Skip to content
Microsoft Acknowledges RoguePlanet Zero-Day Vulnerability in Defender

Microsoft Acknowledges RoguePlanet Zero-Day Vulnerability in Defender

First seen 17 Jun 2026, 12:10 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster June 18, 2026 at 11:42 UTC
  • CVE-2026-50656 is a critical zero-day vulnerability in Microsoft Defender.
  • The vulnerability allows local privilege escalation without user interaction.
  • Microsoft is actively developing a patch to address the issue.

Microsoft has confirmed a critical zero-day vulnerability in Microsoft Defender, identified as CVE-2026-50656, which allows for local privilege escalation. The flaw, dubbed 'RoguePlanet,' was disclosed by security researcher Nightmare Eclipse and has a CVSS score of 7.8. It exploits a race condition in Defender, enabling attackers to gain system privileges without user interaction. Microsoft is actively working on a security patch to address this vulnerability. The vulnerability affects Windows 10 and Windows 11 systems with the June 2026 patches installed. A proof-of-concept exploit has been released, demonstrating the ease of exploitation. Microsoft has advised users to remain vigilant until a patch is available.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 94d ago How this analysis works

Timeline

2026-06-16
CVE-2026-50656 published
Microsoft Security Response Center published details on the RoguePlanet vulnerability affecting Defender.
Api.Msrc.Microsoft
2026-06-17
Microsoft acknowledges vulnerability
Microsoft confirmed the RoguePlanet vulnerability and stated it is working on a patch.
Rss.Slashdot
2026-06-17
Public disclosure by Nightmare Eclipse
Security researcher Nightmare Eclipse publicly disclosed the exploit details and proof-of-concept.
Feeds2.Feedburner
2026-06-18
Ongoing patch development
Microsoft continues to develop a high-quality security update to address the RoguePlanet vulnerability.
Cybersecuritynews

More articles in this cluster (9)

Following this threat?

Track Nightmare Eclipse, Microsoft and CVE-2026-45585 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed