Microsoft has issued an emergency patch for a critical zero-day vulnerability in Windows Defender, dubbed RoguePlanet, which was made public by a disgruntled security researcher known as “Nightmare-Eclipse” just last month. The flaw, tracked as CVE-2026-50656, allows an attacker to escalate privileges on a Windows device from a basic user to the highest SYSTEM-level access, giving them complete control over the system.
RoguePlanet is the latest in a series of zero-day vulnerabilities published by Nightmare-Eclipse, who has been engaged in a public feud with Microsoft for several months. The dispute began when the researcher published an exploit for another privilege-escalation flaw in Windows Defender, dubbed “BlueHammer,” and Microsoft responded with legal threats and warnings. In response, Nightmare-Eclipse continued to publish additional zero-day exploits, including RoguePlanet.
The patch for RoguePlanet is included in the Microsoft Malware Protection Engine version 1.1.26060.3008, and according to Microsoft’s advisory, Windows systems that have disabled Microsoft Defender are not in an exploitable state. However, the attack complexity for the vulnerability is low, and exploitation is “more likely,” making it a high-priority fix.
Despite the availability of a public exploit, it’s unclear if RoguePlanet has been exploited in the wild. Microsoft’s updated advisory states that the flaw has not been exploited, but Qualys published a threat report last month stating that RoguePlanet has been “exploited in attacks.” The uncertainty surrounding exploitation highlights the importance of patching vulnerabilities as soon as possible.
The publication of RoguePlanet and other zero-day exploits by Nightmare-Eclipse has driven multiple public exploit releases ahead of typical patch cycles, increasing risk for unpatched environments. As SOCRadar noted in a recent blog post, “RoguePlanet is not remotely exploitable by itself, but it can be highly valuable after an attacker gains local code execution as a standard user.” This makes it a second-stage tool that can give a threat actor the ability to tamper with security products and telemetry, dump credentials for lateral movement, and establish persistence through scheduled tasks and other techniques.
The urgency of issuing an emergency patch just before Patch Tuesday is unusual, but according to SOCRadar’s CISO Ensar Seker, it’s likely due to increased pressure from the public availability of exploit details. “Nightmare-Eclipse has repeatedly published detailed technical analyses and proof-of-concept exploits shortly after Patch Tuesday, reducing the amount of time defenders have before attackers can begin weaponizing the research,” Seker says.
In light of this incident, it’s essential for organizations to prioritize patching vulnerabilities as soon as possible, even if it means applying an emergency update outside of a regular patch cycle. This will help minimize the risk of exploitation and protect against potential attacks.
Source: Dark Reading — 2026-07-09