Nightmare-Eclipse Drops Another Windows Defender Zero-Day, RoguePlanet
Want more insights like this?
A researcher known as Nightmare-Eclipse has released yet another Microsoft zero-day exploit — this one called RoguePlanet — timed to drop right after Microsoft's June Patch Tuesday, which addressed a record 206 CVEs.
The new exploit abuses a race condition in Windows Defender's signature update workflow and, when it lands, spawns a shell with full SYSTEM privileges on Windows 10 and 11. It's unreliable by the researcher's own account — hit or miss — and doesn't work on Windows Server, though he claims a redesigned version would.
It's the latest salvo in a months-long feud that began in April with BlueHammer (CVE-2026-33825). Microsoft patched that one within the month and attackers exploited it anyway; there's no sign yet of RoguePlanet being used in the wild.
The researcher claims to have more vulnerabilities in Defender and other Windows components ready to go.
Updated 12 Aug 2026: RoguePlanet was assigned CVE-2026-50656 and patched by Microsoft in July, 29 days after the public exploit appeared.
Source: Dark Reading