Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Mindgard Raises $30M to Secure AI Systems Against Emerging Threats
August 12, 2026
City-Forum Hackers Exploit Salesforce, ServiceNow Critical Vulnerabilities
August 12, 2026
Palo Alto Networks Patches 11 Vulnerabilities in PAN-OS, GlobalProtect, Prisma Access
August 12, 2026
Home/CyberSecurity News/Critical Microsoft Defender Vulnerability Lets Attackers Bypass Security
CyberSecurity News

Critical Microsoft Defender Vulnerability Lets Attackers Bypass Security

Key Takeaways A critical zero-day vulnerability, dubbed “RoguePlanet” (CVE-2026-50656), has been identified in Microsoft Defender. The flaw is an Elevation of Privilege (EoP) issue within...

David kimber
David kimber
June 18, 2026 3 Min Read
55 0

Key Takeaways

  • A critical zero-day vulnerability, dubbed “RoguePlanet” (CVE-2026-50656), has been identified in Microsoft Defender.
  • The flaw is an Elevation of Privilege (EoP) issue within the Microsoft Malware Protection Engine, allowing local attackers to gain SYSTEM-level access.
  • The vulnerability affects fully patched Windows 10 and Windows 11 systems, including those with the June 2026 cumulative updates.
  • A functional public proof-of-concept (PoC) exists, and the vulnerability can be exploited even when Defender’s real-time protection is active or in passive mode.
  • Microsoft is actively developing a patch, but no release date has been announced.

Microsoft has acknowledged a significant zero-day vulnerability within its Defender security software, publicly named “RoguePlanet.” The company is currently developing a patch to address this critical flaw.

Table Of Content

  • Key Takeaways
  • Vulnerability Details and Impact
  • Discovery and Exploitation
  • Affected Systems and Mitigation Challenges
  • Microsoft’s Response
  • What You Should Do

Vulnerability Details and Impact

Formally documented as CVE-2026-50656, the vulnerability was officially disclosed by the Microsoft Security Response Center (MSRC) on June 16, 2026. It carries a CVSS 3.1 score of 7.8, classifying it as “Important.”

The issue is categorized as an Elevation of Privilege (EoP) vulnerability, stemming from CWE-59: Improper Link Resolution Before File Access (‘Link Following’). This flaw resides within the Microsoft Malware Protection Engine, which is the core scanning component integrated into Microsoft Defender.

According to the CVSS vector string, the vulnerability is locally exploitable, requiring only low privileges and no user interaction. It presents a high impact on confidentiality, integrity, and availability. Significantly, the “Remediation Level” is listed as “Unavailable,” while the “Exploit Code Maturity” is rated “Functional,” confirming the existence of a working public proof-of-concept (PoC).

Discovery and Exploitation

The “RoguePlanet” exploit was first released on June 10, 2026, merely hours after Microsoft completed its June 2026 Patch Tuesday updates. The discovery was made by a security researcher known by the aliases Nightmare Eclipse and Chaotic Eclipse.

The exploit targets a Time-of-Check to Time-of-Use (TOCTOU) race condition within Defender’s real-time scanning engine. It leverages the brief window between when Defender verifies a file path and when it subsequently acts upon it. Successful exploitation results in the spawning of a Windows command prompt with NT AUTHORITYSYSTEM privileges, which represents the highest privilege level available on a Windows system.

Affected Systems and Mitigation Challenges

This vulnerability impacts fully patched Windows 10 and Windows 11 systems, including those that have installed the June 2026 cumulative update, KB5094126. Cybersecurity firm ThreatLocker independently verified the exploit’s viability, successfully reproducing it on fully patched Windows 11 environments.

In a concerning update, Nightmare Eclipse revealed that the PoC functions regardless of whether Defender’s Real-Time Protection is enabled or disabled. It may even operate effectively in passive mode. While the exploit’s reliability can vary across machines due to its race-condition nature, the researcher expressed confidence in its potential for refinement to achieve consistent success rates.

Attempts by the security community to detect or block the PoC using signatures have largely proven ineffective, as minor modifications to the PoC can completely bypass existing mitigations.

Microsoft’s Response

Microsoft has rated this vulnerability as “Exploitation More Likely” on its Exploitability Index, confirming public disclosure but noting that it has not yet been observed being exploited in the wild. The vendor stated, “We are working to provide a high quality security update that addresses this vulnerability.”

Microsoft has not yet announced a specific release date for the patch. The CVE advisory will be updated once the security update becomes available.

What You Should Do

  • Monitor official Microsoft channels for the release of a security update addressing CVE-2026-50656.
  • Apply the forthcoming patch immediately upon its availability to all affected Windows 10 and Windows 11 systems.
  • While awaiting the patch, ensure all other security best practices are rigorously followed, including timely application of non-related security updates and maintaining robust endpoint detection and response (EDR) solutions.
  • Given the local exploitation vector, reinforce least privilege principles for all user accounts and restrict access to sensitive system directories where possible.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

CVECybersecurityExploitMalwarePatchSecurityThreatVulnerabilityzero-day

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

Critical OpenBSD Vulnerability Lets Attackers Bypass PAP Authentication

Next Post

Critical Splunk AI Toolkit Flaw Lets Attackers Run OS Commands

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Google Chrome 115 Patches Five High-Severity Use-After-Free Flaws
August 12, 2026
Eclipse Ransomware Launches RaaS, Targets Windows, Linux, ESXi
August 12, 2026
WhatsApp launches new scam alert feature to combat social engineering
August 12, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us