Kaspersky has published an advisory confirming it fixed the issue behind HardBreacher, a proof-of-concept exploit that a researcher released publicly, with no warning to the company, over the weekend. The advisory is interesting less for the fix than for how small the company says the problem was.
"Kaspersky has fixed the issue described in the HardBreacher research," the advisory reads. The issue "could potentially have resulted in a partial degradation of the application functionality," and "was mitigated by updating the antivirus databases." Kaspersky lists Kaspersky Endpoint Security for Windows 14.0 and 14.1 as affected, and says the fix rides in antivirus databases released on 30 August 2026 or later. Asked about the exploit, Kaspersky told SecurityWeek: "The corresponding fix is delivered via an automatic update, or users can trigger a database update manually."
The vendor and the exploit describe different bugs
The repository is titled "Kaspersky Antivirus For Endpoint ZeroDay Elevation of Privileges Vulnerability." Kaspersky's advisory never uses that phrase. It does not dispute it either. It describes a possible loss of application functionality and stops there, which leaves a vendor and a researcher characterising the same fix in materially different terms, with no independent test to settle it.
The repository README is unusually candid about its own limits. The author says the code "is not in the best shape at all, it is basically duct tapped," that it fails often and has to be rerun, and that success looks like one file written into C:\Windows\System32 with full permissions for the current user. He reports testing a single build, Kaspersky Endpoint Security 14.0.0.504, on a fully patched Windows 11 25H2. Kaspersky's advisory covers more ground than he tested, naming both the 14.0 and 14.1 branches.
That is a narrower claim than some accounts of it have suggested. The README does not describe a standard user reaching SYSTEM, and nobody has published a reproduction. Of the repository's 54 forks, all but one are unmodified copies.
Two more drops in the next 48 hours

The three releases and what each one claims. Diagram by IntelFusions.
HardBreacher was not the end of it. On 29 August the same account published GreenSection, claiming a memory corruption bug in Nvidia user mode components where a shared memory section is left writable by every user on the machine. The author is explicit that it "does not get SYSTEM privileges immediately." On 30 August came PrettyPrague, aimed at Avast, and it carries the most serious claim of the three: a dump of the SAM database, the store of Windows password hashes, plus a full SYSTEM shell on a fully patched installation. The author writes that he believes it may affect other Gen Digital products such as AVG and Norton. Both were publicised on the X account @MSNightmare2000, which carries the same display name and bio as the GitHub profile.
Neither Nvidia nor Gen Digital had published a statement IntelFusions could find on 31 August. The vendor that answered was the one whose bug the researcher himself called duct tapped.
Check the database date, and do not run the binaries
Kaspersky's own remediation advice is to check the antivirus database update date inside the application. Anything from 30 August 2026 or later carries the fix, and that update normally arrives on its own. There is no patch to install and no identifier to track: no CVE appears in any of the three repositories, and none appears in Kaspersky's advisory, although other entries on the same page do cite CVE numbers.
The second precaution concerns the exploits themselves. All three repositories ship compiled Windows executables alongside their source, and HardBreacher alone has been forked 54 times. Running a stranger's precompiled exploit is a well established way to get compromised, as the campaign that trojanised public exploit code to steal researchers' credentials showed earlier this month.
The researcher has a track record against Microsoft, which names two of his releases in its own vulnerability records: RoguePlanet as CVE-2026-50656 and ShieldBreak as CVE-2026-69414. Those are different bugs in different products and they corroborate nothing about the Kaspersky claim. We covered the RoguePlanet patch in July. What changed this week is the target list. After months aimed squarely at Microsoft, three vendors in three days.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.