ShieldBreak CVE-2026-50656 Cortex XDR
unsigned process loading both MpClient.dll and cldapi.dll in the same process instance. this is the core behavioral invariant of CVE-2026-50656 exploitation - MpClient is needed to trigger scan/remediation via RPC, cldapi provides the cloud filter callback that swaps file content mid-scan. neither DLL can be removed without breaking the exploit. with Cortex XDR as primary AV, Defender runs in passive mode and the exploit fails at scan stage, but the DLL load pattern still gets recorded by the agent. this rule detects the attempt, not the successful exploitation.
Cortex XDR

