Microsoft patches 'RoguePlanet' Defender flaw after researcher publishes exploit in disclosure spat

The zero-day let attackers hand themselves the keys to a fully patched Windows machine. It was revealed by a researcher publicly feuding with Microsoft.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 3 min read
Illustration: a modern laptop screen glowing blue in a dim office
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • Microsoft patched a Defender zero-day, tracked as CVE-2026-50656 and nicknamed RoguePlanet, on Wednesday via a Malware Protection Engine update.
  • A researcher going by "Nightmare Eclipse" published a working exploit before the fix, saying Microsoft had removed their earlier exploit repositories from GitHub and GitLab.
  • The bug worked on fully patched Windows 10 and Windows 11 machines even with real-time protection turned on.
  • The fix ships in Microsoft Malware Protection Engine version 1.1.26060.3008, which updates automatically on most machines.
  • Microsoft has hinted at legal action against researchers publishing exploits, which security experts read as a warning shot at Nightmare Eclipse.

Microsoft has shipped an emergency fix for a flaw in Microsoft Defender, its built-in Windows antivirus. The bug let an ordinary program on a Windows PC promote itself to the highest level of access on the machine, called SYSTEM. From there, an attacker can install software, read any file, or turn off security tools.

The flaw is officially CVE-2026-50656. Its unofficial name is RoguePlanet. We've been tracking it since our first report on 17 June, when Microsoft confirmed the bug existed but had no fix ready.

It hit fully patched Windows 10 and Windows 11 machines. That's the part that stings.

How did the attack actually work?

RoguePlanet is a race condition: the exploit wins by acting in a tiny sliver of time between two steps Defender takes. Get the timing right and Defender itself hands you a command prompt running as SYSTEM. Miss and nothing happens, so you try again.

Nightmare Eclipse said reliability varies by machine. On some PCs the exploit worked every single time; on others it sputtered. It worked whether or not Defender's real-time protection was switched on, which closes off the usual "just leave the antivirus running" advice.

Why was the exploit public before the patch?

Because the researcher and Microsoft are, to put it politely, not getting along.

Nightmare Eclipse posted the working exploit on a self-hosted Git repository they run themselves, after Microsoft had already leaned on GitHub and GitLab to remove earlier proof-of-concept code. This is the latest round in a dispute over how Microsoft handles bug bounties and vulnerability disclosure. Our 10 June story covered the moment Nightmare Eclipse dropped the original proof-of-concept, the day after June Patch Tuesday.

Over the past several months the same researcher has published a cluster of Windows zero-days: BlueHammer, RedSun, GreenPlasma, MiniPlasma, YellowKey, UnDefend. Some target Defender; others go after BitLocker, the disk-encryption feature, along with various Windows internals. Microsoft quietly fixed GreenPlasma, MiniPlasma and YellowKey in its June 2026 Patch Tuesday, the monthly bundle of security updates Microsoft ships on the second Tuesday of each month.

Microsoft has responded with public statements warning of legal action against people engaged in "malicious activity causing real harm to our customers," as first reported by BleepingComputer. Security professionals read that as a direct shot at Nightmare Eclipse. Microsoft still hasn't credited the researcher for finding RoguePlanet.

What should ordinary Windows users do?

Check that Defender has updated itself. That's really it.

The fix is inside Microsoft Malware Protection Engine version 1.1.26060.3008, the core scanner behind Defender. It updates in the background on most home and work machines, usually within a day or two. To force it: open Windows Security, click Virus & threat protection, then Check for updates.

For most people at home, that's enough. Larger organisations should confirm the new engine version has rolled out across every endpoint, especially on servers where automatic updates are sometimes throttled.

One uncomfortable footnote. A working exploit sat on the public internet before the patch shipped, so anyone paying attention had a window to grab it. I haven't seen credible reports of RoguePlanet being used against real victims. But the code is out there now, and it'll stay out there.

Patch, then move on.

© 2026 Threat Vectr