A security researcher known as Nightmare Eclipse has released a new Microsoft Defender zero-day exploit called ShieldBreak, which bypasses the previously patched RoguePlanet vulnerability (CVE-2026-50656) to grant SYSTEM privileges on fully patched Windows 10, Windows 11, and Windows Server systems. The exploit requires Defender to be enabled and has a reported 100% success rate in testing, confirmed working by Will Dormann of Tharros. This is part of an ongoing dispute between Microsoft and the researcher, who has disclosed numerous other zero-days (LegacyHive, RoguePlanet, BlueHammer, RedSun, YellowKey, GreenPlasma, MiniPlasma, UnDefend) since April 2026 after Microsoft threatened legal action over the disclosures. Several of these flaws remain unpatched.
Table of contents
Related Articles:Questions this post answers
What is the ShieldBreak Microsoft Defender zero-day exploit?
ShieldBreak is a proof-of-concept exploit released by researcher Nightmare Eclipse that bypasses Microsoft's patch for the RoguePlanet vulnerability (CVE-2026-50656), granting SYSTEM privileges on fully patched Windows 10, Windows 11, and Windows Server systems. It requires Microsoft Defender to be enabled and was reported to have a 100% success rate in testing on Windows 11 25H2 and Windows Server 2025. Security teams tracking Defender privilege escalation flaws can follow patch-bypass reports like this on daily.dev.
Has Microsoft patched the RoguePlanet Defender vulnerability CVE-2026-50656 completely?
No, Microsoft's July patch for RoguePlanet (CVE-2026-50656) was incomplete. The ShieldBreak exploit, released by Nightmare Eclipse, demonstrates a full bypass of that patch, allowing attackers to still gain SYSTEM privileges on Windows systems that Microsoft considers fully patched. Admins verifying Defender patch coverage can track disclosures like this bypass on daily.dev.
Why is Microsoft in a public dispute with the security researcher Nightmare Eclipse?
Microsoft threatened legal action against Nightmare Eclipse, warning against 'malicious activity causing real harm' to customers, after the researcher publicly disclosed a series of unpatched Windows zero-days including LegacyHive, RoguePlanet, BlueHammer, RedSun, and BitLocker flaws like YellowKey and GreenPlasma starting in April 2026. Cybersecurity experts viewed the warning as a direct threat rather than a standard coordinated disclosure response. Developers following disclosure disputes affecting Windows security can track the fallout on daily.dev.