The newly disclosed Windows Defender flaw, tracked as CVE-2026-50656, could let attackers escalate privileges on fully updated Windows 11 systems, while Microsoft says a patch is still being developed.
If you use Windows Defender as your primary antivirus, Microsoft's latest security advisory is worth paying attention to.
The company has confirmed a vulnerability, tracked as CVE-2026-50656, that could allow someone with access to a standard Windows account to gain full SYSTEM-level privileges on a fully updated Windows 11 computer. Microsoft has acknowledged the issue, classified exploitation as "more likely," and says a fix is under development. No release date has been announced.
The disclosure comes as security researchers warn that this is not an isolated Defender bug but part of a pattern that has repeatedly left Windows users waiting for patches while working exploits circulate publicly.
How the vulnerability worksResearchers have nicknamed the exploit RoguePlanet.
According to ThreatLocker and Cyderes, which independently reproduced the flaw, RoguePlanet exploits a race condition inside Microsoft Defender's file-scanning and quarantine process.
Normally, Defender removes suspicious files using SYSTEM privileges. The exploit manipulates that process so Defender performs privileged actions on attacker-controlled files instead, allowing an ordinary user account to obtain administrator-level access.
Researchers said the attack succeeds even when Defender's real-time protection is disabled, meaning simply changing antivirus settings does not reduce the risk.
Microsoft has not reported active exploitation but has rated the vulnerability as more likely to be exploited.
Why researchers say this isn't just another bugThe Defender flaw is the seventh publicly disclosed zero-day and the fourth targeting Microsoft Defender released by the online researcher known as Nightmare Eclipse.
Investigations by Brian Krebs and The Register identified the individual behind the pseudonym as a former Microsoft security engineer who worked at the company between September 2022 and June 2025. Microsoft has not publicly confirmed that identification. Security researchers have also noted another recurring pattern.
For three consecutive months, new zero-days from the same researcher have appeared within hours of Microsoft's monthly Patch Tuesday updates, creating fresh exposure immediately after customers install security fixes.
The researcher has publicly described the campaign as retaliation over Microsoft's handling of vulnerability disclosures and its bug bounty programme.
Microsoft's Security Response Center has accused the researcher of irresponsible disclosure, while reports indicate the company also raised the possibility of legal action. The researcher has since been removed from GitHub and GitLab but continues publishing through independently hosted websites.
Security experts remain dividedThe campaign has sparked debate across the cybersecurity community.
Dustin Childs of Trend Micro's Zero Day Initiative has argued that Microsoft's vulnerability response process contributed to the ongoing dispute by creating frustration among researchers.
Other security firms take a different view.
Barracuda and several incident-response teams have described Nightmare Eclipse as a malicious actor rather than a conventional security researcher, noting that earlier Defender exploits including BlueHammer, RedSun and UnDefend were later used in real-world attacks before Microsoft released patches.
That history makes RoguePlanet more significant than a single software flaw.
Three of the previous Defender vulnerabilities disclosed by the same researcher were reportedly exploited before fixes became available, suggesting organizations may face another period where publicly available exploit code exists before Microsoft's patch arrives.
What Windows users should doUntil Microsoft releases an update, security experts recommend reducing exposure rather than relying on Defender alone.
That includes installing Microsoft's security update as soon as it becomes available, maintaining offline or cloud backups of important files, avoiding unknown executables and suspicious downloads, and using multiple security controls rather than depending exclusively on a single antivirus product.
For businesses, monitoring systems for unusual privilege-escalation activity becomes particularly important while no patch exists.
A bigger question for MicrosoftRoguePlanet is more than another Windows vulnerability. It highlights an increasingly public dispute between Microsoft and a former insider who continues to disclose Defender weaknesses on a regular schedule.
Whether that pattern reflects shortcomings in Microsoft's vulnerability disclosure process, the actions of a malicious researcher, or both remains disputed.
What is clear is that Windows users have now experienced several consecutive Patch Tuesday cycles in which new Defender vulnerabilities emerged almost immediately after Microsoft's monthly fixes. Until that pattern changes or Microsoft shortens the time between disclosure and patch, organizations are likely to face recurring periods where fully updated systems remain exposed despite having installed the latest security updates.
| # | Наименование новости | Тональность | Информативность | Дата публикации |
|---|---|---|---|---|
| 1 | В Windows 10 и 11 выявили уязвимость компонента, отвечающего за VPN-соединение | 0 | 0 | 25-07-2025 |
| 2 | Microsoft: не стоит откладывать апдейты Windows 11 больше чем на ... | 0 | 5 | 16-07-2026 |
| 3 | В серверных и десктопных Windows нашли очередную уязвимость | 0 | 0 | 13-08-2025 |
| 4 | SUSE Python-Lxml Moderate Local File Read Threat Update 2026-2728-1 | 0 | 5 | 03-07-2026 |
| 5 | Recent patches for Windows 11 could have been created by Microsoft's new Mythos rival | 2 | 6 | 17-07-2026 |
| 6 | SUSE 2026-2731-1 editorconfig-core-c Moderate Stack Overflow Threat | 0 | 5 | 03-07-2026 |
| 7 | Microsoft confirms Windows 11 26H2 is another boring update that does nothing — but here's why I'm happy about that | 1 | 3 | 22-06-2026 |
| 8 | Microsoft дала пользователям Windows 10 ещё один «безопасный» год | 0 | 5 | 27-06-2026 |
| 9 | Microsoft confirms WSUS service degradation impacting all versions of Windows | -2 | 6 | 18-07-2026 |
| 10 | New GitHub Zero-Day Exposed Developer Tokens to Attackers | -5 | 7 | 04-06-2026 |