Security researcher Chaotic Eclipse has released a proof-of-concept exploit dubbed ShieldBreak that allegedly bypasses Microsoft’s fix for CVE-2026-50656, also known as RoguePlanet, in Microsoft Defender for Windows. The flaw affects the Microsoft Malware Protection Engine and has been described as a local privilege escalation race condition that can let an attacker with local access spawn a SYSTEM-level shell and execute arbitrary code. The researcher said the bypass works reliably on Windows 11 25H2 and Windows Server 2025, and that Windows 10 is also believed to be vulnerable.
Microsoft had issued updates for the RoguePlanet zero-day after acknowledging it earlier, but the new claims suggest the patch was incomplete. The disclosure adds to ongoing scrutiny of Microsoft’s recent security fixes and follows earlier public zero-day releases by the same researcher, including LegacyHive, amid a broader dispute over coordinated vulnerability disclosure. Separate reporting also noted that Microsoft recently patched hundreds of flaws and that CISA added CVE-2026-68820, an actively exploited WinSock driver issue, to its Known Exploited Vulnerabilities catalog with a remediation deadline for U.S. federal agencies.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
14 events from the most recent confirmed update back to the earliest known activity.
On August 11, 2026, the ShieldBreak proof-of-concept exploit was publicly published on GitHub under the MSNightmare handle. The release bypassed Microsoft's July fix for RoguePlanet and, at the time of publication, had no coordinated disclosure, CVE assignment, or patch.
Three days after ShieldBreak's public disclosure, Microsoft said it was tracking the issue as CVE-2026-69414, an elevation-of-privilege flaw in the Microsoft Malware Protection Engine, and was preparing a security update. The company said it was actively investigating the vulnerability's validity and applicability.
After ShieldBreak was published, Will Dormann and Kevin Beaumont analyzed it and said it works differently from RoguePlanet rather than being a true bypass of Microsoft's July patch. Their analysis described abuse of Defender cloud-hydration scanning, Cloud Filter API behavior, and malicious phoneinfo.dll loading to gain SYSTEM privileges.
In the previous month, Chaotic Eclipse disclosed CVE-2026-62832 under the name LegacyHive, a Windows User Profile Service privilege escalation issue.
In early July 2026, Microsoft released security updates for CVE-2026-50656, nearly a month after the initial disclosure, to address the RoguePlanet Microsoft Defender flaw.
Before Microsoft's patch was released, Chaotic Eclipse published a proof-of-concept exploit for RoguePlanet that was reportedly tested on fully updated Windows 10 and Windows 11 systems running the June 2026 Patch Tuesday updates.
In mid-June 2026, Microsoft acknowledged the RoguePlanet zero-day and said it was developing a security update for the flaw.
Chaotic Eclipse first disclosed CVE-2026-50656, also called RoguePlanet, in June 2026 as a Microsoft Defender privilege escalation issue in the Microsoft Malware Protection Engine.
At the end of May 2026, Microsoft's Security Response Center said several public zero-day dumps were irresponsible, specifically naming RedSun, UnDefend, BlueHammer, YellowKey, GreenPlasma, and MiniPlasma as not responsibly disclosed.
In May 2026, Chaotic Eclipse disclosed two Windows zero-days: YellowKey, affecting BitLocker, and GreenPlasma, affecting the Windows Collaborative Translation Framework (CTFMON).
Microsoft said it was aware of the report that its defense-in-depth updates for CVE-2026-50656 could cause Microsoft Defender to leak 8 bytes of data when opening a file in certain scenarios and that it was investigating.
Chaotic Eclipse released a proof-of-concept exploit named ShieldBreak, claiming it fully bypasses Microsoft's patch for RoguePlanet (CVE-2026-50656) and works reliably on Windows 11 25H2 and Windows Server 2025.
CISA added the actively exploited Windows Ancillary Function Driver for WinSock flaw CVE-2026-68820 to its Known Exploited Vulnerabilities catalog and ordered federal agencies to remediate it.
Microsoft shipped patches for 421 security flaws, including fixes for LegacyHive (CVE-2026-62832), the actively exploited WinSock zero-day CVE-2026-68820, and the publicly disclosed container isolation flaw CVE-2026-72971.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
40 references tracked. Mallory keeps watching after this page renders.
meetcyber.net
Open sourcemalware.news
Open sourcemalwarebytes.com
Open sourcebleepingcomputer.com
Open sourcegithub.com
Open sourceblog.projectnightcrawler.dev
Open sourcegit.projectnightcrawler.dev
Open sourcegmcsirt.gm
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.