
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-50658 is a Time-of-check Time-of-use (TOCTOU) race condition vulnerability in Microsoft Defender for Endpoint for Mac that allows an authorized local attacker to elevate privileges. It affects versions from 101.0.0 up to (excluding) 101.26042.0020. The vulnerability was disclosed on July 14, 2026, as part of Microsoft's July 2026 Patch Tuesday, which addressed a record 570 vulnerabilities. It carries a CVSS v3.1 base score of 7.0 (High), assigned by Microsoft (Microsoft MSRC, Feedly).
The vulnerability is classified as CWE-367 (Time-of-check Time-of-use Race Condition), where a security check is performed and then a privileged action is executed, but an attacker can manipulate the resource in the window between the two operations. This is consistent with CAPEC-27 (Leveraging Race Conditions via Symbolic Links) and CAPEC-29 (Leveraging TOCTOU Race Conditions), suggesting the attack may involve symbolic link manipulation to redirect file operations performed by the Defender process after a security check has passed. Exploitation requires local access and low privileges, but has high attack complexity due to the timing requirements of the race condition (Microsoft MSRC, Feedly).
Successful exploitation allows an authorized local user with limited privileges to escalate to elevated system privileges on macOS. The CVSS metrics indicate high confidentiality, integrity, and availability impact, meaning an attacker could gain full control over the affected system, access sensitive data, modify system files, or disrupt Defender's security functions. The scope is limited to the local system (unchanged scope), but privilege escalation could enable further lateral movement or persistence within the environment (Microsoft MSRC, Feedly).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation. CISA's SSVC assessment classifies exploitation as "none" and the vulnerability as not automatable. The EPSS score is approximately 0.193%, reflecting a low near-term exploitation probability. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog (Microsoft MSRC, Feedly).
Microsoft has released a patch addressing this vulnerability. Organizations should update Microsoft Defender for Endpoint for Mac to version 101.26042.0020 or later. As a defense-in-depth measure, restrict local system access to trusted users only and monitor for suspicious privilege escalation activity targeting Defender processes. No configuration-based workaround has been published; patching is the recommended remediation (Microsoft MSRC, Feedly).
The vulnerability was noted as part of Microsoft's July 2026 Patch Tuesday, which was widely covered due to its record-breaking scope of 570 fixes and three zero-days. Security community outlets such as BleepingComputer and SANS ISC covered the broader Patch Tuesday release, with CVE-2026-50658 receiving limited individual attention given its local-only attack vector and lack of active exploitation (BleepingComputer, SANS ISC).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."