This isn't a Windows cumulative update, an engine upgrade or a new feature. It's a definitions refresh, the routine kind that keeps Defender current. Still, because it's routine, people tend to find it confusing. Why does the same KB number keep showing up? Is a failed install dangerous? Should you be clearing definitions before you update? Here's what the evidence supports.
What's actually in 1.459.576.0
Microsoft's change log splits each release into newly added detections and updated ones. For 1.459.576.0 it lists two new detections, both rated severe:
- Ransom:HTML/CrpxCrypter.PA!MTB
- Trojan:Win64/AgentB.A!MTB
The updated list is much longer, more than a hundred entries. Many familiar names are on it:
- Ransomware families: LockBit (Win64), BlackCat (Windows and Linux) and BabukLoader
- Loaders and banking trojans: Qakbot in many forms (HTML, JS, VBS, LNK, Office macro, BAT and Win32/Win64), Emotet, IcedID, Latrodectus, ZLoader and Oyster
- Remote access and post-exploitation tools: XWorm, Remcos, Meterpreter and the Sliver framework (as VirTool:Win32/Sliver)
- Cross-platform entries: Linux backdoors such as Mirai and Gafgyt, a Linux exploit detection called DirtyFrag, and a run of "Multiverze" detections covering Android, macOS, Python, script, Linux and Windows
- Grey-area tools: HackTool:Win32/AutoKMS and HackTool:Win32/Crack, both rated high
That last group matters on PCs where someone has used an unofficial KMS activator or a software crack. Defender may flag those files after it picks up a new definition set. That's working as designed, not a false positive to report.
Many of the updated entries end in "!rfn" or "!MTB". These are Microsoft's internal detection suffixes, and the change log doesn't explain them. Read the list as a sign of where Microsoft has been tuning its detections. It doesn't tell you what's attacking you today.
Section summary: Microsoft's own change log confirms 1.459.576.0. It adds two new severe detections and updates more than a hundred others, mostly ransomware, loaders and remote-access tools.
A tale of two version numbers
Your screen may show a different number from the one in the headline, and there's a simple reason. A snapshot of Microsoft's manual download page from the same day listed Version: 1.459.574.0, Engine Version: 1.1.26080.3, Platform Version: 4.18.26080.4, Released: 10/6/2026 8:04:37 AM.
Put the two timestamps side by side. Build .574.0 shipped that morning and .576.0 followed a few hours later. That's normal. The OPSWAT documentation on KB2267602 says Microsoft adjusts detection logic (daily or twice a day), and that Microsoft provide a different version of KB2267602 instead of a new KB name.
That also explains a common complaint. Notebookcheck noted that seeing the same KB offered the next day again is normal behavior. The KB number stays the same while the build number underneath it changes. By the time you read this, 1.459.576.0 may have been replaced too.
How KB2267602 fits into Defender servicing
Microsoft Learn's Defender update documentation splits updates into separate tracks, each with its own KB:
| Component | KB / cadence | What it does |
|---|---|---|
| Security intelligence (Defender Antivirus) | KB2267602, several times a day | Malware definitions |
| Security intelligence (System Center Endpoint Protection) | KB2461484 | Definitions for SCEP |
| Antimalware platform | KB4052623, monthly | The Defender client itself |
| Engine | Monthly, bundled with intelligence updates | Scanning engine |
Microsoft also says Defender pulls dynamic security intelligence through cloud-delivered protection (MAPS). Those dynamic updates add to the regular definition updates and don't replace them. In its evaluation guidance, Microsoft notes that standard intelligence updates can take hours to prepare and deliver, while cloud protection can respond to new threats in seconds. That's why it recommends keeping cloud protection on.
On managed fleets, timing also depends on which channel a device is in. A Microsoft Q&A answer explains that devices in the broad channel receive security intelligence updates only after the gradual rollout completes. Two machines on the same network can show different builds for a few hours.
Step-by-step: check your installed version
Windows Security (any user):
- Open Windows Security from the Start menu.
- Select Virus & threat protection.
- Select Virus & threat protection updates. Notebookcheck calls this page "Protection Updates"; the label differs a little between builds.
- Read the Security intelligence version and its download date.
- Select Check for updates to fetch anything newer.
