Microsoft patches RoguePlanet Defender zero-day vulnerability
Microsoft has released a security patch to address a Defender zero-day vulnerability known as 'RoguePlanet,' disclosed after the June 2026 Patch Tuesday. The flaw affects fully patched Windows 10 and Windows 11 devices, allowing attackers to spawn a command prompt with SY…
Intelligence analysis by Llama

Microsoft has released a security patch to address a Defender zero-day vulnerability known as 'RoguePlanet.' The flaw affects fully patched Windows 10 and Windows 11 devices, allowing attackers to spawn a command prompt with SYSTEM privileges via a Microsoft Defender race condition. The vulnerability was disclosed by a security researcher using the 'Nightmare Eclipse' handle, who also…
Imagine you have a special kind of security software on your computer called Microsoft Defender. It's like a superhero that protects your computer from bad guys. But, there's a problem. A bad guy found a way to trick the superhero into giving them special powers. This is called a zero-day vulnerability. Microsoft has released a patch to fix this problem, so you should update your computer to stay safe.
Analysis
A Critical Vulnerability in Microsoft Defender
Microsoft has released a security patch to address a Defender zero-day vulnerability known as 'RoguePlanet,' disclosed after the June 2026 Patch Tuesday. The flaw affects fully patched Windows 10 and Windows 11 devices, allowing attackers to spawn a command prompt with SYSTEM privileges via a Microsoft Defender race condition.
The vulnerability was disclosed by a security researcher using the 'Nightmare Eclipse' handle, who also shared a proof-of-concept exploit in a self-hosted Git repository. According to Nightmare Eclipse, RoguePlanet affects fully patched Windows 10 and Windows 11 devices, allowing attackers to spawn a command prompt with SYSTEM privileges via a Microsoft Defender race condition.
"The exploit is a race condition, so it's a hit or miss. I have managed to get a 100% success rate on some machines while it struggled to work on others," they explained. "The PoC for RoguePlanet works regardless if real time protection is on or not," the researcher added in a follow-up update.
Microsoft confirmed it was working on a patch for CVE-2026-50656 on June 16, but has yet to acknowledge that Nightmare Eclipse discovered the vulnerability. Patched via Malware Protection Engine update On Wednesday, the company addressed the RoguePlanet vulnerability by releasing Microsoft Malware Protection Engine 1.1.26060.3008, an update to the core scanning engine that powers its security solutions and services.
"Microsoft has released an update to the Microsoft Malware Protection Engine that addresses the vulnerability identified by CVE-2026-50656. Please see the FAQ for more information on how to check if the new version has been installed," Microsoft noted.
Over the past several months, Nightmare Eclipse has disclosed multiple other Windows zero-day exploits, including for the BlueHammer, RedSun, GreenPlasma, MiniPlasma, YellowKey, and UnDefend flaws. While some of these security vulnerabilities affect Microsoft Defender, others target BitLocker and Windows components. Microsoft fixed the GreenPlasma, MiniPlasma, and YellowKey flaws one month ago as part of the June 2026 Patch Tuesday updates.
Microsoft has also reacted to Nightmare Eclipse's disclosures by issuing warnings of legal action against people engaging in what it described as 'malicious activity causing real harm to our customers,' leading cybersecurity experts to believe that Microsoft was directly threatening the security researcher.
Test every layer before attackers do Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen. The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection. Get the whitepaper
Key points
- Microsoft has released a security patch to address a Defender zero-day vulnerability known as 'RoguePlanet.'
- The flaw affects fully patched Windows 10 and Windows 11 devices, allowing attackers to spawn a command prompt with SYSTEM privileges via a Microsoft Defender race condition.
- The vulnerability was disclosed by a security researcher using the 'Nightmare Eclipse' handle, who also shared a proof-of-concept exploit in a self-hosted Git repository.
- Microsoft confirmed it was working on a patch for CVE-2026-50656 on June 16, but has yet to acknowledge that Nightmare Eclipse discovered the vulnerability.
- Over the past several months, Nightmare Eclipse has disclosed multiple other Windows zero-day exploits, including for the BlueHammer, RedSun, GreenPlasma, MiniPlasma, YellowKey, and UnDefend flaws.
If this development plays out positively, Microsoft's patch for the RoguePlanet vulnerability could help prevent future attacks on fully patched Windows 10 and Windows 11 devices. This could lead to improved security for users and reduce the risk of system compromise.
However, the fact that Nightmare Eclipse was able to disclose multiple Windows zero-day exploits, including RoguePlanet, raises concerns about the effectiveness of Microsoft's bug bounty and vulnerability disclosure practices. This could lead to a lack of trust in Microsoft's ability to handle security vulnerabilities and potentially put users at risk.



