Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Microsoft Confirms Defender RoguePlanet 0-Day Exploit Working
June 18, 2026
OpenBSD Vulnerability Lets Attackers Bypass PAP Authentication
June 17, 2026
Stop URL Phishing: Cut SOC Triage Time & Draining SOCs
June 17, 2026
Home/CyberSecurity News/Microsoft Confirms Defender RoguePlanet 0-Day Exploit Working
CyberSecurity News

Microsoft Confirms Defender RoguePlanet 0-Day Exploit Working

Microsoft has confirmed a critical zero-day vulnerability within its Defender security suite. Publicly designated “RoguePlanet,” the company is actively developing a security patch to address this...

David kimber
David kimber
June 18, 2026 2 Min Read
2 0

Microsoft has confirmed a critical zero-day vulnerability within its Defender security suite. Publicly designated “RoguePlanet,” the company is actively developing a security patch to address this flaw.

Tracked as CVE-2026-50656, the vulnerability was formally published on June 16, 2026, by the Microsoft Security Response Center (MSRC) and carries a CVSS score of 7.8 (Important) under the CVSS 3.1 scoring framework.

The flaw is classified as an Elevation of Privilege (EoP) vulnerability rooted in CWE-59: Improper Link Resolution Before File Access (‘Link Following’), affecting the Microsoft Malware Protection Engine, the core scanning component embedded in Microsoft Defender.

The CVSS vector string reflects a locally exploitable flaw requiring only low privileges and no user interaction, with high impact across confidentiality, integrity, and availability. Notably, the Remediation Level is listed as Unavailable, and the Exploit Code Maturity is rated Functional, confirming that a working public proof-of-concept (PoC) exists.

RoguePlanet was first released on June 10, 2026, just hours after Microsoft concluded its June 2026 Patch Tuesday rollout by a security researcher operating under the aliases Nightmare Eclipse and Chaotic Eclipse.

The exploit targets a Time-of-Check to Time-of-Use (TOCTOU) race condition within Defender’s real-time scanning engine, exploiting the brief timing window between when Defender verifies a file path and when it acts on it. When successfully triggered, the exploit spawns a Windows command prompt running as NT AUTHORITYSYSTEM the highest privilege level on a Windows machine.

The vulnerability affects fully patched Windows 10 and Windows 11 systems, including those running the June 2026 cumulative update KB5094126. Cybersecurity firm ThreatLocker independently reproduced the exploit and confirmed its viability on fully patched Windows 11 systems.

In a particularly alarming update, Nightmare Eclipse revealed that the PoC works regardless of whether Defender’s Real-Time Protection is enabled or disabled and may even function in passive mode. The exploit’s reliability varies by machine due to its race-condition nature, but the researcher expressed confidence that it can be refined to achieve consistent success rates.

Attempts by the security community to detect or block the PoC through signatures have proven largely ineffective, as minor modifications to the PoC can bypass mitigations entirely.

Microsoft has rated this vulnerability “Exploitation More Likely” on its Exploitability Index, with public disclosure confirmed and the vulnerability not yet observed being exploited in the wild. The vendor stated: “We are working to provide a high quality security update that addresses this vulnerability.”

Microsoft has not yet announced a specific patch release date, and the CVE advisory will be updated once the security update becomes available.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

CVECybersecurityExploitMalwarePatchSecurityThreatVulnerabilityzero-day

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

OpenBSD Vulnerability Lets Attackers Bypass PAP Authentication

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Hackers Exploit ClickFix Prompt for MSI & Hands- Install Package
June 17, 2026
GitBait Phishing Abuses GitHub Pages to Attack Banks
June 17, 2026
Fake macOS Updates Steal Passwords & Crypto Hackers Software
June 17, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
Emy Elsamnoudy
Emy Elsamnoudy
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Detects Critical MongoDB CVE-

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us