Find notable cyber news and cases, enriched with sources, timelines, and signals.

Microsoft Defender RoguePlanet race-condition zero-day remote code execution flaw

Vulnerability
First reported
Last updated
Happening score
H score 39
2 unique sources, 2 articles

Summary

Hide ▲

Microsoft Defender zero-day RoguePlanet is a race-condition flaw affecting fully patched Windows 10 and Windows 11 systems. A public proof-of-concept exploit was released shortly after June 2026 Patch Tuesday and can spawn a SYSTEM-level command prompt or shell when exploitation succeeds. Later reporting added that the exploit was reproduced on fully patched Windows 11 with KB5094126 and that the issue was originally aimed at remote code execution over SMB-hosted files, though the released proof of concept is mainly described as local privilege escalation. The later disclosure also says the exploit has been tested on Windows 10 and Windows 11 with June 2026 updates and does not yet work on Windows Server without redesign.

Related Happenings

Microsoft Azure DevOps MCP server prompt-injection security flaw

Vulnerability
H score29 First: 22.07.2026 07:57 Last: 22.07.2026 07:57 Sources 1

About this happening: Microsoft Azure DevOps MCP server has a prompt-injection flaw in the repo_get_pull_request_by_id path that lets hidden HTML comments in pull request descriptions s...

Windows User Profile Service zero-day privilege-escalation flaw (LegacyHive)

Vulnerability
H score41 First: 17.07.2026 14:05 Last: 17.07.2026 14:05 Sources 1

About this happening: A public LegacyHive zero-day against Windows User Profile Service can escalate privileges on up-to-date Windows systems, creating admin-level compromise risk. The expl...

Latest development: 21.07.2026 11:06

ACROS Security and 0Patch released free unofficial micropatches for LegacyHive, the Windows User Profile Service zero-day that lets a regular non-admin user mount another user's registry hive in full access mode and modify values that affect what gets executed when an admin logs in. The micropatches cover Windows 10 2004 or later and Windows Server 2022 or later, while Microsoft had not yet assigned a CVE-ID or issued security updates.

Active Directory Federation Services actively exploited elevation of privilege privilege-escalation flaw (CVE-2026-56155)

Vulnerability
H score29 First: 14.07.2026 21:01 Last: 14.07.2026 21:01 Sources 1

About this happening: Microsoft patched CVE-2026-56155 in Active Directory Federation Services (AD FS) after confirming active exploitation of an elevation-of-privilege flaw that could let...

Microsoft Defender BlueHammer (CVE-2026-33825) ransomware exploitation wave

Exploitation Wave
H score41 First: 30.06.2026 11:53 Last: 30.06.2026 11:53 Sources 1

About this happening: CISA has flagged BlueHammer (CVE-2026-33825) as exploited in ransomware campaigns, expanding the risk to Windows devices exposed to privilege escalation. The flaw in *...

Microsoft Malware Protection Engine race-condition elevation-of-privilege remote code execution flaw (CVE-2026-50656)

Vulnerability
H score32 First: 17.06.2026 11:32 Last: 17.06.2026 11:32 Sources 1

About this happening: Microsoft has released a security update for CVE-2026-50656 after public disclosure of RoguePlanet, a privilege-escalation flaw in the Microsoft Malware Protecti...

Timeline

  1. 10.06.2026 08:22 2 articles · 1mo ago

    Chaotic Eclipse releases RoguePlanet proof-of-concept exploit for Microsoft Defender

    Initial Disclosure

    The anonymous security researcher Chaotic Eclipse, also known as Nightmare-Eclipse, released a proof-of-concept (PoC) exploit for the Microsoft Defender zero-day RoguePlanet under a new GitHub account named MSNightmare. The race-condition exploit can yield a SYSTEM-level shell and arbitrary code execution when it succeeds, has been tested on Windows 11 and Windows 10 with the June 2026 Patch Tuesday updates installed, and currently does not work on Windows Server without redesign because standard users cannot mount an ISO image.

    Show sources
  2. 10.06.2026 02:11 2 articles · 1mo ago

    Nightmare Eclipse releases RoguePlanet Microsoft Defender exploit

    Initial Disclosure

    Nightmare Eclipse releases the RoguePlanet proof-of-concept as a Microsoft Defender race-condition exploit that can spawn a command prompt with SYSTEM privileges on fully patched Windows 10 and Windows 11 systems.

    Show sources
  3. 10.06.2026 02:11 1 articles · 1mo ago

    ThreatLocker reproduces RoguePlanet on fully patched Windows 11

    Technical Analysis Update

    ThreatLocker reproduces RoguePlanet against fully patched Windows 11 systems with KB5094126 installed and says application allowlisting can prevent the exploit from executing.

    Show sources