antivirus and other Microsoft anti-malware .
Enhancements and features
Improved archive scanning performance to scale service memory limits dynamically based on the number of logical cores.
Improved cache builds on devices with Lunar Lake CPUs by using TrustedImageIdentifier .
Fixed an issue where files that were already excluded were still submitted to the cloud protection service for rescanning, only to return the same result.
Fixed HTTPS connection stalls under Network Protection Block mode caused by dropped TCP FIN segments.
Windows Antivirus | June 2026 | Platform 4.18.26060.3008 | Engine 1.1.26060.3008
Release details
1 The security intelligence version listed here is relevant to the listed engine release. Newer versions of security intelligence are released regularly. For more information, see Security intelligence updates for Microsoft Defender Antivirus and other Microsoft anti-malware .
Enhancements and features
Resolved an issue where Controlled Folder Access toast notifications continuously appeared for the C: drive because of AMD driver injection into protected processes, so users no longer see a flood of repeated CFA "protected memory" prompts.
Improved Endpoint DLP enforcement reliability for Chrome uploads to Google Drive, ensuring policy-based blocking is consistently applied during bulk file transfers.
Fixed an issue in Endpoint DLP where Chrome and Firefox uploads could occasionally display the default Just-In-Time (JIT) notification instead of the organization-configured custom message due to a timing-related race condition.
Addressed Microsoft Defender Elevation of Privilege vulnerability CVE-2026-50656, improving protection against local privilege escalation scenarios in the Microsoft Malware Protection Engine
Windows Antivirus | May 2026 | Platform 4.18.26050.15 | Engine 1.1.26050.11
Release details
1 The security intelligence version listed here is relevant to the listed engine release. Newer versions of security intelligence are released regularly. For more information, see Security intelligence updates for Microsoft Defender Antivirus and other Microsoft anti-malware .
Enhancements and features
Fixed remote-share file scans missing detections, when files were accessed through a symlink.
Fixed mpcmdrun -scan output incorrectly displaying non-ASCII characters in localized paths and threat names.
Fixed network protection watchdog timers silently not firing.
Windows Antivirus | April 2026 | Platform 4.18.26040.7 | Engine 1.1.26040.8
Release details
1 The security intelligence version listed here is relevant to the listed engine release. Newer versions of security intelligence are released regularly. For more information, see Security intelligence updates for Microsoft Defender Antivirus and other Microsoft anti-malware .
Enhancements and features
Performance improvement for SFC cache build during engine reload.
Reduced API calls for Device Control to prevent Entra throttling and improved logging.
Improved TVM Block logic handling.
Fixed TVM Warn temporary paths exclusion issue when Tamper Protection Exclusions and Disable Local Admin Merge (DLAM) are enabled.
Fixed Defender managed type when migrating from Co-management to Intune.
Fixed three CVEs: CVE-2026-41091 : Microsoft Defender Elevation of Privilege Vulnerability — Improper link resolution before file access (Important; fixed in Engine 1.1.26040.8). CVE-2026-45498 : Microsoft Defender Denial of Service Vulnerability (Low; fixed in Platform 4.18.26040.7). CVE-2026-45584 : Microsoft Defender Remote Code Execution Vulnerability — Heap-based buffer overflow (Critical; fixed in Engine 1.1.26040.8).
CVE-2026-41091 : Microsoft Defender Elevation of Privilege Vulnerability — Improper link resolution before file access (Important; fixed in Engine 1.1.26040.8).
CVE-2026-45498 : Microsoft Defender Denial of Service Vulnerability (Low; fixed in Platform 4.18.26040.7).
CVE-2026-45584 : Microsoft Defender Remote Code Execution Vulnerability — Heap-based buffer overflow (Critical; fixed in Engine 1.1.26040.8).
Windows Antivirus | March 2026 | Platform 4.18.26030.3011 | Engine 1.1.26030.3008
Release details
1 The security intelligence version listed here is relevant to the listed engine release. Newer versions of security intelligence are released regularly. For more information, see Security intelligence updates for Microsoft Defender Antivirus and other Microsoft anti-malware .
Enhancements and features
Fixed a bug where Antimalware Scan Interface (AMSI) scan calls weren't passing exclusions in the scan configuration, causing unnecessary scans on excluded content.
Fixed deadlocks in the platform that occur during remote procedure calls (RPC).
Fixed a bug where Microsoft Protection Antimalware (MPAM) packages downloaded for direct update from Microsoft Malware Protection Center (MMPC) aren't cleaned up when the update fails, leading to unnecessary disk usage over time.
Improved quick scan error handling logic to avoid scan interruptions due to corrupted user registry hive.
Fixed tamper protection exclusions not activating after transitioning existing devices from co-management to full Intune management.
Fixed Network Inspection Service (NisSrv) ESP reputation mode checks to avoid blocks during service shutdown, which impact Remote Desktop Protocol (RDP) sessions.
Fixed the Defender Core Service display name in the Windows Services console.
Fixed NisSrv self-healing when the service crosses memory thresholds.
Improved encrypted PDF scanning.
Fixed Get-MpPerformanceReport JSON parsing failures.
Was this page helpful?
Need help with this topic?
Want to try using Ask Learn to clarify or guide you through this topic?
Additional resources
Last updated on 2026-08-05