CVE-2026-50656Patch(microsoft / malware_protection_engine)

CRITICALCVSS 7.0 · HIGH

Exploitation observed; activity peaked at 29 mentions and remains active

Immediate actions

  • Patch microsoft malware_protection_engine systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RoguePlanet ".

8.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-59

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • malware_protection_engine

Threat summary

  • Active exploitation appears in 15 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 188 mentions across 40 observed days

What's happening

  • Active exploitation reported across 15 signals
  • Exploit tool or code specified in 25 signals
  • PoC mentioned or linked in 67 signals
  • Patch or workaround mentioned in 121 signals
  • Technical details provided in 115 signals
  • Disclosure: 37 classified signals
  • Peaked 27d ago at 29 mentions (2026-07-09); latest day: 1
  • 188 total mentions across 40 days

Affected systems

Vendors
Products
malware_protection_engine

1 version affected across 1 product

Deep dive

Activity timeline188 mentions / 40d
07152229Mentions · 2026-06-16: 3Mentions · 2026-06-17: 20Mentions · 2026-06-18: 20Mentions · 2026-06-19: 10Mentions · 2026-06-20: 3Mentions · 2026-06-22: 1Mentions · 2026-06-23: 1Mentions · 2026-06-24: 2Mentions · 2026-06-25: 1Mentions · 2026-07-01: 1Mentions · 2026-07-05: 3Mentions · 2026-07-07: 2Mentions · 2026-07-09: 29Mentions · 2026-07-10: 16Mentions · 2026-07-11: 3Mentions · 2026-07-12: 3Mentions · 2026-07-13: 4Mentions · 2026-07-14: 3Mentions · 2026-07-15: 2Mentions · 2026-07-16: 1Mentions · 2026-07-19: 1Mentions · 2026-07-28: 1Mentions · 2026-07-30: 1Mentions · 2026-08-02: 1Mentions · 2026-08-05: 1Mentions · 2026-08-11: 3Mentions · 2026-08-12: 20Mentions · 2026-08-13: 12Mentions · 2026-08-14: 6Mentions · 2026-08-15: 1Mentions · 2026-08-16: 1Mentions · 2026-08-17: 3Mentions · 2026-08-25: 1Mentions · 2026-08-26: 1Mentions · 2026-09-01: 1Mentions · 2026-09-02: 1Mentions · 2026-09-03: 1Mentions · 2026-09-04: 1Mentions · 2026-09-09: 2Mentions · 2026-09-11: 1PoC Mentioned / Linked · 2026-06-17: 10PoC Mentioned / Linked · 2026-06-18: 4PoC Mentioned / Linked · 2026-06-19: 4PoC Mentioned / Linked · 2026-06-20: 1PoC Mentioned / Linked · 2026-07-07: 1PoC Mentioned / Linked · 2026-07-09: 6PoC Mentioned / Linked · 2026-07-10: 2PoC Mentioned / Linked · 2026-07-11: 1PoC Mentioned / Linked · 2026-07-12: 2PoC Mentioned / Linked · 2026-07-14: 2PoC Mentioned / Linked · 2026-08-11: 3PoC Mentioned / Linked · 2026-08-12: 14PoC Mentioned / Linked · 2026-08-13: 7PoC Mentioned / Linked · 2026-08-14: 3PoC Mentioned / Linked · 2026-08-15: 1PoC Mentioned / Linked · 2026-08-17: 2PoC Mentioned / Linked · 2026-08-25: 1PoC Mentioned / Linked · 2026-09-01: 1PoC Mentioned / Linked · 2026-09-03: 1PoC Mentioned / Linked · 2026-09-11: 1Exploit Tool / Code · 2026-06-17: 2Exploit Tool / Code · 2026-06-18: 1Exploit Tool / Code · 2026-07-09: 1Exploit Tool / Code · 2026-07-11: 1Exploit Tool / Code · 2026-07-14: 1Exploit Tool / Code · 2026-08-11: 3Exploit Tool / Code · 2026-08-12: 7Exploit Tool / Code · 2026-08-13: 3Exploit Tool / Code · 2026-08-14: 2Exploit Tool / Code · 2026-08-15: 1Exploit Tool / Code · 2026-08-25: 1Exploit Tool / Code · 2026-09-01: 1Exploit Tool / Code · 2026-09-03: 1Active Exploitation · 2026-06-17: 2Active Exploitation · 2026-06-19: 4Active Exploitation · 2026-06-24: 1Active Exploitation · 2026-07-05: 1Active Exploitation · 2026-07-09: 2Active Exploitation · 2026-07-13: 1Active Exploitation · 2026-07-15: 1Active