Microsoft Patches "RoguePlanet" Defender Zero-Day (CVE-2026-50656) via Engine Update
The Defender flaw was disclosed with a public proof-of-concept amid an ongoing dispute over Microsoft's bug bounty and disclosure practices — and was patched through an engine update rather than a Patch Tuesday fix.

On this page
Key takeaways
- Microsoft fixed CVE-2026-50656 ("RoguePlanet") via Malware Protection Engine update 1.1.26060.3008.
- The researcher "Nightmare Eclipse" says the flaw is a Defender race condition enabling local escalation to SYSTEM.
- A proof-of-concept was published in a self-hosted Git repository; success is inconsistent because it depends on a race condition.
- Microsoft confirmed it was working on the patch on June 16 but has not credited the researcher for the discovery.
- The engine update is delivered automatically to Defender; admins should verify the deployed engine version.
What to do now
High urgency- Confirm Malware Protection Engine version 1.1.26060.3008 or later is deployed.
- Ensure Defender updates reach offline and update-restricted endpoints.
- Monitor for unexpected SYSTEM-level process activity.
Microsoft has released a security update to fix a Microsoft Defender zero-day dubbed "RoguePlanet," tracked as CVE-2026-50656, which was disclosed publicly after the June 2026 Patch Tuesday by a security researcher using the "Nightmare Eclipse" handle. The fix ships as Microsoft Malware Protection Engine 1.1.26060.3008, an update to the core scanning engine behind Microsoft's security products.
According to the researcher, the flaw is a Defender race condition that can spawn a command prompt with SYSTEM privileges on fully patched Windows 10 and 11 machines, and works whether or not real-time protection is enabled. A proof-of-concept was published, raising the risk that others could weaponize it before organizations confirm the engine update has rolled out.
Microsoft patched the RoguePlanet Defender zero-day (CVE-2026-50656) through a Malware Protection Engine update after the flaw was disclosed with a public proof-of-concept.
Microsoft shipped Malware Protection Engine 1.1.26060.3008 to fix the RoguePlanet Defender race-condition flaw (CVE-2026-50656). Confirm your Defender engine is updated to that version or later.
Affected & context
Microsoft released Malware Protection Engine 1.1.26060.3008 to address CVE-2026-50656 ("RoguePlanet"), a Microsoft Defender race-condition vulnerability disclosed with a public proof-of-concept by a researcher using the "Nightmare Eclipse" handle.
The flaw was claimed to allow local privilege escalation to SYSTEM on fully patched Windows 10 and 11 devices regardless of real-time protection state, and a proof-of-concept was published before the fix.
Windows 10 and Windows 11 devices running Microsoft Defender, per the researcher's claims.
- Vendors
- Microsoft
- Products
- Microsoft DefenderMicrosoft Malware Protection EngineWindows 10Windows 11
- Geography
- Global
- CVEs
- CVE-2026-50656
What happened
Microsoft has patched a Microsoft Defender zero-day vulnerability nicknamed "RoguePlanet" and tracked as CVE-2026-50656. The flaw was disclosed publicly after the June 2026 Patch Tuesday by a security researcher operating under the "Nightmare Eclipse" handle, who also published a proof-of-concept exploit.
Rather than shipping through a monthly Windows cumulative update, the fix arrived as Microsoft Malware Protection Engine version 1.1.26060.3008 — an update to the core scanning engine that underpins Microsoft's security products and services. Microsoft stated that the engine update addresses the vulnerability identified by CVE-2026-50656 and pointed to its FAQ for instructions on checking whether the new version is installed.
- Fix delivered via Malware Protection Engine 1.1.26060.3008
- Tracked as CVE-2026-50656
How RoguePlanet works
According to the researcher, RoguePlanet exploits a race condition in Microsoft Defender to spawn a command prompt running with SYSTEM privileges. They said the flaw affects fully patched Windows 10 and Windows 11 devices.
Because the exploit relies on a timing race, its reliability varies. The researcher described it as "hit or miss," reporting a 100% success rate on some machines while it struggled on others. They also stated the proof-of-concept works whether or not Defender's real-time protection is enabled.
Unverified specifics
The privilege-escalation behavior and the claim that the exploit works regardless of real-time protection come from the researcher's own statements. These details had not been independently confirmed by Microsoft at the time of writing.
A disclosure dispute with Microsoft
The RoguePlanet disclosure is part of an ongoing dispute between the researcher and Microsoft over the company's bug bounty and vulnerability disclosure practices. Nightmare Eclipse published the proof-of-concept in a self-hosted Git repository, saying Microsoft had previously taken down their exploit repositories on GitHub and GitLab.
Over recent months the same researcher has disclosed several other Windows zero-days, referred to as BlueHammer, RedSun, GreenPlasma, MiniPlasma, YellowKey, and UnDefend. Some affect Microsoft Defender while others target BitLocker and other Windows components. Microsoft fixed the GreenPlasma, MiniPlasma, and YellowKey flaws as part of the June 2026 Patch Tuesday updates a month earlier.
