Microsoft has released a fix for a Windows Defender zero-day called RoguePlanet that could let attackers gain full SYSTEM-level control on Windows 10 and Windows 11 devices. The flaw is tracked as CVE-2026-50656 and was publicly disclosed with proof-of-concept code by the researcher using the handle Nightmare Eclipse after June 2026 Patch Tuesday. Microsoft says the issue is fixed in Microsoft Malware Protection Engine version 1.1.26060.3008, the scanning engine used by Defender and related security products.
2026.09.09
64% relevant
The article says ShieldCrash is the latest link in the same underlying exploit lineage, specifically a bypass of ShieldBreak, which itself bypassed Microsoft's earlier RoguePlanet fix in Defender.
Ionut Arghire
2026.08.13
86% relevant
This article adds that Nightmare Eclipse has now released a fresh exploit called ShieldBreak that targets Microsoft Defender and is presented as a bypass for the July fix for CVE-2026-50656, along with technical exploitation details and public disagreement from Will Dormann and Kevin Beaumont over whether it is truly a RoguePlanet bypass.
Arctic Wolf Labs
2026.08.12
98% relevant
This is a direct update to the same underlying event: CVE-2026-50656/RoguePlanet in Microsoft Defender. The new information is that the original July 2026 patch (engine v1.1.26060.3008) has been bypassed by a newly released exploit chain called ShieldBreak from the same researcher, leaving fully patched Defender systems still exposed with no official fix yet.
Sergiu Gatlan
2026.08.12
92% relevant
This is a direct follow-up to the RoguePlanet event: the researcher says the July patch for CVE-2026-50656 was incomplete and has now published ShieldBreak, a working patch bypass that again grants SYSTEM privileges via Microsoft Defender on fully patched Windows 10, Windows 11, and Windows Server systems.
2026.07.09
97% relevant
This article is a direct update on the same RoguePlanet event, adding that Microsoft has now fixed CVE-2026-50656 via a Microsoft Malware Protection Engine update rather than Patch Tuesday and advising customers to run the latest engine version.
Eduard Kovacs
2026.07.09
97% relevant
This article directly updates the same event by reporting that Microsoft has now rolled out the fix for RoguePlanet via a Microsoft Malware Protection Engine update, after the zero-day exploit was published and after Microsoft's earlier advisory.
info@thehackernews.com (The Hacker News)
2026.07.09
99% relevant
This article covers the same underlying event: Microsoft releasing a fix for the RoguePlanet Windows Defender zero-day, tracked as CVE-2026-50656, which can be exploited to gain SYSTEM privileges on Windows 10 and 11.
Sergiu Gatlan
2026.07.09
100% relevant
The article establishes a distinct new event: Microsoft has now shipped the patch for RoguePlanet, a specific Windows Defender zero-day tracked as CVE-2026-50656, rather than only discussing public disclosure of other Nightmare Eclipse flaws.