Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4355 articles · 196337 vulns · 36/41 feeds (7d)
← Back to list
7.8
CVE-2026-50656EXPLOITEDPATCHED
microsoft · malware_protection_engine

Microsoft Defender Elevation of Privilege Vulnerability

Description

Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RoguePlanet ".

Affected Products

VendorProductVersions
microsoftmalware_protection_engine1.1.0.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
microsoftmicrosoft defendercert_advisory90%
microsoftmicrosoft malware protectioncert_advisory90%

References

  • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50656(vendor-advisory, patch)

Related News (22 articles)

Tier C
Qualys Blog3d ago
ShieldBreak: The Windows Defender Zero-Day With No Patch — Detect It, Mitigate It, With Qualys
→ No new info (linked only)
Tier D
CSO Online11d ago
Researcher creates workaround for Microsoft Defender security patch
→ No new info (linked only)
Tier D
CSO Online11d ago
Researcher bypasses Microsoft Defender security patch, seizing control
→ No new info (linked only)
Tier E
Hacker News11d ago
RoguePlanet Vulnerability Still Exploitable
→ No new info (linked only)
Tier D
BleepingComputer11d ago
New Microsoft Defender 'ShieldBreak' zero-day grants SYSTEM privileges
→ No new info (linked only)
Tier D
Heise Security12d ago
Patchday: Angreifer attackieren Windows und verschaffen sich System-Rechte
→ No new info (linked only)
Tier D
The Hacker News12d ago
ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access
→ No new info (linked only)
Tier C
Rapid7 Blog40d ago
Patch Tuesday - July 2026
→ No new info (linked only)
Tier D
Help Net Security45d ago
July 2026 Patch Tuesday forecast: Is CVE tracking still practical?
→ No new info (linked only)
Tier D
Ars Technica Security45d ago
Patch for Windows Defender 0-day could allow attackers to fill hard disk
→ No new info (linked only)
Tier D
Help Net Security45d ago
Microsoft releases fix for RoguePlanet Defender flaw (CVE-2026-50656)
→ No new info (linked only)
Tier D
SecurityWeek45d ago
Microsoft Patches Defender ‘RoguePlanet’ Vulnerability
→ No new info (linked only)
Tier D
The Hacker News45d ago
Microsoft Patches RoguePlanet Defender Flaw That Can Grant SYSTEM Privileges
→ No new info (linked only)
Tier D
BleepingComputer46d ago
Microsoft patches RoguePlanet Defender zero-day vulnerability
→ No new info (linked only)
Tier D
The Hacker News67d ago
Microsoft Confirms RoguePlanet Defender Zero-Day, Says Patch is in Development
→ No new info (linked only)
Tier B
CCCS Canada67d ago
Microsoft security advisory (AV26-607)
→ No new info (linked only)
Tier D
Help Net Security67d ago
Microsoft working on patch for RoguePlanet Defender zero-day (CVE-2026-50656)
→ No new info (linked only)
Tier B
BSI Advisories67d ago
[NEU] [UNGEPATCHT] [hoch] Microsoft Malware Protection Engine: Schwachstelle ermöglicht Privilegieneskalation
→ No new info (linked only)
Tier D
SecurityWeek67d ago
Microsoft Working on Patch for ‘RoguePlanet’ Zero-Day
→ No new info (linked only)
Tier D
BleepingComputer67d ago
Microsoft working on Defender patch for RoguePlanet zero-day
→ No new info (linked only)
Tier C
VulDB68d ago
CVE-2026-50656 | Microsoft Malware Protection Engine link following
→ No new info (linked only)
Tier A
Microsoft MSRC68d ago
CVE-2026-50656 Microsoft Defender Elevation of Privilege Vulnerability
→ No new info (linked only)
CVSS 3.17.8 HIGH
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:U/RC:C
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50656
CWECWE-59
PublishedJun 16, 2026
Last enriched44d agov9
Tags
RoguePlanetNightmare EclipseChaotic Eclipse
Trending Score59
Source articles22
Independent14
Info Completeness10/14
Missing: epss, kev, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-69836EXPKEV
Microsoft Entra ID Remote Code Execution Vulnerability
Trending: 127
CRITICALCVE-2026-55040EXPKEV
Microsoft SharePoint Server Security Feature Bypass Vulnerability
Trending: 86
CRITICALCVE-2026-50522EXPKEV
Microsoft SharePoint Remote Code Execution Vulnerability
Trending: 78
HIGHCVE-2026-68820EXPKEV
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Trending: 72
HIGHCVE-2026-45586EXPKEV
Windows Collaborative Translation Framework (CTFMON) Elevation of Privilege Vulnerability
Trending: 64

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 16, 2026
Discovered by ZDM
Jun 16, 2026
Updated: description, exploitAvailable, activelyExploited, tags
Jun 16, 2026
Updated: affectedVersions, tags
Jun 17, 2026
Updated: description, cweIds
Jun 17, 2026
Updated: affectedVersions
Jul 9, 2026
Updated: description, tags
Jul 9, 2026
Updated: description, affectedVersions
Jul 9, 2026
Updated: description
Jul 9, 2026
Updated: description, affectedVersions
Jul 10, 2026
Actively Exploited
Aug 14, 2026
Exploit Available
Aug 14, 2026
Patch Available
Aug 14, 2026

Version History

v9
Last enriched 44d ago
v9Tier D44d ago

Updated description with technical details about the RoguePlanet vulnerability and added Windows 11 26H2 as an affected version.

descriptionaffectedVersions
via Help Net Security
v8Tier D45d ago

Updated description with new technical details and changed severity from HIGH to CRITICAL.

description
via Ars Technica Security
v7Tier D45d ago

Updated description with technical details about improper link resolution and added affected versions for Windows 10 and Windows 11.

descriptionaffectedVersions
via Help Net Security
v6Tier D45d ago

Updated description with technical details about the vulnerability and added new tag 'Chaotic Eclipse'.

descriptiontags
via SecurityWeek
v5Tier D46d ago

Updated affected versions to include 1.1.26060.3008 and specified the patch available version.

affectedVersions
via BleepingComputer
v4Tier D67d ago

Updated description with technical details about the vulnerability and added CWE-22.

descriptioncweIds
via Help Net Security
v3Tier D67d ago

Added affected versions for Windows 10 and Windows 11, provided a more detailed description of the vulnerability, and included a new tag 'Nightmare Eclipse'.

affectedVersionstags
via BleepingComputer
v2Tier A68d ago

Added a description detailing the vulnerability as 'RoguePlanet', marked exploit availability and active exploitation as true, and added a new tag.

descriptionexploitAvailableactivelyExploitedtags
via Microsoft MSRC
v168d ago

Initial creation