discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.

Microsoft patches RoguePlanet Defender zero-day vulnerability

Microsoft has released a security patch to address a Defender zero-day vulnerability known as 'RoguePlanet,' disclosed after the June 2026 Patch Tuesday. The flaw affects fully patched Windows 10 and Windows 11 devices, allowing attackers to spawn a command prompt with SY…

By Sergiu Gatlan·Jul 9·bleepingcomputer.com·3 min read

Intelligence analysis by Llama

Microsoft patches RoguePlanet Defender zero-day vulnerability
Image: bleepingcomputer.com

Microsoft has released a security patch to address a Defender zero-day vulnerability known as 'RoguePlanet.' The flaw affects fully patched Windows 10 and Windows 11 devices, allowing attackers to spawn a command prompt with SYSTEM privileges via a Microsoft Defender race condition. The vulnerability was disclosed by a security researcher using the 'Nightmare Eclipse' handle, who also…

Why it matters

This story matters to someone following Security because it highlights a critical vulnerability in Microsoft Defender that could be exploited by attackers to gain SYSTEM privileges on fully patched Windows 10 and Windows 11 devices.

Imagine you have a special kind of security software on your computer called Microsoft Defender. It's like a superhero that protects your computer from bad guys. But, there's a problem. A bad guy found a way to trick the superhero into giving them special powers. This is called a zero-day vulnerability. Microsoft has released a patch to fix this problem, so you should update your computer to stay safe.

Analysis

A Critical Vulnerability in Microsoft Defender

Microsoft has released a security patch to address a Defender zero-day vulnerability known as 'RoguePlanet,' disclosed after the June 2026 Patch Tuesday. The flaw affects fully patched Windows 10 and Windows 11 devices, allowing attackers to spawn a command prompt with SYSTEM privileges via a Microsoft Defender race condition.

The vulnerability was disclosed by a security researcher using the 'Nightmare Eclipse' handle, who also shared a proof-of-concept exploit in a self-hosted Git repository. According to Nightmare Eclipse, RoguePlanet affects fully patched Windows 10 and Windows 11 devices, allowing attackers to spawn a command prompt with SYSTEM privileges via a Microsoft Defender race condition.

"The exploit is a race condition, so it's a hit or miss. I have managed to get a 100% success rate on some machines while it struggled to work on others," they explained. "The PoC for RoguePlanet works regardless if real time protection is on or not," the researcher added in a follow-up update.

Microsoft confirmed it was working on a patch for CVE-2026-50656 on June 16, but has yet to acknowledge that Nightmare Eclipse discovered the vulnerability. Patched via Malware Protection Engine update On Wednesday, the company addressed the RoguePlanet vulnerability by releasing Microsoft Malware Protection Engine 1.1.26060.3008, an update to the core scanning engine that powers its security solutions and services.

"Microsoft has released an update to the Microsoft Malware Protection Engine that addresses the vulnerability identified by CVE-2026-50656. Please see the FAQ for more information on how to check if the new version has been installed," Microsoft noted.

Over the past several months, Nightmare Eclipse has disclosed multiple other Windows zero-day exploits, including for the BlueHammer, RedSun, GreenPlasma, MiniPlasma, YellowKey, and UnDefend flaws. While some of these security vulnerabilities affect Microsoft Defender, others target BitLocker and Windows components. Microsoft fixed the GreenPlasma, MiniPlasma, and YellowKey flaws one month ago as part of the June 2026 Patch Tuesday updates.

Microsoft has also reacted to Nightmare Eclipse's disclosures by issuing warnings of legal action against people engaging in what it described as 'malicious activity causing real harm to our customers,' leading cybersecurity experts to believe that Microsoft was directly threatening the security researcher.

Test every layer before attackers do Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen. The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection. Get the whitepaper

Key points

  • Microsoft has released a security patch to address a Defender zero-day vulnerability known as 'RoguePlanet.'
  • The flaw affects fully patched Windows 10 and Windows 11 devices, allowing attackers to spawn a command prompt with SYSTEM privileges via a Microsoft Defender race condition.
  • The vulnerability was disclosed by a security researcher using the 'Nightmare Eclipse' handle, who also shared a proof-of-concept exploit in a self-hosted Git repository.
  • Microsoft confirmed it was working on a patch for CVE-2026-50656 on June 16, but has yet to acknowledge that Nightmare Eclipse discovered the vulnerability.
  • Over the past several months, Nightmare Eclipse has disclosed multiple other Windows zero-day exploits, including for the BlueHammer, RedSun, GreenPlasma, MiniPlasma, YellowKey, and UnDefend flaws.
The Upside

If this development plays out positively, Microsoft's patch for the RoguePlanet vulnerability could help prevent future attacks on fully patched Windows 10 and Windows 11 devices. This could lead to improved security for users and reduce the risk of system compromise.

The Downside

However, the fact that Nightmare Eclipse was able to disclose multiple Windows zero-day exploits, including RoguePlanet, raises concerns about the effectiveness of Microsoft's bug bounty and vulnerability disclosure practices. This could lead to a lack of trust in Microsoft's ability to handle security vulnerabilities and potentially put users at risk.

Originally reported at

bleepingcomputer.com

Discernion covers the story. Read the full piece at the source.

Tagsmicrosoftsecurityvulnerabilityzero-dayrogueplanetdefenderwindowspatchexploit

Author

Sergiu Gatlan

Intelligence analysis by

Llama

Published

Jul 9, 2026

Source

bleepingcomputer.com

Share

Topics

microsoftsecurityvulnerabilityzero-dayrogueplanetdefenderwindowspatchexploit

Related

More from this desk

Aug 24·bleepingcomputer.com

ReliaQuest confirms failed data-theft attack after ShinyHunters breach

ReliaQuest confirms a failed data-theft attack after hackers impersonated a member of the security team. An attacker called multiple employees and tried to trick them into accessing a fake ReliaQuest single sign-on (SSO) page.

Aug 24·bleepingcomputer.com

Microsoft Teams now lets admins block external bots from meetings

Microsoft is rolling out a Teams meeting protection policy that lets administrators automatically block identified external bots from joining meetings, without requiring organizer approval.

Aug 24·bleepingcomputer.com

Microsoft: August updates break printing, PDF export in WPF apps

Microsoft has confirmed that .NET Framework updates released as part of the August 2026 Patch Tuesday are breaking printing and PDF export in some applications. The issue affects only apps that use the Windows Presentation Foundation (WPF) UI framework.

Aug 24·thehackernews.com

WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords

Cybersecurity researchers have flagged two new malware families called WordlistLoader and SynkLoader that's used to deliver next-stage payloads and likely sell access to ransomware groups.