VYPR
patchPublished Jul 9, 2026· Updated Jul 10, 2026· 11 sources

Microsoft Patches RoguePlanet Zero-Day in Defender Amid Researcher Dispute

Microsoft has released a patch for a zero-day vulnerability in Microsoft Defender, dubbed RoguePlanet, which was publicly disclosed by a researcher in dispute with the company.

Microsoft has issued a security update to address a critical zero-day vulnerability affecting Microsoft Defender, identified as CVE-2026-50656 and publicly known as "RoguePlanet." The vulnerability was disclosed following the June 2026 Patch Tuesday, adding to a series of recent disclosures by security researchers targeting Microsoft products.

The flaw was brought to light by a security researcher operating under the pseudonym "Nightmare Eclipse." This disclosure occurred amidst an ongoing public dispute between the researcher and Microsoft concerning the company's bug bounty program and vulnerability disclosure policies. The researcher also provided a proof-of-concept exploit, initially hosted on self-managed Git repositories after alleged takedowns from platforms like GitHub and GitLab.

According to Nightmare Eclipse, the RoguePlanet vulnerability impacts fully patched installations of Windows 10 and Windows 11. It exploits a race condition within Microsoft Defender, allowing an attacker to achieve elevated privileges and spawn a command prompt with SYSTEM-level access. The researcher noted that the exploit's success rate can vary, with some systems requiring multiple attempts, but importantly, it functions irrespective of whether real-time protection is enabled.

Microsoft acknowledged the existence of CVE-2026-50656 and stated it was working on a patch on June 16th. However, the company has not publicly attributed the discovery of this specific vulnerability to Nightmare Eclipse. The release of the patch indicates Microsoft's commitment to addressing such critical flaws, even when disclosures are contentious.

The fix for RoguePlanet was delivered through an update to the Microsoft Malware Protection Engine, specifically version 1.1.26060.3008. This core engine is fundamental to the operation of Microsoft's security solutions and services. Microsoft advised users to ensure their systems receive the latest platform updates via Windows Update to incorporate this critical security enhancement.

This incident is part of a broader pattern of disclosures by Nightmare Eclipse, who has previously revealed multiple other zero-day exploits affecting Windows and Microsoft Defender. These include vulnerabilities such as BlueHammer, RedSun, GreenPlasma, MiniPlasma, YellowKey, and UnDefend. Microsoft has since patched several of these, including GreenPlasma, MiniPlasma, and YellowKey, in its June 2026 Patch Tuesday updates.

Microsoft's response to Nightmare Eclipse's disclosures has also included stern warnings regarding "malicious activity causing real harm to our customers." This stance has led to speculation among cybersecurity experts that the company may be indirectly threatening the researcher, highlighting the complex and often fraught relationship between security researchers and large software vendors.

The patching of RoguePlanet underscores the persistent threat landscape surrounding endpoint security software. Microsoft Defender, a widely deployed security solution, remains a prime target for attackers seeking to gain initial access or escalate privileges on victim systems. The ongoing disclosures and subsequent patches emphasize the need for continuous vigilance and rapid deployment of security updates.

The newly released patches for CVE-2026-50656, dubbed "RoguePlanet," address an elevation-of-privilege vulnerability in the Microsoft Defender Malware Protection Engine. This update, version 1.1.26060.3008, is being rolled out automatically to most users, mitigating the risk of exploitation which Microsoft deems "more likely" despite no current in-the-wild activity. The vulnerability affects engine versions prior to the update and could allow low-privilege attackers to execute code with system-level permissions.

Microsoft has updated its advisory for CVE-2026-50656, confirming that patches for the RoguePlanet vulnerability in the Malware Protection Engine are now available. While the initial exploit was disclosed in June, the company's July 8 update indicates that customers will receive the fix automatically through standard engine updates, with no further action required on their part. The update also includes unspecified 'defense-in-depth' security enhancements.

Microsoft has now released security updates for CVE-2026-50656, the privilege escalation vulnerability in its Malware Protection Engine, nearly a month after details of the flaw were made public. The vulnerability, tracked as RoguePlanet, has been remediated in Microsoft Malware Protection Engine version 1.1.26060.3008, with Microsoft stating no customer action is required as the software updates automatically. This marks the fourth Defender vulnerability disclosed by the researcher Chaotic Eclipse, following BlueHammer, UnDefend, and RedSun, all of which have also been patched.

Microsoft has released an update for its Defender Antivirus software, specifically Malware Protection Engine version 1.1.26060.3008, to address the RoguePlanet zero-day vulnerability (CVE-2026-50656). This update resolves the elevation of privilege flaw that allowed attackers to gain SYSTEM-level control on Windows machines. Users whose systems have Microsoft Defender turned off due to another antivirus solution are not affected by this specific vulnerability.

Microsoft has released a security update for the Microsoft Malware Protection Engine, addressing CVE-2026-50656, a local privilege escalation vulnerability. This update, version 1.1.26060.3008, comes a month after the flaw was publicly disclosed by researcher Nightmare Eclipse and is considered by Microsoft to be likely to be exploited, though not yet actively. Users with automatic updates enabled should receive the fix automatically, while others are advised to update manually.

Microsoft has now officially patched CVE-2026-50656, the zero-day vulnerability dubbed RoguePlanet, which allowed for SYSTEM privilege escalation within Microsoft Defender. The fix was delivered via an update to the Malware Protection Engine, separate from the typical Patch Tuesday releases, and ensures protection against this specific privilege escalation technique.

Microsoft has issued an out-of-band patch for the RoguePlanet vulnerability (CVE-2026-50656) in Windows Defender, addressing a high-severity elevation-of-privilege flaw. While the advisory states the vulnerability has not been exploited in the wild and CISA has not added it to its KEV catalog, some threat intelligence reports suggest exploitation may have occurred. The patch is included in the Microsoft Malware Protection Engine version 1.1.26060.3008.

The article highlights that Microsoft did not release any out-of-band (OOB) updates in June, despite the high volume of patches. It also mentions that the researcher Nightmare-Eclipse has identified a new zero-day vulnerability in Microsoft Defender, referred to as RoguePlanet and tracked as CVE-2026-50656, which is a race condition privilege escalation flaw.

A security researcher known as Chaotic Eclipse has raised concerns that Microsoft's recent patch for the RoguePlanet zero-day (CVE-2026-50656) in Windows Defender may introduce new vulnerabilities. These alleged flaws include an information disclosure of eight bytes in specific file-handling scenarios and a denial-of-service condition that can exhaust local disk space by abusing Zone.Identifier alternate data streams, though exploitation requires access to a controlled SMB share.

Independent security researcher NightmareEclipse has levied new criticism against Microsoft's patch for CVE-2026-50656, also known as RoguePlanet. The researcher claims the implemented mitigations can lead to disk space exhaustion, application crashes, and memory leaks, potentially exacerbating the issues caused by the vulnerability rather than resolving them. This adds another layer to the ongoing dispute between the researcher and Microsoft regarding vulnerability disclosure practices.

Synthesized by Vypr AI