Microsoft Defender RoguePlanet race-condition zero-day remote code execution flaw
Vulnerability
Summary
Hide ▲
Show ▼
Microsoft Defender zero-day RoguePlanet is a race-condition flaw affecting fully patched Windows 10 and Windows 11 systems. A public proof-of-concept exploit was released shortly after June 2026 Patch Tuesday and can spawn a SYSTEM-level command prompt or shell when exploitation succeeds. Later reporting added that the exploit was reproduced on fully patched Windows 11 with KB5094126 and that the issue was originally aimed at remote code execution over SMB-hosted files, though the released proof of concept is mainly described as local privilege escalation. The later disclosure also says the exploit has been tested on Windows 10 and Windows 11 with June 2026 updates and does not yet work on Windows Server without redesign.
Related Happenings
Microsoft Defender Antivirus false 'turned off' alerts after latest updates
Security Tool/Service
H score11
First: 31.08.2026 11:29
Last: 31.08.2026 11:29
Sources 1
About this happening:
Microsoft Defender Antivirus is showing false 'turned off' alerts after the latest updates, creating confusion on supported Windows client and server systems even though p...
Microsoft Defender Antivirus false 'turned off' alerts after latest updates
Security Tool/ServiceAbout this happening: Microsoft Defender Antivirus is showing false 'turned off' alerts after the latest updates, creating confusion on supported Windows client and server systems even though p...
Microsoft Defender signature update fixes scan-crash bug on Windows 10 and Windows 11
Security Tool/Service
H score11
First: 19.08.2026 14:14
Last: 19.08.2026 14:14
Sources 1
About this happening:
Microsoft Defender now has a fix for a crash bug that broke scans on some Windows 10 and Windows 11 systems, restoring malware protection after a recent security updat...
Microsoft Defender signature update fixes scan-crash bug on Windows 10 and Windows 11
Security Tool/ServiceAbout this happening: Microsoft Defender now has a fix for a crash bug that broke scans on some Windows 10 and Windows 11 systems, restoring malware protection after a recent security updat...
Microsoft Azure DevOps MCP server prompt-injection security flaw
Vulnerability
H score29
First: 22.07.2026 07:57
Last: 22.07.2026 07:57
Sources 1
About this happening:
Microsoft Azure DevOps MCP server has a prompt-injection flaw in the repo_get_pull_request_by_id path that lets hidden HTML comments in pull request descriptions s...
Microsoft Azure DevOps MCP server prompt-injection security flaw
VulnerabilityAbout this happening: Microsoft Azure DevOps MCP server has a prompt-injection flaw in the repo_get_pull_request_by_id path that lets hidden HTML comments in pull request descriptions s...
Windows User Profile Service zero-day privilege-escalation flaw (LegacyHive)
Vulnerability
H score41
First: 17.07.2026 14:05
Last: 17.07.2026 14:05
Sources 1
About this happening:
A public LegacyHive zero-day against Windows User Profile Service can escalate privileges on up-to-date Windows systems, creating admin-level compromise risk. The expl...
Windows User Profile Service zero-day privilege-escalation flaw (LegacyHive)
VulnerabilityAbout this happening: A public LegacyHive zero-day against Windows User Profile Service can escalate privileges on up-to-date Windows systems, creating admin-level compromise risk. The expl...
Latest development: 21.07.2026 11:06
ACROS Security and 0Patch released free unofficial micropatches for LegacyHive, the Windows User Profile Service zero-day that lets a regular non-admin user mount another user's registry hive in full access mode and modify values that affect what gets executed when an admin logs in. The micropatches cover Windows 10 2004 or later and Windows Server 2022 or later, while Microsoft had not yet assigned a CVE-ID or issued security updates.
Active Directory Federation Services actively exploited elevation of privilege privilege-escalation flaw (CVE-2026-56155)
Vulnerability
H score29
First: 14.07.2026 21:01
Last: 14.07.2026 21:01
Sources 1
About this happening:
Microsoft patched CVE-2026-56155 in Active Directory Federation Services (AD FS) after confirming active exploitation of an elevation-of-privilege flaw that could let...
Active Directory Federation Services actively exploited elevation of privilege privilege-escalation flaw (CVE-2026-56155)
VulnerabilityAbout this happening: Microsoft patched CVE-2026-56155 in Active Directory Federation Services (AD FS) after confirming active exploitation of an elevation-of-privilege flaw that could let...
Timeline
-
10.06.2026 08:22 2 articles · 3mo ago
Chaotic Eclipse releases RoguePlanet proof-of-concept exploit for Microsoft Defender
Initial DisclosureThe anonymous security researcher Chaotic Eclipse, also known as Nightmare-Eclipse, released a proof-of-concept (PoC) exploit for the Microsoft Defender zero-day RoguePlanet under a new GitHub account named MSNightmare. The race-condition exploit can yield a SYSTEM-level shell and arbitrary code execution when it succeeds, has been tested on Windows 11 and Windows 10 with the June 2026 Patch Tuesday updates installed, and currently does not work on Windows Server without redesign because standard users cannot mount an ISO image.
Show sources
- Microsoft Defender RoguePlanet Zero-Day Grants SYSTEM Access on Updated Windows — thehackernews.com — 10.06.2026 08:22
- Microsoft Defender RoguePlanet Zero-Day Grants SYSTEM Access on Updated Windows — thehackernews.com — 10.06.2026 08:22
-
10.06.2026 02:11 2 articles · 3mo ago
Nightmare Eclipse releases RoguePlanet Microsoft Defender exploit
Initial DisclosureNightmare Eclipse releases the RoguePlanet proof-of-concept as a Microsoft Defender race-condition exploit that can spawn a command prompt with SYSTEM privileges on fully patched Windows 10 and Windows 11 systems.
Show sources
- Microsoft Defender 'RoguePlanet' zero-day grants SYSTEM privileges — www.bleepingcomputer.com — 10.06.2026 02:11
- Microsoft Defender 'RoguePlanet' zero-day grants SYSTEM privileges — www.bleepingcomputer.com — 10.06.2026 02:11
-
10.06.2026 02:11 1 articles · 3mo ago
ThreatLocker reproduces RoguePlanet on fully patched Windows 11
Technical Analysis UpdateThreatLocker reproduces RoguePlanet against fully patched Windows 11 systems with KB5094126 installed and says application allowlisting can prevent the exploit from executing.
Show sources
- Microsoft Defender 'RoguePlanet' zero-day grants SYSTEM privileges — www.bleepingcomputer.com — 10.06.2026 02:11