The Circuitry
THE CIRCUITRYYour one-stop source for all tech news
HOMETODAYNEWSFEEDEVENTS
BOOKMARKS
RSS
© 2026 The Circuitry
About UsSourcesContactCorrectionsPrivacy
  • Today
  • Feed
  • Events
  • Saved
Scroll for more
Verification
VERIFIEDConfidence: HIGH
Source identified
Claims cross-referenced
No discrepancies found
Fact-check summary

BleepingComputer and other outlets confirm Microsoft patched the RoguePlanet Defender zero-day (CVE-2026-50656) via out-of-band Malware Protection Engine update on July 9.

Sourcing
1source

via The Register

The Register · track record
14Stories
100%Verified
1430d
All sources →
Markets
MSFT···

Live quote · not investment advice

Home/Tech/Microsoft patches Nightmare Eclipse's RoguePlanet Defender zero-day
VERIFIEDBy Xavier Rivera· ·1.5 min read

Microsoft patches Nightmare Eclipse's RoguePlanet Defender zero-day

Microsoft has fixed the RoguePlanet zero-day in Defender via an update to the Malware Protection Engine. The patch closes the latest vulnerability publicly disclosed by researcher Nightmare Eclipse, who has sparred with the company over its handling of bug reports all year.

Source:The Register
Post
Microsoft patches Nightmare Eclipse's RoguePlanet Defender zero-day
TL;DRAI · 60 sec read

Microsoft fixed the RoguePlanet zero-day in Microsoft Defender after Nightmare Eclipse published exploit code for CVE-2026-50656. The patch arrived outside Patch Tuesday and requires the latest Malware Protection Engine. It closes the researcher's seventh public zero-day disclosure amid disputes over Microsoft's vulnerability handling.

Microsoft has fixed the RoguePlanet zero-day vulnerability in Microsoft Defender, weeks after security researcher Nightmare Eclipse published exploit code for the flaw.

Microsoft addressed the bug outside its regular Patch Tuesday cycle. The company updated the Microsoft Malware Protection Engine to resolve CVE-2026-50656. Customers must run the latest engine version to receive the protection.
Microsoft addressed the bug outside its regular Patch Tuesday cycle.
The vulnerability first appeared in June when Nightmare Eclipse released technical details and a proof-of-concept exploit. The researcher claimed RoguePlanet could spawn a command prompt with SYSTEM privileges on fully patched Windows 10 and Windows 11 systems by exploiting a race condition in Defender.

The exploit's success depended on precise timing. Nightmare Eclipse described it as a race condition that delivered a 100 percent success rate on some machines but struggled on others. The bug reportedly worked whether or not Defender's real-time protection was enabled.
From The CircuitryThe Feed — live briefs across tech, all day.See what’s happening →
When The Register first reported on RoguePlanet in June, Microsoft said only that it was investigating the claims. The company has now completed that probe and issued the fix but has not explained the technical changes or confirmed any real-world exploitation beyond the published proof-of-concept.
RoguePlanet marks the seventh zero-day publicly disclosed by Nightmare Eclipse since April.
RoguePlanet marks the seventh zero-day publicly disclosed by Nightmare Eclipse since April. The researcher, who claims to be a former Microsoft employee, has conducted an increasingly acrimonious campaign against the company's vulnerability disclosure and bug bounty programs. Nightmare Eclipse has accused Microsoft of ignoring reports, deleting submission accounts, and treating independent researchers with contempt.

Microsoft initially warned that publishing exploit code could carry legal consequences. Security researchers pushed back, prompting the company to clarify it had no intention of pursuing action against legitimate security research. The researcher also alleged that Microsoft removed RoguePlanet proof-of-concept repositories from GitHub and GitLab before the code moved to a self-hosted location.
With the patch for CVE-2026-50656 now live, Microsoft has closed every public zero-day disclosed by Nightmare Eclipse earlier this year.

EXPERT TAKE

The quiet engine update rather than a Patch Tuesday release suggests Microsoft treated the race condition as a targeted Defender fix, though the lack of technical detail leaves defenders without clear guidance on detection or mitigation steps.

Why this mattersAI · ~100 words

Tap a lens to see what this story means for you.

Reader-supported
DonateBuy me a coffee →Follow@thecircuitry_ →Follow@thecircuitry.to →

Reader-supported · Daily Brief

Daily brief at 7 AM ET. Top tech stories, every morning. Sourced and fact-checked.

HELP US IMPROVE
From The Circuitry

See what’s happening right now

The Feed runs all day — short, verified briefs the moment they break.

Open the Feed →
From The Circuitry

Follow @thecircuitry_

Every story we publish, as it happens. No noise between.

Follow on X ↗On Bluesky ↗

Reader-supported

The Circuitry is a passion project I've always wanted to build, and I love the work behind it.

Running it costs real money. APIs, hosting, time. To keep improving the site and growing this into something useful for everyone, those costs have to be covered.

Any contribution is appreciated. If not, no pressure. Thanks for reading.

Buy me a coffee
MicrosoftSecurityZero-DayVulnerability
More fromThe Register
  • Philips to replace bricked Hue Bridge Pro devices

    Tech · 2d
  • Microsoft tells Windows 10 holdouts they can keep using their PCs until 2027

    Tech · 2d
  • SAP ends EU antitrust probe by dropping legacy support fees

    Tech · 6d
More inTech
  • China's CXMT Doubles IPO Target to $8.55 Billion

    Tech · 17m
  • CISA Adds KNX Protocol CVE-2023-4346 to KEV Catalog

    Tech · 4h
  • Report: OnePlus to Pull Out of US and Europe

    Tech · 4h
SupportThe Work

The Circuitry is reader-supported. If you find the daily brief useful, you can buy me a coffee to keep it going.

Buy a coffee →
SubscribeCircuitry Brief

Daily brief at 7 AM ET. Top tech stories, every morning.

MORE IN TECH

China's CXMT Doubles IPO Target to $8.55 Billion

ChangXin Memory Technologies expects to raise 57.9 billion yuan ($8.55 billion) in its Shanghai STAR Market IPO after doubling its original target. The world's fourth-largest DRAM chipmaker will list on July 27, advancing China's push for semiconductor self-reliance.

CISA Adds KNX Protocol CVE-2023-4346 to KEV Catalog

CISA added CVE-2023-4346 affecting KNX Association KNX Protocol Connection Authorization Option 1 to its Known Exploited Vulnerabilities catalog on 2026-07-15. Federal agencies must finish remediation by 2026-07-29. The overly restrictive account lockout mechanism could let attackers purge devices and set a BCU key when extra security options remain disabled, so organizations must apply vendor mitigations under BOD 26-04.

Report: OnePlus to Pull Out of US and Europe

Bloomberg reports that OnePlus will exit the U.S. and European smartphone markets as part of restructuring at owner Oppo, with the move possibly starting as soon as this week. The brand's earlier popularity has faded while Chinese suppliers face mounting pressure from memory chip costs and declining shipments in key regions.