Exploitation · 2026-08-13: 2Active Exploitation · 2026-09-11: 1Patch / Workaround · 2026-06-16: 3Patch / Workaround · 2026-06-17: 13Patch / Workaround · 2026-06-18: 16Patch / Workaround · 2026-06-19: 5Patch / Workaround · 2026-06-20: 1Patch / Workaround · 2026-06-22: 1Patch / Workaround · 2026-06-23: 1Patch / Workaround · 2026-06-24: 1Patch / Workaround · 2026-06-25: 1Patch / Workaround · 2026-07-01: 1Patch / Workaround · 2026-07-05: 2Patch / Workaround · 2026-07-07: 1Patch / Workaround · 2026-07-09: 26Patch / Workaround · 2026-07-10: 14Patch / Workaround · 2026-07-11: 3Patch / Workaround · 2026-07-12: 3Patch / Workaround · 2026-07-13: 2Patch / Workaround · 2026-07-14: 3Patch / Workaround · 2026-07-15: 1Patch / Workaround · 2026-07-28: 1Patch / Workaround · 2026-07-30: 1Patch / Workaround · 2026-08-02: 1Patch / Workaround · 2026-08-05: 1Patch / Workaround · 2026-08-12: 7Patch / Workaround · 2026-08-13: 5Patch / Workaround · 2026-08-14: 2Patch / Workaround · 2026-08-26: 1Patch / Workaround · 2026-09-01: 1Patch / Workaround · 2026-09-09: 2Patch / Workaround · 2026-09-11: 1Technical Details · 2026-06-16: 2Technical Details · 2026-06-17: 14Technical Details · 2026-06-18: 12Technical Details · 2026-06-19: 7Technical Details · 2026-06-20: 2Technical Details · 2026-06-22: 1Technical Details · 2026-06-24: 2Technical Details · 2026-06-25: 1Technical Details · 2026-07-01: 1Technical Details · 2026-07-05: 2Technical Details · 2026-07-07: 1Technical Details · 2026-07-09: 19Technical Details · 2026-07-10: 11Technical Details · 2026-07-11: 3Technical Details · 2026-07-12: 3Technical Details · 2026-07-13: 3Technical Details · 2026-07-14: 2Technical Details · 2026-07-15: 1Technical Details · 2026-07-16: 1Technical Details · 2026-08-05: 1Technical Details · 2026-08-12: 11Technical Details · 2026-08-13: 5Technical Details · 2026-08-14: 4Technical Details · 2026-08-15: 1Technical Details · 2026-08-16: 1Technical Details · 2026-09-02: 1Technical Details · 2026-09-03: 1Technical Details · 2026-09-09: 1Technical Details · 2026-09-11: 106-1606-2006-2507-0907-1307-1908-0508-1408-2509-0309-11
Signal classification6 categories
Patch
8444.7%
Disclosure
3719.7%
PoC
3518.6%
Active Exploitation
126.4%
Exploit
105.3%
General
105.3%
Referenced assets114 URLs
By indicator
Classification over time
DateTotalLabels
2026-06-163
Disclosure1Patch2
2026-06-1720
Active Exploitation2Disclosure5Exploit1General1Patch7PoC4
2026-06-1820
Disclosure7General1Patch9PoC3
2026-06-1910
Active Exploitation4Disclosure4Patch2
2026-06-203
General1Patch1PoC1
2026-06-221
Patch1
2026-06-231
Patch1
2026-06-242
Active Exploitation1Disclosure1
2026-06-251
Disclosure1
2026-07-011
Disclosure1
2026-07-053
Active Exploitation1Disclosure1Patch1
2026-07-072
Disclosure1PoC1
2026-07-0929
Active Exploitation2Disclosure2General1Patch24
2026-07-1016
Disclosure2Exploit1General1Patch12
2026-07-113
Patch3
2026-07-123
Patch3
2026-07-134
Disclosure1General1Patch2
2026-07-143
Patch3
2026-07-152
Exploit1Patch1
2026-07-161
Disclosure1
2026-07-191
General1
2026-07-281
Patch1
2026-07-301
Patch1
2026-08-021
Patch1
2026-08-051
Patch1
2026-08-113
PoC3
2026-08-1220
Disclosure4Exploit3Patch2PoC11
2026-08-1312
Active Exploitation1Disclosure2Exploit1Patch3PoC5
2026-08-146
Disclosure2Exploit1PoC3
2026-08-151
PoC1
2026-08-161
General1
2026-08-173
General1PoC2
2026-08-251
PoC1
2026-08-261
Patch1
2026-09-011
Exploit1
2026-09-021
Disclosure1
2026-09-031
Exploit1
2026-09-041
General1
2026-09-092
Patch2
2026-09-111
Active Exploitation1
Full discourse20 posts
  • INFINITE NIGHTMARE@MSNightmare2000
    PoC

