Microsoft Confirms RoguePlanet, a Defender 0-Day Dropped by a Feuding Researcher
A week after the exploit went public, Microsoft confirmed RoguePlanet (CVE-2026-50656), a Defender race-condition 0-day that escalates to SYSTEM, and promised a fix.
A week after an exploit for a flaw called RoguePlanet went public, Microsoft has confirmed the bug, assigned it a CVE, and said a fix is on the way. The vulnerability, tracked as CVE-2026-50656, affects Microsoft Defender and can hand an attacker full control of a Windows machine.
What RoguePlanet does
The flaw was disclosed shortly after June's patches by a researcher who goes by Nightmare Eclipse (also known as Chaotic Eclipse), along with a proof-of-concept exploit. According to the researcher, it works even on fully updated Windows 10 and Windows 11 and allows privilege escalation to SYSTEM, the highest level on the operating system.
At its core is a race condition in Microsoft Defender. A successful exploit lets an attacker open a command prompt with SYSTEM privileges and run arbitrary code. The researcher cautioned that reliability depends on the machine: on some it fires almost every time, while on others it takes several attempts.
Microsoft acknowledges the bug, but not the finder
After the disclosure, Microsoft first said it was investigating and checking whether the flaw could be exploited in practice. It has now officially recognized the problem and issued a security advisory, though it did not name Nightmare Eclipse as the person who found it. The company said it is aware of an elevation-of-privilege issue in the Microsoft Malware Protection Engine, publicly known as RoguePlanet, and that it is working on a security update to fix it.
A researcher at war with Microsoft
RoguePlanet is the latest round in a long-running feud between the researcher and Microsoft. Back in the spring, Nightmare Eclipse promised to release a fresh 0-day after every Patch Tuesday, and has been keeping that promise ever since.
In recent months the researcher has published exploits for several Windows zero-days, including BlueHammer (CVE-2026-33825), RedSun (CVE-2026-41091), UnDefend (CVE-2026-45498), YellowKey (CVE-2026-45585), GreenPlasma (CVE-2026-45586), MiniPlasma (CVE-2020-17103) and GreatXML. Some hit Defender, while others targeted BitLocker and various Windows components.
Threats, takedowns, and a protest
Nightmare Eclipse says the disclosures are a protest against how the Microsoft Security Response Center (MSRC) treats security researchers. By his account, Microsoft threatened him and promised to "ruin his life," ignored his vulnerability reports, revoked his MSRC account access, and had his exploit repositories pulled from GitHub and GitLab. He now publishes on his own infrastructure.
Microsoft, for its part, has criticized the practice of releasing exploits for unpatched flaws and warned of possible legal consequences for anyone whose actions harm users, comments that many in the security community read as a veiled threat. The company later said it does not intend to go after security researchers.
Some flaws already fixed
Not every bug from the researcher is still open. In June's Patch Tuesday, Microsoft engineers fixed GreenPlasma, MiniPlasma and YellowKey. RoguePlanet now joins the queue for a patch of its own.
Based on public reporting and statements from Microsoft and the researcher.
Written by
Read next
LegacyHive: Unpatched Windows Zero-Day PoC Dropped Hours After Patch Tuesday
Within hours of July's Patch Tuesday, a researcher going by Nightmare Eclipse (also seen as Chaotic Eclipse) published a proof-of-concept exploit for a new Windows vulnerability dubbed LegacyHive. No patch existed at the time of release, and the exploit works on the latest build of the system, assembled with July's updates already applied. The vulnerability lives in the Windows User Profile Service (ProfSvc) and its registry hive loading mechanism. When a user signs in, Windows mounts the UsrCl
$643M in Six Months: How Lazarus Operates and Where the Evidence Runs Out
In the first half of 2026, analysts at TRM Labs attributed roughly $643 million to groups linked to North Korea, about 66% of everything stolen from the cryptocurrency industry, out of some $972 million lost across 207 incidents. Almost all of it came from two April attacks on DeFi protocols: the roughly $292 million breach of KelpDAO and the $285 million hit on Drift Protocol. A year earlier the shape was similar but the scale was not. Chainalysis put 2024 losses to DPRK-linked hackers at $1.34
Microsoft Patches a Record 570 Flaws, Two Zero-Days Already Under Attack
On Tuesday, July 14, Microsoft shipped the largest set of fixes in Patch Tuesday history, closing 570 vulnerabilities at once. Attackers are already exploiting two of them in the wild, and a third was publicly disclosed before the patch landed. The most serious of the exploited bugs is CVE-2026-56164 in Microsoft SharePoint Server. A missing authentication check in a critical function lets an unauthenticated attacker escalate privileges across the network, with no password at all. Researchers a
LegacyHive: Unpatched Windows Zero-Day PoC Dropped Hours After Patch Tuesday
Within hours of July's Patch Tuesday, a researcher going by Nightmare Eclipse (also seen as Chaotic Eclipse) published a proof-of-concept exploit for a new Windows vulnerability dubbed LegacyHive. No patch existed at the time of release, and the exploit works on the latest build of the system, assembled with July's updates already applied. The vulnerability lives in the Windows User Profile Service (ProfSvc) and its registry hive loading mechanism. When a user signs in, Windows mounts the UsrCl