Researcher publishes 'ShieldBreak' code that claims to defeat a recent Microsoft Defender fix
A proof-of-concept from a researcher known as Chaotic Eclipse says the patch for CVE-2026-50656 can still be bypassed to gain full control of Windows machines.

Key points
- A researcher using the handle Chaotic Eclipse has published proof-of-concept code called ShieldBreak that claims to bypass Microsoft's fix for a Defender flaw.
- The underlying bug, CVE-2026-50656 (nicknamed RoguePlanet), carries a severity score of 7.8 out of 10.
- The flaw sits inside Microsoft Defender, the antivirus software built into every modern Windows PC.
- A successful bypass would give an attacker SYSTEM-level access, the highest privilege on a Windows machine.
- Microsoft hasn't confirmed whether ShieldBreak works against fully updated systems.
A security researcher who goes by Chaotic Eclipse has released working code that, they say, defeats Microsoft's recent patch for a serious flaw inside Windows Defender.
Chaotic Eclipse is also known online as INFINITE NIGHTMARE and Nightmare-Eclipse. The new technique is called ShieldBreak, and it targets Microsoft Defender, the antivirus program that ships with Windows and runs on hundreds of millions of PCs by default.
The original bug is CVE-2026-50656, nicknamed RoguePlanet, with a severity score of 7.8 out of 10. We've tracked this vulnerability across four stories since 17 June, including August's Patch Tuesday roundup. Microsoft patched it, but Chaotic Eclipse says the fix doesn't fully close the hole.
What does the flaw actually let attackers do?
It lets an attacker who already has a foothold on a Windows PC promote themselves to SYSTEM, the highest access level on the machine. From there they can install software, read any file, and disable security tools.
Think of it as a burglar who has climbed through a window finding a master key on the kitchen counter. Already inside, they now own the building.
This is what security people call a local privilege escalation bug. It can't, on its own, break into a computer over the internet. An attacker needs some way in first, usually a phishing email (criminals send fake messages to trick staff into running a file) or a stolen password.
Why does a 'patch bypass' matter?
Because it means the official fix doesn't actually fix the problem. When Microsoft ships a security update, IT teams install it and move on. A bypass tells them the danger isn't over.
According to The Hacker News, Chaotic Eclipse published proof-of-concept code alongside the disclosure. A working demonstration exploit lowers the bar for other attackers to copy the technique.
Microsoft hasn't publicly confirmed the bypass or issued a new advisory. Until it does, defenders are working from the researcher's claims alone.
The facts so far
| Item | Detail |
|---|---|
| Vulnerability ID | CVE-2026-50656 |
| Nickname | RoguePlanet |
| Severity score | 7.8 out of 10 |
| Affected product | Microsoft Defender on Windows |
| Bypass name | ShieldBreak |
| Researcher handle | Chaotic Eclipse |
| Impact if exploited | SYSTEM-level access on the PC |
Should ordinary Windows users worry?
Not immediately, but keep updating. This flaw isn't something a stranger can fire at your laptop over the internet. It matters most inside businesses, where an attacker who phishes one employee could use it to spread across the network.
Home users should keep Windows Update turned on and treat unexpected email attachments with suspicion. Businesses running Defender as their main antivirus should watch Microsoft's security update guide closely for a revised patch or workaround.
IT teams may also want to review logs for unusual Defender behaviour and restrict which staff hold local administrator rights. That single step blunts most privilege escalation attacks, patched or not. Separately, our August Patch Tuesday coverage noted that Microsoft shipped fixes for roughly 400 flaws that month, a pace that makes thorough patch verification harder for defenders.
Threat Vectr has contacted Microsoft for comment and will update this story when the company responds.



