Microsoft Defender Update Leaves Linux Servers Vulnerable Post-Reboot

Microsoft’s recent update to Defender for Endpoint inadvertently disabled antivirus protection on certain Linux servers following system reboots, leaving these systems exposed to potential threats. The issue affected platform builds 101.26042.0000 through 101.26042.0009, where the Defender service failed to restart after an upgrade and subsequent reboot.

System administrators reported that the ‘mdatp’ service, running version 101.26042.0009, became inactive after routine patching and reboots over the weekend, necessitating urgent troubleshooting to restore protection across affected servers.

In response, Microsoft withdrew the problematic builds from the production channel across all supported Linux distributions, preventing further installations of the faulty versions. To address the issue, the company released platform version 101.26042.0011, which resolves the service disablement problem. Administrators are advised to upgrade directly to this build to reinstate active protection.

To ensure systems are secure, administrators should:

  • Verify the current Defender version by running ‘mdatp health’ on Linux endpoints to confirm the platform build is 101.26042.0011 or newer.
  • Cross-reference with the Microsoft Defender portal’s ‘Device health’ report to identify any endpoints reporting an inactive or disabled antivirus state.
  • Prioritize remediation on internet-facing or high-value Linux servers, as these are at greater risk during protection gaps.
  • Review recent patch and reboot logs to identify machines that underwent the vulnerable upgrade path between the release of the affected build and the deployment of the fix.

This incident highlights the importance of post-update verification, especially in mixed-OS environments. While Microsoft’s efforts to expedite update delivery aim to enhance responsiveness, this event underscores the need for organizations to actively monitor agent health and not solely rely on the success of updates to ensure system security.