Skip to content
Microsoft Reins in RoguePlanet Zero

Microsoft Reins in RoguePlanet Zero

Darkreading Rob Wright July 9, 2026

The researcher known as "Nightmare-Eclipse" published a proof-of-concept (PoC) exploit for the Windows Defender vulnerability in early June after dropping several other Microsoft zero-days.

Microsoft has tackled yet another zero-day vulnerability published by a disgruntled security researcher with a vendetta against the software giant.

On Wednesday, Microsoft issued an out-of-band patch for RoguePlanet , an elevation-of-privilege vulnerability in Windows Defender, tracked as CVE-2026-50656. The high-severity flaw, which received a 7.8 CVSS score from Microsoft, could allow an attacker to escalate privileges on a Windows device from a basic user to the highest SYSTEM-level access, which would give them complete control over the device.

RoguePlanet was initially published, along with a proof-of-concept (PoC) exploit, by an anonymous security researcher known as "Nightmare-Eclipse," who has been embroiled in a public feud with Microsoft for several months. The dispute began in April when the researcher published an exploit for another privilege-escalation flaw in Windows Defender, dubbed " BlueHammer " and tracked as CVE-2026-33825, out of frustration with Microsoft's Security Response Center (MSRC).

The feud escalated over several weeks, with Microsoft taking action and issuing legal threats, while Nightmare-Eclipse continued publishing additional zero-day exploits , several of which came under attack soon after. The research swore revenge against Microsoft for allegedly humiliating them, and threatened to "make sure your bones are shattered" on July 14, though Nightmare-Eclipse has since backed off that date.

The patch for RoguePlanet is included in the Microsoft Malware Protection Engine version 1.1.26060.3008. According to Microsoft's advisory for CVE-2026-50656, Windows systems that have disabled Microsoft Defender "are not in an exploitable state."

However, Microsoft noted the attack complexity for the vulnerability is low, and that exploitation is "more likely."

In a blog post on Thursday, SOCRadar noted that while RoguePlanet requires local access to a vulnerable device before exploitation and is best described a post-compromise privilege-escalation exploit, it's still dangerous.

"RoguePlanet is not remotely exploitable by itself, but it can be highly valuable after an attacker gains local code execution as a standard user," the research team wrote in the blog post.

As a second-stage tool, SOCRadar said RoguePlanet could give a threat actor the ability to tamper with security products and telemetry, dump credentials for lateral movement, and establish persistence through scheduled tasks and other techniques.

Additionally, SOCRadar noted that Nightmare-Eclipse's ongoing feud with Microsoft has "driven multiple public exploit releases ahead of typical patch cycles, increasing risk for unpatched environments." SOCRadar chief information security officer (CISO) Ensar Seker tells Dark Reading that, while it's unusual for Microsoft to issue an emergency update shortly before a Patch Tuesday release (July's is on the 14th), it's likely due to increased urgency around a flaw.

"Nightmare-Eclipse has repeatedly published detailed technical analyses and proof-of-concept exploits shortly after Patch Tuesday, reducing the amount of time defenders have before attackers can begin weaponizing the research," Seker says. "Even if Microsoft had already been preparing the fix, widespread public availability of exploit details likely accelerated its release."

Despite a public exploit being available for RoguePlanet, it's unclear if the vulnerability has been exploited in the wild. Microsoft's updated advisory states the flaw has not been exploited, and CISA has not added CVE-2026-50656 to its Known Exploited Vulnerabilities (KEV) catalog . Qualys, meanwhile, published a threat report on June 18 stating that RoguePlanet has been "exploited in attacks," though no details were provided.

Seker says the absence of confirmed exploitation doesn't mean RoguePlanet hasn't yet been weaponized by attackers.

"Endpoint security products such as Microsoft Defender are deployed across millions of systems, making them attractive targets, but successful exploitation often leaves very limited public visibility, he says. "Attackers who gain the ability to disable or evade security controls have a strong incentive to remain quiet because revealing the technique would shorten its useful lifetime."

Even though CVE-2026-50656 has the prerequisite that an attacker must have local access, Seker says RoguePlanet should be treated as a high-priority risk because Nightmare-Eclipse has a track record of publishing "technically sound research" with exploits that have been incorporated into attackers' tooling.

"In many cases, defenders only learn that a security product vulnerability was abused months later through incident-response investigations or threat-intelligence reporting," he says.

SOCRadar urged organizations to ensure they've received the Microsoft Malware Protection Engine update, harden local execution controls on endpoints, and monitor for signs of privilege escalation activity. These signs include user-context processes spawning SYSTEM-level shells, Windows Defender service or configuration changes, and the creation of news services, scheduled tasks, and autoruns.

Senior News Director, Dark Reading

Rob Wright is a longtime reporter with more than 25 years of experience as a technology journalist. Prior to joining Dark Reading as senior news director, he spent more than a decade at TechTarget's SearchSecurity in various roles, including senior news director, executive editor and editorial director. Before that, he worked for several years at CRN, Tom's Hardware Guide, and VARBusiness Magazine covering a variety of technology beats and trends.

Prior to becoming a technology journalist in 2000, he worked as a weekly and daily newspaper reporter in Virginia, where he won three Virginia Press Association awards in 1998 and 1999. At TechTarget and Dark Reading, he has won several Azbee awards, including the 2026 National Silver Award for a series on vibe coding.

At Dark Reading, Rob currently covers security operations, cloud security, and Internet infrastructure. He has a keen interest in malvertising activity and the certificate authority industry, and has written extensively on both topics. He graduated from the University of Richmond in 1997 with a degree in journalism and English. A native of Massachusetts, he lives in the Boston area.

The State of Cloud Security: The Latest Challenges

The total economic impact™ of Snyk

How Organizations Are Managing Incident Response

How Enterprises Are Developing Secure Applications

Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy

When AI Becomes an Insider: Rethinking Risk in Critical Infrastructure

Governing the Agent; Identity Security in the Age of Autonomous AI

Securing the AI Era: Shadow AI, AI Agents, and Why AI Detection and Response Changes Everything

Practical Zero Trust Implementation on a Budget in the Age of Mythos

Building a Risk Based Vulnerability Management Program