Microsoft has responded to these disclosures by warning of possible legal action against those it accused of "malicious activity causing real harm to our customers." Some security experts interpreted that language as a direct threat aimed at the researcher. Microsoft confirmed on June 16 that it was working on a fix for CVE-2026-50656 but has not acknowledged that Nightmare Eclipse discovered the vulnerability.
What admins should do
The Malware Protection Engine typically updates automatically alongside Defender security intelligence updates, so most managed and internet-connected devices should receive the fix without manual action. Administrators should nonetheless confirm the deployed engine version.
- Verify Microsoft Malware Protection Engine is at version 1.1.26060.3008 or later on Defender-protected endpoints.
- Check that Defender platform and security intelligence updates are flowing to offline, air-gapped, or update-restricted systems.
- Prioritize hosts where local users are untrusted, since the flaw is described as a local privilege-escalation issue.
- Monitor for unexpected SYSTEM-level command prompts or Defender process anomalies.
Checking the engine version
Microsoft's advisory FAQ describes how to confirm the installed Malware Protection Engine version. Because updates roll out automatically, verification is mainly needed for isolated or manually managed environments.
Timeline
Microsoft confirms it is working on a fix
Microsoft acknowledges it is preparing a patch for CVE-2026-50656 but does not credit the discovering researcher.
Source: Microsoft
Confidence: Medium
Disclosure and proof-of-concept published
The researcher using the "Nightmare Eclipse" handle discloses RoguePlanet and shares a PoC in a self-hosted Git repository.
Source: Nightmare Eclipse
Confidence: Medium
Engine update released
Microsoft releases Malware Protection Engine 1.1.26060.3008 addressing CVE-2026-50656.
Source: Microsoft
Confidence: Medium
Impact
A publicly disclosed Defender race-condition flaw claimed to enable local escalation to SYSTEM on fully patched Windows 10 and 11 devices, now addressed by an engine update.
Business impact
Organizations relying on Microsoft Defender needed to confirm the automatic engine update reached all endpoints, particularly isolated or manually managed systems.
Technical impact
Exploitation reportedly yields a SYSTEM-privileged command prompt via a Defender race condition; reliability varies because the exploit depends on timing.
Security impact
Local privilege escalation could let an attacker with limited access gain full control of a device; a public proof-of-concept raises the risk of reuse.
Affected audience: IT admins, Security teams, MSPs, Windows endpoint owners
Action required.
Technical details
- CVEs
- CVE-2026-50656
- Exploitation
- Proof of concept
- Attack vector
- Local (privilege escalation via Microsoft Defender race condition, per researcher)
- Affected versions
- Microsoft Defender on Windows 10 (per researcher), Microsoft Defender on Windows 11 (per researcher)
- Patched versions
- Microsoft Malware Protection Engine 1.1.26060.3008
- CWEs
- CWE-362
- MITRE ATT&CK
- T1068 - Exploitation for Privilege Escalation
Mitigations
- Update to Malware Protection Engine 1.1.26060.3008 or later.
Technical references
Response
Vendor statement
Microsoft said it released an update to the Microsoft Malware Protection Engine that addresses the vulnerability identified by CVE-2026-50656, and directed users to its FAQ for how to confirm the new version is installed.
Customer guidance
Microsoft advised checking whether the updated Malware Protection Engine version is installed; the engine generally updates automatically with Defender.
Response status: Patched
Patch available: Yes
Workaround available: No
FAQ
What is RoguePlanet (CVE-2026-50656)?
RoguePlanet is a Microsoft Defender vulnerability tracked as CVE-2026-50656. According to the researcher who disclosed it, it is a race condition that can spawn a command prompt with SYSTEM privileges on fully patched Windows 10 and 11 devices.
How did Microsoft fix it?
Microsoft released Malware Protection Engine version 1.1.26060.3008, an update to the core scanning engine used by its security products, rather than a Patch Tuesday Windows update.
Do I need to install anything manually?
The Malware Protection Engine usually updates automatically with Defender. Administrators should still verify the engine version on isolated or manually managed systems.
Is RoguePlanet being exploited in the wild?
There is no confirmation of in-the-wild exploitation. The researcher published a proof-of-concept, but its reliability varies because it depends on a timing race condition.
The bottom line
Microsoft patched the RoguePlanet Defender zero-day (CVE-2026-50656) through Malware Protection Engine 1.1.26060.3008 after a researcher disclosed it with a public proof-of-concept amid a dispute over Microsoft's disclosure practices.
The fix ships through Defender's engine update, so most systems patch automatically — but verify the engine version on any devices that do not update on their own.
What happens next
Watch for independent analysis of the flaw's real-world reliability, further disclosures from the same researcher, and whether Microsoft ultimately credits the discovery.
What to do
Confirm Malware Protection Engine 1.1.26060.3008 or later is deployed across your Defender endpoints.
Sources
Microsoft · Primary source
Claims supported
- Microsoft addressed CVE-2026-50656 via a Malware Protection Engine update.
Nightmare Eclipse · Primary source
Claims supported
- The researcher described RoguePlanet as a Defender race condition granting SYSTEM privileges.
- A proof-of-concept was published in a self-hosted Git repository.