    Microsoft has failed to properly patch RoguePlanet (CVE-2026-50656), ShieldBreak, a PoC that demonstrates a full bypass to the previous patch is now public. https://github.com/MSNightmare/ShieldBreak The PoC works with the latest August 2026 patch

    Post summary

    A public PoC, ShieldBreak, demonstrates a complete bypass of Microsoft's August 2026 patch for CVE‑2026‑50656, but no evidence of active exploitation or vendor remediation is reported.

    36341311.8K673204.2K
    20.0K followersView on X
  • International Cyber Digest@IntCyberDigest
    Exploit

    ‼️ Microsoft's July patch for the RoguePlanet local privilege escalation Defender flaw (CVE-2026-50656) has been bypassed. Nightmare Eclipse published exploit code called ShieldBreak on GitHub, hours after August Patch Tuesday. The researcher claims a 100% success rate on fully patched Windows 11 25H2 and Server 2025, where RoguePlanet's race condition was hit-or-miss. The vulnerability makes it possible for any local user to get SYSTEM. No fix yet.

    Post summary

    Microsoft’s July patch for CVE‑2026‑50656 is reportedly bypassed; researcher Nightmare Eclipse released the ShieldBreak exploit on GitHub, claiming 100 % success on fully patched Windows 11 25H2 and Server 2025, exposing a local privilege escalation race condition with no fix yet.

    36145171.4K35260.7K
    225.0K followersView on X
  • Dark Web Informer@DarkWebInformer
    PoC

    🚨Nightmare Eclipse has released a new zero-day PoC called ShieldBreak Per the security researcher: "Microsoft has failed to properly patch the RoguePlanet vulnerability CVE-2026-50656, this PoC demonstrates a full patch bypass." GitHub: https://github.com/MSNightmare/ShieldBreak https://t.co/TguW17Negh

    Post summary

    Nightmare Eclipse released a PoC ‘ShieldBreak’ that bypasses the patch for CVE‑2026‑50656, demonstrating a vulnerable loophole but no active exploitation or vendor fix details were shared.

    951232112924.0K
    237.0K followersView on X
  • INFINITE NIGHTMARE@MSNightmare2000
    Patch

    Microsoft issued a security patch for RoguePlanet https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-50656

    Post summary

    Microsoft released a patch to address the CVE-2026-50656 RoguePlanet vulnerability.

    92003404423.6K
    18.8K followersView on X
  • The Hacker News@TheHackersNews
    PoC

    ‼️ Microsoft patched RoguePlanet. Now the researcher has dropped another zero-day that claims to bypass the fix. ShieldBreak is said to fully bypass Defender’s CVE-2026-50656 patch. The underlying flaw can lead to SYSTEM-level privileges. Read more: https://thehackernews.com/2026/08/shieldbreak-zero-day-poc-claims.html https://t.co/uyVTIrG2GG

    Post summary

    The text reports a new zero‑day, ShieldBreak, that allegedly bypasses Microsoft Defender’s CVE‑2026‑50656 patch and could grant SYSTEM‑level privileges; a PoC reference is included via the link.

    37242475938.7K
    2.3M followersView on X
  • The Hacker News@TheHackersNews
    Patch

    🚨 Microsoft Defender zero-day RoguePlanet is now officially CVE-2026-50656. Microsoft is preparing a patch for the Malware Protection Engine flaw, which can enable privilege escalation. A public PoC describes a race condition that may grant SYSTEM-level privileges. Read: https://thehackernews.com/2026/06/microsoft-confirms-rogueplanet-defender_02022423645.html

    Post summary

    Microsoft confirms CVE‑2026‑50656, a privilege‑escalation flaw in Defender, and is preparing a patch, while a public PoC demonstrates the race condition.

