Find notable cyber news and cases, enriched with sources, timelines, and signals.

Microsoft Malware Protection Engine race-condition elevation-of-privilege remote code execution flaw (CVE-2026-50656)

Vulnerability
First reported
Last updated
Happening score
H score 32
2 unique sources, 4 articles

Summary

Hide ▲

Microsoft has released a security update for CVE-2026-50656 after public disclosure of RoguePlanet, a privilege-escalation flaw in the Microsoft Malware Protection Engine (mpengine.dll) used by Microsoft Defender. The issue was described as a race condition that could let an attacker spawn a SYSTEM-level shell, enabling arbitrary code execution or unauthorized actions. Microsoft says the issue is remediated in Microsoft Malware Protection Engine version 1.1.26060.3008 and paired with defense-in-depth hardening updates.

Related Happenings

Microsoft SharePoint Server actively exploited multi-CVE wave

Exploitation Wave
H score78 First: 15.07.2026 12:44 Last: 15.07.2026 12:44 Sources 1

About this happening: SharePoint Server exploitation wave remains active across internet-exposed on-premises instances, with CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164 used...

Microsoft Defender BlueHammer (CVE-2026-33825) ransomware exploitation wave

Exploitation Wave
H score41 First: 30.06.2026 11:53 Last: 30.06.2026 11:53 Sources 1

About this happening: CISA has flagged BlueHammer (CVE-2026-33825) as exploited in ransomware campaigns, expanding the risk to Windows devices exposed to privilege escalation. The flaw in *...

Microsoft Defender RoguePlanet race-condition zero-day remote code execution flaw

Vulnerability
H score39 First: 10.06.2026 02:11 Last: 10.06.2026 02:11 Sources 1

About this happening: Microsoft Defender zero-day RoguePlanet is a race-condition flaw affecting fully patched Windows 10 and Windows 11 systems. A public proof-of-concept exploit was released shortly...

Latest development: 10.06.2026 08:22

The anonymous security researcher Chaotic Eclipse, also known as Nightmare-Eclipse, released a proof-of-concept (PoC) exploit for the Microsoft Defender zero-day RoguePlanet under a new GitHub account named MSNightmare. The race-condition exploit can yield a SYSTEM-level shell and arbitrary code execution when it succeeds, has been tested on Windows 11 and Windows 10 with the June 2026 Patch Tuesday updates installed, and currently does not work on Windows Server without redesign because standard users cannot mount an ISO image.

CCB urgent patch warning for CVE-2026-41089 on Windows servers

Public Sector Action
H score48 First: 01.06.2026 15:30 Last: 01.06.2026 15:30 Sources 1

About this happening: Belgium's CCB warned that CVE-2026-41089 is being actively exploited in the wild, urging admins to immediately patch vulnerable Windows servers because the fla...

Microsoft Defender zero-days exploited in attacks (multiple vulnerabilities)

Vulnerability
H score39 First: 21.05.2026 10:49 Last: 21.05.2026 10:49 Sources 1

About this happening: Microsoft began rolling out fixes for CVE-2026-41091 and CVE-2026-45498, two actively exploited zero-days in Microsoft Defender components that affect unpatched Wi...

Timeline

  1. 17.06.2026 11:32 5 articles · 28d ago

    Microsoft prepares a security update for RoguePlanet in Defender

    Mitigation Patch Update

    Microsoft said it is working to provide a high-quality security update for RoguePlanet, an elevation-of-privilege flaw now tracked as CVE-2026-50656 in the Microsoft Malware Protection Engine in Microsoft Defender. The researcher known as Nightmare Eclipse said the race-condition exploit can spawn SYSTEM command prompts on fully patched Windows 10 and Windows 11 devices, shared proof-of-concept code in a self-hosted repository, and said the PoC works even when real time protection is enabled.

    Show sources