Microsoft Defender for Endpoint leaves some Linux boxes defenseless after update
Microsoft has identified two distinct bugs in Defender for Endpoint on Linux affecting versions 101.26042.0000 through 101.26042.0009. The primary issue can disable the security service following system restarts or fresh installations across all supported Linux platforms. A second problem prevents these versions from installing on Red Hat Enterprise Linux 8 and 9 systems configured with FIPS compliance standards.
The problems carry significant operational implications because automatic update mechanisms may have already deployed the affected versions to cloud-managed systems, potentially leaving devices without active endpoint protection after reboots until remediation occurs. Microsoft directed users to upgrade to version 101.26042.0011 for the first issue and 101.26052.0011 or later for the FIPS installation problem. The incidents underscore broader concerns about update reliability when security-critical components are affected.
- Microsoft Defender for Endpoint Linux versions 101.26042.0000-9 disable the security service after system reboot or reinstall
- Same versions fail to install on FIPS-enabled Red Hat Enterprise Linux 8 and 9
- Affected versions may already be distributed via automatic updates, leaving some systems unprotected until patched