Microsoft's documentation adds one caveat for managed devices. If Defender updates come from WSUS or a Software Update Point, and Windows Update policy is set to "3 – Auto download and notify for install", Check for updates installs every available Defender update (intelligence, engine and platform), not just definitions.
PowerShell (elevated):
Get-MpComputerStatus | Format-Table AntivirusSignatureVersion
A Microsoft employee on Microsoft Q&A suggested a version that also shows when the last update happened: Get-MpComputerStatus | select AntivirusSignatureVersion,AntivirusSignatureLastUpdated
What success looks like: you're current if your build is 1.459.576.0 or anything numerically higher. Never roll back to match a number in a news story.
Step-by-step: request an update from the command line
MpCmdRun.exe usually isn't on your PATH. Microsoft says the current copy sits in the newest folder under %ProgramData%\Microsoft\Windows Defender\Platform\<platform version>, with %ProgramFiles%\Windows Defender as the fallback.
- Open Command Prompt with Run as administrator.
- Change to the folder that contains
MpCmdRun.exe. - Run one of the commands Microsoft documents:
MpCmdRun.exe -SignatureUpdate
MpCmdRun.exe -SignatureUpdate -UNC \\FileServer\ShareName
MpCmdRun.exe -SignatureUpdate -MMPC
The first uses the device's configured update source. The -UNC form pulls from a file share. The -MMPC form downloads straight from Microsoft's Malware Protection Center, which helps when you suspect WSUS is the problem. The ElevenForum tutorial uses the shortcut "%ProgramFiles%\Windows Defender\MpCmdRun.exe" -SignatureUpdate, which works on most consumer PCs. The platform-folder copy is the more current binary, though.
Running the command doesn't prove anything installed. Check the version again afterward.
About clearing definitions first
Notebookcheck says Microsoft's guidance for a stuck cache pairs the update command with one that removes old definitions first, and it advises checking the documentation before running that across a fleet. That's good advice.
Microsoft Learn lists the removal commands under rolling back an update:
MpCmdRun.exe -RemoveDefinitions -Allreturns security intelligence to the previous version or the original inbox set.MpCmdRun.exe -RemoveDefinitions -DynamicSignaturesremoves only the dynamically downloaded intelligence.
Our take, based on general IT practice: use -All as a recovery tool for a diagnosed problem, not as part of every update. If you run it and the update that follows fails, the machine is left on old or inbox definitions. Test it on one device before you script it for thousands.
Fixing a stalled update
- Try the Microsoft source directly. A Microsoft Q&A answer notes that if a manual install works, the problem is likely with the configured update source (WSUS, UNC share, or Windows Update policy).
- Install the offline package. Microsoft's download page offers separate 32-bit, 64-bit and ARM packages for Microsoft Defender Antivirus for Windows 11, Windows 10, Windows 8.1, and Windows Server. The files are named mpam-fe.exe or mpam-feX64.exe, and you just run them. Each package installs only the build listed on the download page.
- Network Inspection System updates are listed separately on the same page, according to Notebookcheck. Check your Antimalware Client version before you download those.
- Check for a third-party antivirus. Microsoft says Defender switches itself off, or into passive mode, when another antivirus product is installed and kept up to date. Microsoft still recommends keeping definitions updated in passive mode.
The bottom line
1.459.576.0 is one of the several definition builds Microsoft ships each day, and Microsoft's change log confirms it. It adds two new severe detections and updates more than a hundred others, led by ransomware and loader families. Most home users don't need to do anything because Windows Update handles it. Admins should take away three points:
- Confirm versions with
Get-MpComputerStatus, not Windows Update history. - Use
-SignatureUpdate -MMPCto rule out WSUS when updates stall. - Treat
-RemoveDefinitions -Allas a recovery step, not a routine one.
Seeing KB2267602 offered again tomorrow doesn't mean the update failed. That's how Microsoft ships definitions.
References
- Microsoft pushes new Defender update - Notebookcheck Notebookcheck · 2026-10-06T17:04:00+00:00
- How does the Security intelligence updates for Microsoft Defender Antivirus and other Microsoft Antimalware - KB2267602 work? - My OPSWAT Central Management opswat.com
- Manually Update Microsoft Defender Antivirus Signature Version in Windows 11 elevenforum.com