Microsoft Defender RoguePlanet race-condition zero-day remote code execution flaw
Vulnerability
Summary
Hide ▲
Show ▼
Microsoft Defender zero-day RoguePlanet is a race-condition flaw affecting fully patched Windows 10 and Windows 11 systems. A public proof-of-concept exploit was released shortly after June 2026 Patch Tuesday and can spawn a SYSTEM-level command prompt or shell when exploitation succeeds. Later reporting added that the exploit was reproduced on fully patched Windows 11 with KB5094126 and that the issue was originally aimed at remote code execution over SMB-hosted files, though the released proof of concept is mainly described as local privilege escalation. The later disclosure also says the exploit has been tested on Windows 10 and Windows 11 with June 2026 updates and does not yet work on Windows Server without redesign.
Related Happenings
Microsoft Azure DevOps MCP server prompt-injection security flaw
Vulnerability
H score29
First: 22.07.2026 07:57
Last: 22.07.2026 07:57
Sources 1
About this happening:
Microsoft Azure DevOps MCP server has a prompt-injection flaw in the repo_get_pull_request_by_id path that lets hidden HTML comments in pull request descriptions s...
Microsoft Azure DevOps MCP server prompt-injection security flaw
VulnerabilityAbout this happening: Microsoft Azure DevOps MCP server has a prompt-injection flaw in the repo_get_pull_request_by_id path that lets hidden HTML comments in pull request descriptions s...
Windows User Profile Service zero-day privilege-escalation flaw (LegacyHive)
Vulnerability
H score41
First: 17.07.2026 14:05
Last: 17.07.2026 14:05
Sources 1
About this happening:
A public LegacyHive zero-day against Windows User Profile Service can escalate privileges on up-to-date Windows systems, creating admin-level compromise risk. The expl...
Windows User Profile Service zero-day privilege-escalation flaw (LegacyHive)
VulnerabilityAbout this happening: A public LegacyHive zero-day against Windows User Profile Service can escalate privileges on up-to-date Windows systems, creating admin-level compromise risk. The expl...
Latest development: 21.07.2026 11:06
ACROS Security and 0Patch released free unofficial micropatches for LegacyHive, the Windows User Profile Service zero-day that lets a regular non-admin user mount another user's registry hive in full access mode and modify values that affect what gets executed when an admin logs in. The micropatches cover Windows 10 2004 or later and Windows Server 2022 or later, while Microsoft had not yet assigned a CVE-ID or issued security updates.
Active Directory Federation Services actively exploited elevation of privilege privilege-escalation flaw (CVE-2026-56155)
Vulnerability
H score29
First: 14.07.2026 21:01
Last: 14.07.2026 21:01
Sources 1
About this happening:
Microsoft patched CVE-2026-56155 in Active Directory Federation Services (AD FS) after confirming active exploitation of an elevation-of-privilege flaw that could let...
Active Directory Federation Services actively exploited elevation of privilege privilege-escalation flaw (CVE-2026-56155)
VulnerabilityAbout this happening: Microsoft patched CVE-2026-56155 in Active Directory Federation Services (AD FS) after confirming active exploitation of an elevation-of-privilege flaw that could let...
Microsoft Defender BlueHammer (CVE-2026-33825) ransomware exploitation wave
Exploitation Wave
H score41
First: 30.06.2026 11:53
Last: 30.06.2026 11:53
Sources 1
About this happening:
CISA has flagged BlueHammer (CVE-2026-33825) as exploited in ransomware campaigns, expanding the risk to Windows devices exposed to privilege escalation. The flaw in *...
Microsoft Defender BlueHammer (CVE-2026-33825) ransomware exploitation wave
Exploitation WaveAbout this happening: CISA has flagged BlueHammer (CVE-2026-33825) as exploited in ransomware campaigns, expanding the risk to Windows devices exposed to privilege escalation. The flaw in *...
Microsoft Malware Protection Engine race-condition elevation-of-privilege remote code execution flaw (CVE-2026-50656)
Vulnerability
H score32
First: 17.06.2026 11:32
Last: 17.06.2026 11:32
Sources 1
About this happening:
Microsoft has released a security update for CVE-2026-50656 after public disclosure of RoguePlanet, a privilege-escalation flaw in the Microsoft Malware Protecti...
Microsoft Malware Protection Engine race-condition elevation-of-privilege remote code execution flaw (CVE-2026-50656)
VulnerabilityAbout this happening: Microsoft has released a security update for CVE-2026-50656 after public disclosure of RoguePlanet, a privilege-escalation flaw in the Microsoft Malware Protecti...
Timeline
-
10.06.2026 08:22 2 articles · 1mo ago
Chaotic Eclipse releases RoguePlanet proof-of-concept exploit for Microsoft Defender
Initial DisclosureThe anonymous security researcher Chaotic Eclipse, also known as Nightmare-Eclipse, released a proof-of-concept (PoC) exploit for the Microsoft Defender zero-day RoguePlanet under a new GitHub account named MSNightmare. The race-condition exploit can yield a SYSTEM-level shell and arbitrary code execution when it succeeds, has been tested on Windows 11 and Windows 10 with the June 2026 Patch Tuesday updates installed, and currently does not work on Windows Server without redesign because standard users cannot mount an ISO image.
Show sources
- Microsoft Defender RoguePlanet Zero-Day Grants SYSTEM Access on Updated Windows — thehackernews.com — 10.06.2026 08:22
- Microsoft Defender RoguePlanet Zero-Day Grants SYSTEM Access on Updated Windows — thehackernews.com — 10.06.2026 08:22
-
10.06.2026 02:11 2 articles · 1mo ago
Nightmare Eclipse releases RoguePlanet Microsoft Defender exploit
Initial DisclosureNightmare Eclipse releases the RoguePlanet proof-of-concept as a Microsoft Defender race-condition exploit that can spawn a command prompt with SYSTEM privileges on fully patched Windows 10 and Windows 11 systems.
Show sources
- Microsoft Defender 'RoguePlanet' zero-day grants SYSTEM privileges — www.bleepingcomputer.com — 10.06.2026 02:11
- Microsoft Defender 'RoguePlanet' zero-day grants SYSTEM privileges — www.bleepingcomputer.com — 10.06.2026 02:11
-
10.06.2026 02:11 1 articles · 1mo ago
ThreatLocker reproduces RoguePlanet on fully patched Windows 11
Technical Analysis UpdateThreatLocker reproduces RoguePlanet against fully patched Windows 11 systems with KB5094126 installed and says application allowlisting can prevent the exploit from executing.
Show sources
- Microsoft Defender 'RoguePlanet' zero-day grants SYSTEM privileges — www.bleepingcomputer.com — 10.06.2026 02:11