Skip to content
RoguePlanet Zero-Day: Microsoft releases new Windows patch

RoguePlanet Zero-Day: Microsoft releases new Windows patch

Heise.De July 9, 2026

Yesterday, Wednesday, Microsoft updated its Windows Malware Protection Engine to better protect against possible attacks on the “RoguePlanet” vulnerability (CVE-2026-50656, CVSS-Base Score 7.8), known since mid-June. In the course of a successful attack, attackers could gain system privileges via the vulnerability.

CVE-2026-50656 affects Windows 10 and 11 and was first targeted by Microsoft on June 10 as part of definition update 1.453.20.0. According to our experiments at the time, however, only superficially : With a trivial change in the source code of the proof-of-concept exploit, the old patch could be bypassed in a very short time and a shell with system privileges could be executed again.

The Malware Protection Engine is a central virus protection component of Windows Defender and related protection solutions in Microsoft products. By default, the engine update happens automatically, so users don't have to do anything. In case of different configurations, it is advisable to take a look at the updated security advisory for CVE-2026-50656 .

According to MS, engine versions from 1.1.26060.3008 onwards are secured against RoguePlanet. You can check the module version in Windows 10 and 11 by opening the Security Center, going to Settings, and clicking on “Info”.

RoguePlanet is one of a whole series of Windows zero-day vulnerabilities that a security researcher with the pseudonym “Nightmare Eclipse” has gradually disclosed over the past three months.

Following BlueHammer (CVE-2026-33825) in April , RedSun (CVE-2026-41091), UnDefend (CVE-2026-45498), YellowKey (CVE-2026-45585) as well as GreenPlasma and MiniPlasma (both tracing back to CVE-2020-17103) followed. In several cases, the vulnerabilities described in detail on GitHub had been exploited for attacks .

According to Microsoft, there was no Coordinated Vulnerability Disclosure (CVD) process, during which manufacturers of vulnerable products are usually informed vulnerabilities in advance. The company therefore threatened legal action and the police . “Nightmare Eclipse” denied the accusations.

In particular, an MSRC blog post titled “A shared responsibility: Protecting customers through Coordinated Vulnerability Disclosure, ” in which the company expressed its outrage quite emotionally, triggered sometimes heated discussions in the security community. Among other things, Microsoft wrote: “Our digital crimes department will continue to initiate proceedings against [criminal] actors and against those who enable their criminal activities.” The latter half-sentence was widely interpreted as a general threat against (public) security research.

It remains to be seen whether an engine patch, as a rather superficial solution, will hold up long-term against RoguePlanet and possible variants. And whether and in what form Nightmare Eclipse will release further vulnerability findings soon.

At least for the upcoming patch day on July 14, the researcher according to a blog post does not plan a mass zero-day release. Whether this can be believed is another matter.

This article was originally published in German . It was translated with technical assistance and editorially reviewed before publication.