All incidents

Microsoft patches Windows Defender zero‑day elevation of privilege flaw (CVE-2026-50656)

incidentopenJun 17, 2026 — Jul 9, 2026
Microsoft patches Windows Defender zero‑day elevation of privilege flaw (CVE-2026-50656)

MICROSOFT has released an emergency update for Windows Defender that fixes a zero‑day elevation of privilege flaw tracked as CVE-2026-50656. The vulnerability, nicknamed RoguePlanet, was disclosed by security researcher Nightmare‑Eclipse and carries a CVSS score of 7.8. The patch was issued ahead of the regular Patch Tuesday cycle because of the elevated risk it poses to Windows 10 and 11 systems.

The flaw resides in the Microsoft Malware Protection Engine and is caused by a race condition that can be triggered when real‑time protection is disabled. An attacker with standard user privileges can exploit it by delivering a specially crafted file through a configured SMB server, which then allows the engine to execute code with SYSTEM privileges. Versions of the engine older than 1.1.26060.3008 are affected. The exploit leverages a temporary file creation routine that the engine mishandles, allowing arbitrary code to run with elevated rights.

Microsoft’s update raises the engine to version 1.1.26060.3008 and adds hardening measures to close the race condition. Although no confirmed instances of wild exploitation have been reported, a public proof of concept exists that demonstrates the privilege escalation. The disclosure continues a pattern of friction between Nightmare‑Eclipse and Microsoft, with the researcher having previously published other Defender flaws. The update is distributed automatically via Windows Update, but enterprises can also push it through WSUS or Configuration Manager for immediate enforcement.

Previous vulnerabilities credited to Nightmare‑Eclipse have been seen used in attacks, raising concerns that RoguePlanet could follow a similar path if not mitigated. Security observers note that the early release of exploit code limited the window for defenders to apply fixes before potential abuse. Nightmare‑Eclipse has previously disclosed three other Defender vulnerabilities, two of which were later observed in ransomware campaigns. The incident underscores the challenge of managing zero‑day risks when researchers choose to publish details before a vendor patch is ready.

Defenders should verify that the Microsoft Malware Protection Engine on all endpoints is at version 1.1.26060.3008 or newer, which can be checked through the Windows Security app or via PowerShell. Keeping real‑time protection enabled reduces the attack surface, as the race condition requires the feature to be turned off. Monitoring for anomalous SMB file writes and unexpected privilege escalation events in security logs is also recommended. Administrators can query the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Microsoft Antimalware\Signature\EngineVersion to confirm the exact build in use.

Applying the update through Windows Update or WSUS will push the patched engine to managed machines; administrators should confirm successful deployment before closing the ticket. Maintaining layered defences, such as limiting SMB exposure and employing least‑privilege accounts, further reduces the chance of abuse. It is advisable to test the patch on a small group of systems first to ensure compatibility with any third‑party security tools that may interface with the engine. No additional actions are required beyond staying current with the monthly security baseline.

Intelligence briefing updated Jul 9, 2026

CVE-2026-50656 7.8
Root sourcemsrc.microsoft.com
Timeline Coverage

Swipe to explore timeline