    55841724217.6K
    2.2M followersView on X
  • Rıdvan Yağlı@ridvanyagli
    PoC

    🔴 SON DAKİKA !!! Siber güvenlik araştırmacısı Nightmare-Eclipse (MSNightmare / INFINITE NIGHTMARE), Microsoft'un RoguePlanet (CVE-2026-50656) açığı için düzgün bir yama yayınlayamadığını belirterek, önceki yamayı tamamen bypass eden "ShieldBreak" adlı herkese açık bir PoC paylaştı. PoC, iddiaya göre Ağustos 2026 Windows güncellemeleri yüklüyken bile çalışıyor. PoC: https://github.com/MSNightmare/ShieldBreak

    Post summary

    Nightmare‑Eclipse shares the publicly available "ShieldBreak" PoC that bypasses the prior patch for CVE‑2026‑50656, demonstrating the vulnerability remains unpatched.

    07088415.9K
    2.3K followersView on X
  • The Hacker News@TheHackersNews
    Patch

    ⚡ Microsoft patched RoguePlanet weeks after the Defender flaw was publicly disclosed. CVE-2026-50656 affects the #Microsoft Malware Protection Engine and could let local attackers gain SYSTEM-level privileges, according to the researcher who disclosed it. Full story here → https://thehackernews.com/2026/07/microsoft-patches-rogueplanet-defender.html

    Post summary

    Microsoft has issued a patch for CVE-2026-50656, a privilege‑escalation flaw in the Malware Protection Engine that could grant local attackers SYSTEM access.

    3220921322.6K
    2.3M followersView on X
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    PoC

    تذكرون ثغره RoguePlanet في Microsoft Defender اللي تعطي المستخدم المحلي صلاحيات SYSTEM؟ 🚨 نشر Nightmare Eclipse PoC باسم ShieldBreak ويقول إنه يتجاوز إصلاح Microsoft لـ CVE-2026-50656 على Windows 11 وWindows Server 2025 يتبع 👇 https://t.co/Q6BLfEyQ2n

    Post summary

    Nightmare Eclipse released a PoC called ShieldBreak that bypasses Microsoft's fix for CVE-2026-50656 on Windows 11 and Windows Server 2025, enabling local users to gain SYSTEM privileges.

    151322421.5K
    50.2K followersView on X
  • 7h3h4ckv157@7h3h4ckv157
    PoC

    ShieldBreak Windows Defender 0day vulnerability Microsoft has failed to properly patch the RoguePlanet vulnerability CVE-2026-50656, this PoC demonstrates a full patch bypass. Credit/Source: https://github.com/MSNightmare/ShieldBreak https://t.co/VJ6B8MeEqp

    Post summary

    A PoC demonstrating a patch bypass for CVE-2026-50656 is shared via a GitHub repository, with no evidence of active exploitation or mitigation.

    04040162.5K
    56.8K followersView on X
  • Ratan Jyoti@reach2ratan
    Active Exploitation

