Microsoft Acknowledges 'RoguePlanet' Defender Zero-Day, Patch Still in the Works
CVE-2026-50656 is a privilege escalation bug in the Malware Protection Engine — the component sitting at the heart of every Defender install.

Microsoft has confirmed an unpatched elevation-of-privilege flaw in the Microsoft Malware Protection Engine, the scanning core that ships with every supported version of Defender.
The bug is tracked as CVE-2026-50656 and carries a CVSS score of 7.8. Microsoft has internally codenamed it RoguePlanet.
No patch yet. The company says one is in development and will roll out through the Malware Protection Engine's automatic update channel rather than the monthly cumulative cycle.
That detail matters. The Malware Protection Engine updates itself silently in most environments, which is why Microsoft historically resolves engine flaws without a Patch Tuesday entry. Enterprise admins who block or delay engine updates will need to revisit those policies.
What the flaw does
Microsoft describes RoguePlanet as a local elevation of privilege. A 7.8 CVSS rating with that vector typically means a low-privileged attacker already on the box can escalate to SYSTEM by abusing a component Defender itself runs with high privileges. Microsoft has not published exploitation details, attribution, or a list of affected engine versions in its public note so far.
The company has not said whether the flaw is being exploited in the wild, and there is no public proof-of-concept at the time of writing. Treat "zero-day" here as meaning "disclosed before a fix shipped" rather than confirmed active abuse.
Defender variants that share the engine — Defender for Endpoint, Defender Antivirus on Windows 10, 11, and Server, and Defender for Business — are all in scope until Microsoft narrows that down.
What defenders should do
Two immediate steps:
- Confirm that Malware Protection Engine auto-updates are enabled. The fixed engine build will arrive that way, not through WSUS in the usual sense.
- Audit any GPO or MDM policy that pins or delays engine versions. Those will block the fix.
Longer term, watch the MSRC advisory for the engine version number that contains the patch, and verify rollout across the estate using Get-MpComputerStatus — the AMEngineVersion field is the one that matters.
There is no regulator action tied to this one yet, and there shouldn't need to be: an engine-level fix that ships automatically is the cleanest case Microsoft's update plumbing handles. The risk window is whatever time passes between disclosure and the engine bump landing on your fleet.
Threat Vectr will update this story when Microsoft publishes the fixed engine build number.



