Microsoft Acknowledges 'RoguePlanet' Zero-Day Vulnerability in Defender
Microsoft has issued an advisory acknowledging a publicly disclosed zero-day vulnerability within its Defender security software. The flaw, tracked as CVE-2026-50656 with a CVSS score of 7.8, could lead to privilege escalation. Named 'RoguePlanet' by security researcher Nightmare Eclipse, who disclosed it last week, the vulnerability targets a race condition to allow attackers to gain System privileges on Windows 10 and 11 systems. Microsoft confirmed it is actively working on a security update to address the issue.
Microsoft has published an advisory confirming the public disclosure of a vulnerability in its Defender software that could facilitate privilege escalation. The security defect, identified as CVE-2026-50656, carries a CVSS score of 7.8.
Security researcher Nightmare Eclipse, also known as Chaotic Eclipse, disclosed the vulnerability last week. Microsoft stated it is currently developing a high-quality security update to resolve the issue and will provide further information via the CVE when the update becomes available.
The vulnerability, dubbed 'RoguePlanet' by Nightmare Eclipse, exploits a race condition within Microsoft Defender, enabling attackers to acquire System privileges. The researcher released a proof-of-concept (PoC) exploit demonstrating local privilege escalation (LPE) on Windows 11 and Windows 10 systems, even those with the June 2026 patches installed.
Nightmare Eclipse further noted on Wednesday that the PoC functions irrespective of whether Defender's real-time protection is enabled or disabled. The researcher suggested that it might also be effective in passive mode.
According to Slashdot, these details were shared in a report from SecurityWeek.



