Microsoft Patches RoguePlanet Defender Zero-Day — But Not Without Controversy

Microsoft has finally patched the RoguePlanet vulnerability in Microsoft Defender. Tracked as CVE-2026-50656, the zero-day affects fully patched Windows 10 and Windows 11 systems by letting attackers spawn a command prompt with SYSTEM privileges through a race condition in Defender.

The vulnerability was disclosed by a security researcher using the handle “Nightmare Eclipse.” It came with a proof-of-concept exploit posted to a self-hosted Git repo.

Nightmare Eclipse claimed Microsoft had previously removed their exploit repos from GitHub and GitLab. They’ve been on a disclosure spree, releasing PoCs for BlueHammer, RedSun, GreenPlasma, MiniPlasma, YellowKey, and UnDefend over the past several months. Some hit Defender, others target BitLocker and Windows components.

Microsoft’s fix came via Malware Protection Engine 1.1.26060.3008. The company confirmed CVE-2026-50656 in its update guide but hasn’t acknowledged Nightmare Eclipse as the discoverer.

The researcher said the exploit is a “hit or miss” race condition. They got 100% success on some machines while others were harder. It works regardless of whether real-time protection is on.

Microsoft has also threatened legal action against the researcher, describing their disclosures as “malicious activity causing real harm to our customers.” Cybersecurity experts widely interpreted this as a direct threat.

Microsoft fixed GreenPlasma, MiniPlasma, and YellowKey in the June 2026 Patch Tuesday. RoguePlanet was the latest to join the patched list. Whether the relationship between Microsoft and this researcher gets any less adversarial remains to be seen.

References