    🚨 0-DAY ALERT: "ShieldCrash" hits Microsoft Defender Security, researcher Nightmare Eclipse dropped a new zero-day PoC bypassing Microsoft's Sept 2026 patches for ShieldBreak (CVE-2026-69414). The flaw turns Defender's privileged operations against itself, enabling arbitrary file reads as NT AUTHORITY\SYSTEM (and potential SAM dumping / full LPE). Here is what you need to know, how to hunt for it, and actionable mitigations 🧵👇 What is the Breach / Vulnerability? Origin: Direct patch bypass for ShieldBreak (CVE-2026-69414), which itself was a bypass for RoguePlanet (CVE-2026-50656). Mechanism: Exploits a race condition in the Microsoft Malware Protection Engine (MpEngine) during file hydration and scanning via the Windows Cloud Filter API (cfapi.dll) and Object Manager symbolic link manipulation (\BaseNamedObjects\Restricted\). Impact: A local, low-privileged attacker forces Defender to execute privileged file operations on attacker-controlled paths, resulting in arbitrary file reads with SYSTEM access (including the SAM hive) and escalation paths. Scope: Affects all supported Windows 10, Windows 11 (including 25H2), and Windows Server releases running current September builds. How to Detect Compromise 1. File & Directory Artifacts (Default PoC behavior): Look for staging paths created under the system drive: C:\ShieldBreak_* or C:\ShieldCrash_* Creation of temporary sync-root providers registered via CfRegisterSyncRoot (default PoC name: Flubber). 2. Event Log & Process Telemetry: Event ID 1116 / 1117 (Defender Operational Logs): Sudden bursts of EICAR test file detections immediately followed by cleanup failures or locked file warnings. Named Pipe creation: Telemetry spotting pipe names matching \\.\pipe\SHIELDBREAK* or \\.\pipe\SHIELDCRASH*. Object Manager & Symlink Anomalies: Creation of symbolic links pointing from \BaseNamedObjects\ to protected system locations (C:\Windows\System32\...) or UNC loopback shares (\\127.0.0.1\C$). Abnormal System Reads: Low-privileged user processes causing MsMpEng.exe or system background tasks to interact with C:\Windows\System32\config\SAM or SYSTEM hives. Immediate Mitigations Because this is an active zero-day bypass without a vendor-confirmed engine hotfix, apply defense-in-depth controls: Enable Tamper Protection & Cloud-Delivered Protection: Ensure Microsoft Defender Antivirus cloud lookups and Tamper Protection are enforced across all endpoints via Intune/GPO. Restrict Local Administrative & Execution Footprints: Ensure users do not possess unnecessary local rights, and enforce Application Control (WDAC / AppLocker) to prevent running unapproved staging binaries or scripts. Attack Surface Reduction (ASR) Rules: Block executable files from running unless they meet a prevalence, age, or trusted list criterion. Block process creations originating from PSExec, WMI, or Task Scheduler executing untrusted binaries. Endpoint Isolation: If an endpoint flags suspicious Defender race condition attempts or anomalous SAM registry access, isolate the host immediately for forensic capture. Indicators of Compromise (IoCs) Named Pipes: \\.\pipe\SHIELDBREAK, \\.\pipe\SHIELDCRASH Staging Paths: C:\ShieldBreak_*\, C:\ShieldCrash_*\ Observed Bait / Dropper Artifacts: Warden.dll, BERLIN (placeholder), embedded http://eicar.com resources Suspicious Loopback Calls: Target paths invoking \\127.0.0.1\C$\ paired with Alternate Data Streams (:stream) #ShieldCrash #MicrosoftDefender #ZeroDay #CyberSecurity #InfoSec #ThreatIntel #BlueTeam #SOC #PatchTuesday #ThreatHunting #LPE #YARA #IncidentResponse

    Post summary

    An active zero‑day vulnerability (CVE‑2026‑69414) has been disclosed with a PoC; Microsoft Defender is reportedly being hit, and the post provides detection guidance and interim mitigations pending a vendor patch.

    1200236930
    26.9K followersView on X
  • Kruptos@KuptoKosmos
    Disclosure

    ‼️⚠️ DEFENDER CRACKÉ : Zero-Day RoguePlanet donne les clés SYSTEM ! Microsoft confirme un zero-day dans Windows Defender (CVE-2026-50656) Race condition 👉 privilèges SYSTEM. L’exploit est public Le patch n’est pas encore sorti Des millions de machines exposées en ce moment L’antivirus officiel se fait démonter de l’intérieur ! Vérifiez les mises à jour 👀

    Post summary

    The post announces Microsoft’s zero‑day CVE‑2026‑50656, notes a public exploit exists, indicates a race condition for SYSTEM privileges, and mentions that a patch is not yet available.

    3903252.1K
    10.8K followersView on X
  • IRCF | اینترنت آزاد برای همه@ircfspace
    Patch

    مایکروسافت یک آسیب‌پذیری روز صفر در Microsoft Defender با نام RoguePlanet رو برطرف کرده که می‌تونست به مهاجم اجازه بده تا با سوءاستفاده از یک نقص Race Condition، سطح دسترسی خودش رو تا SYSTEM بالا ببره. این مشکل با شناسه CVE-2026-50656 ثبت شده بود و حتی روی ویندوز ۱۰ و ۱۱ کاملاً آپدیت‌شده هم قابل سوءاستفاده بود. © bleepingcomputer

    Post summary

    Microsoft has patched the zero‑day CVE-2026-50656 in Defender, which exploited a race condition to elevate privileges to SYSTEM; the flaw remained exploitable even on fully updated Windows 10 and 11 before the fix.

