CyberSecurityNews

Microsoft Defender for Endpoint Update Leaves Linux Servers Unprotected After Reboot


A recent Microsoft Defender for Endpoint update briefly disabled antivirus protection on Linux servers following an upgrade and reboot, exposing affected machines to threats before Microsoft rolled out a fix.

The issue struck Linux platform builds 101.26042.0000 through 101.26042.0009, where the Defender service could become disabled on devices that were upgraded and then rebooted, effectively leaving those systems without active protection.

System administrators on community forums confirmed the real-world impact, with one report describing how the mdatp service (running version 101.26042.0009) went down following weekend patch reboots, prompting urgent troubleshooting across affected fleets.

Microsoft responded by pulling the affected builds from the production channel entirely across all supported Linux distributions, meaning the buggy versions are no longer available for new installations.

Microsoft Defender for Endpoint Impacts Linux

This is not the first time Defender’s Linux agent has run into upgrade-related service failures; a similar real-time scanning bug in the January 2026 release caused unexpected reboots on systems with hardware watchdogs enabled.

Microsoft has released platform version 101.26042.0011 to resolve the disabled-service issue, and customers running the affected builds or older supported versions are advised to upgrade directly to this build to restore protection.

Administrators should verify their Defender health status immediately rather than assuming an upgrade alone resolved the gap, since the disabled state persisted silently after the update completed and a reboot occurred.

A silently disabled endpoint agent is a high-risk blind spot, since Linux servers frequently run business-critical workloads and often lack the visibility layers common on Windows fleets. Security teams should treat this as a reminder to actively monitor agent health rather than trust update success alone.

  • Check current version: run mdatp health on affected Linux endpoints to confirm the platform build is 101.26042.0011 or newer.
  • Cross-reference with the Microsoft Defender portal’s “Device health” report to flag any endpoints still reporting an inactive or disabled antivirus state.
  • Prioritize remediation on internet-facing or high-value Linux servers first, since these carry the greatest exposure risk during any protection gap.
  • Review recent patch/reboot logs to identify which machines went through the vulnerable upgrade path between the affected build’s release and the 101.26042.0011 fix.

This incident lands amid a period when Microsoft has also been reworking how Defender delivers updates more broadly, including decoupling Windows EDR sensor updates from monthly OS patches to speed up delivery.

While that shift aims to improve responsiveness, the Linux service-disable bug underscores that faster update cycles still carry regression risk, making post-update verification an essential step rather than an optional one for any organization running mixed-OS endpoint fleets.

 Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.



Source link