<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=10643465&amp;fmt=gif">

Nightmare-Eclipse Drops Another Windows Defender Zero-Day, RoguePlanet

Researcher Nightmare-Eclipse reveals RoguePlanet exploit targeting Windows Defender, exposing users to SYSTEM access risk post June Patch Tuesday.
Content Team

A researcher known as Nightmare-Eclipse has released yet another Microsoft zero-day exploit — this one called RoguePlanet — timed to drop right after Microsoft's June Patch Tuesday, which addressed a record 206 CVEs.

The new exploit abuses a race condition in Windows Defender's signature update workflow and, when it lands, spawns a shell with full SYSTEM privileges on Windows 10 and 11. It's unreliable by the researcher's own account — hit or miss — and doesn't work on Windows Server, though he claims a redesigned version would.

It's the latest salvo in a months-long feud that began in April with BlueHammer (CVE-2026-33825). Microsoft patched that one within the month and attackers exploited it anyway; there's no sign yet of RoguePlanet being used in the wild.

The researcher claims to have more vulnerabilities in Defender and other Windows components ready to go.

Updated 12 Aug 2026: RoguePlanet was assigned CVE-2026-50656 and patched by Microsoft in July, 29 days after the public exploit appeared.

Source: Dark Reading

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo