Security News New Windows Defender 0-Day Exploit “RoguePlanet” Grants SYSTEM Access to Attackers

Nightmare-Eclipse Drops ShieldBreak Windows Defender 0-day Vulnerability

The prolific and controversial security researcher known as Nightmare-Eclipse (also tracked under the alias Chaotic Eclipse) has released a ninth Windows zero-day exploit called ShieldBreak, and this time the target is Microsoft’s own fix.

ShieldBreak demonstrates a complete bypass of the patch Microsoft shipped for RoguePlanet, the Windows Defender elevation-of-privilege flaw tracked as CVE-2026-50656, proving that the underlying weakness in the Microsoft Malware Protection Engine was never fully closed.

RoguePlanet was originally disclosed as a race condition in mpengine.dll, the core scanning engine behind Windows Defender, that let a local attacker win a narrow check-then-act timing window during a file scan and redirect it into a command shell running as NT AUTHORITY\SYSTEM.

Microsoft eventually acknowledged the bug, rated it “Exploitation More Likely” with a CVSS score of 7.8, and remediated it in Malware Protection Engine version 1.1.26060.3008 during its July 2026 patch cycle.