Microsoft Rushes Patch for RoguePlanet Defender Zero-Day Exploit

Microsoft releases a security update to patch a zero-day vulnerability in Microsoft Defender known as "RoguePlanet." The flaw, tracked as CVE-2026-50656, allows attackers to exploit a race condition in the antivirus software to gain SYSTEM-level privileges on fully patched Windows 10 and Windows 11 devices. The company addresses the issue through an update to the Microsoft Malware Protection Engine, version 1.1.26060.3008.

A security researcher using the handle "Nightmare Eclipse" discloses the vulnerability publicly after an ongoing dispute with Microsoft over the company's bug bounty and vulnerability disclosure practices. The researcher shares a proof-of-concept exploit in a self-hosted Git repository, claiming that Microsoft previously removes similar repositories hosted on GitHub and GitLab. According to Nightmare Eclipse, the exploit achieves up to a 100% success rate on some machines and works regardless of whether real-time protection is enabled.

This disclosure adds to a series of zero-day exploits that Nightmare Eclipse reveals in recent months, including flaws dubbed BlueHammer, RedSun, GreenPlasma, and others targeting Microsoft Defender, BitLocker, and Windows components. Microsoft fixes several of these vulnerabilities during the June 2026 Patch Tuesday but has yet to acknowledge Nightmare Eclipse as the discoverer of RoguePlanet. The company also issues warnings of potential legal action against individuals engaging in what it describes as malicious activity causing harm to customers.

Read More at the original source →