    0004223.6K
    39.1K followersView on X
  • SoyITPro@SoyITPro
    Patch

    🚨 Microsoft solucionó la vulnerabilidad en Microsoft Defender CVE-2026-50656 (RoguePlanet), una falla de elevación de privilegios en el Malware Protection Engine. Vulnerabilidad descubierta por el "famoso" NightmareEclipse. Aún sigue la guerra 😬 https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-50656

    Post summary

    Microsoft has released a fix for CVE-2026-50656, a privilege‑escalation vulnerability in the Malware Protection Engine of Microsoft Defender.

    1302731.7K
    13.4K followersView on X
  • SOCRadar®@socradar
    Active Exploitation

    The irony of a flaw in your defense tools. 🚨 #RoguePlanet (CVE-2026-50656) gives attackers LPE to SYSTEM via Microsoft Defender's core engine. The patch is live, but public PoC code is already in the wild. Update to engine 1.1.26060.3008+ immediately to mitigate the risk and strengthen your posture. 🔍 Read more: https://hubs.la/Q04p12Ch0 #CyberSecurity #MicrosoftDefender #InfoSec

    Post summary

    CVE-2026-50656 is a local privilege escalation in Microsoft Defender that is already being exploited in the wild; patches are live and users should update immediately.

    1601282.0K
    7.1K followersView on X
  • Alex@xaitax
    Patch

    It seems MS will address this now as CVE-2026-50656 with release for tomorrow but their API already exposes it? https://patchapalooza.com/cve/CVE-2026-50656 https://t.co/5w6bhlMyAe

    Post summary

    The tweet announces that Microsoft plans to release a patch for CVE-2026-50656 tomorrow, but provides no technical details or exploit information.

    130924.4K
    3.3K followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    PoC

    MSNightmare's ShieldBreak PoC claims to fully bypass Microsoft's July patch for CVE-2026-50656, achieving SYSTEM-level privileges on Windows 11 and Server 2025. #ShieldBreak #CVE202650656 #MicrosoftDefender #PrivilegeEscalation #Windows11 https://meterpreter.org/shieldbreak-cve-2026-50656-defender-bypass/

    Post summary

    MSNightmare’s ShieldBreak PoC demonstrates a bypass of Microsoft's July patch for CVE-2026-50656, achieving SYSTEM-level privileges on Windows 11 and Server 2025.

    03162513
    12.9K followersView on X
  • kokumօtօ@__kokumoto
    Disclosure

    【また君か】SYSTEM取得可能なMicrosoft Defenderのゼロデイ脆弱性"ShieldBreak"が開示された。いつものNightmare Eclipse案件。"RoguePlanet" (CVE-2026-50656)の修正回避。完全パッチ適用済みでも刺さる。【壊れるなぁ】

    Post summary

    Microsoft Defender zero‑day "ShieldBreak" (CVE‑2026‑50656) has been disclosed, and the text indicates it can bypass existing patches while enabling SYSTEM privilege escalation.

    230702.0K
    7.8K followersView on X
  • Hack32@Hack32_
    PoC

    The PoC demonstrates a complete patch bypass for CVE-2026-50656 (RoguePlanet). It affects Windows 11 25H2 and Server 2025 with a 100% success rate. 😎 https://github.com/MSNightmare/ShieldBreak

    Post summary

    The text provides a PoC and code repository that bypasses the patch for CVE-2026-50656, detailing the affected systems and success rate, but does not report any real‑world exploitation or vendor patch information.

    010101618
    818 followersView on X
  • سايبركاست@cyberscastx
    Disclosure

    ثغرة Zero-Day في Microsoft Defender تسمح برفع الصلاحيات والسيطرة على أنظمة Windows المحدثة. الثغرة RoguePlanet، اكتشفها الباحث @ChaoticEclipse0، مع PoC من 10 يونيو. اعترفت @Microsoft بالثغرة (CVE-2026-50656)، وتعمل على تصحيح. سبق للباحث نفسه كشف ثغرات سابقة عالجتها الشركة. https://t.co/M7itvZQ8do

    Post summary

    The post announces a newly disclosed CVE-2026-50656 in Microsoft Defender that enables privilege escalation, notes a PoC released, and states Microsoft is addressing the issue with a fix.

    100831.0K
    6.8K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftmalware_protection_engine---

Explore more