Microsoft it is working on a new security patch to address a critical zero-day vulnerability in Microsoft Defender, codenamed “RoguePlanet.” The case has sparked intense interest in the cybersecurity community, as the vulnerability could be exploited by attackers to gain elevated privileges on Windows systems.
RoguePlanet: Vulnerability Profile and Risk Score
The vulnerability, identified as CVE-2026-50656 , carries a CVSS score of 7.8/10, making it a high severity vulnerability. According to Microsoft, it is a escalation that affects Microsoft Defender's Microsoft Malware Protection Engine.
The company stated that it has already begun the necessary development and testing processes, with the aim of releasing a quality security update that will effectively address the problem without affecting the stability of the systems.
See also: RοguePlanet Zero-Day: New Microsoft Defender vulnerability gives SYSTEM access

How RoguePlanet works
RoguePlanet was discovered about a week ago by security researcher Chaotic Eclipse, also known as Nightmare-Eclipse. He described the exploit as a “race condition,” a condition in which different processes attempt to access a system resource, creating unpredictable situations.
By exploiting this vulnerability, attackers can gain access to a command shell with SYSTEM, the highest level of privileges in Windows. This capability is considered particularly dangerous, as it essentially provides complete control over the computer.
Inconsistent behavior but serious risk
Chaotic Eclipse emphasized that the exploit does not work the same way on all systems. He said that on some devices it achieved a 100% success rate, while on others the vulnerability proved to be particularly difficult to exploit.
This differentiation does not diminish the seriousness of the issue. In the cybersecurity space, even an exploit with limited reliability can pose a significant threat, especially when cybercriminals have the ability to improve or adapt its code for different environments.
See also: RedSun Zero-Day: New Microsoft Defender vulnerability

Independent of real-time protection
In his latest update, the researcher revealed another worrying element: the RoguePlanet proof-of-concept appears to work regardless of whether Defender's real-time protection is enabled or not.
This observation raises new questions about the architecture of Microsoft's protection mechanism. If it is confirmed that the vulnerability can be exploited even in passive mode environments, organizations may need to temporarily reconsider some of their defense strategies until the official update is available.
Microsoft's response and the broader context
Microsoft had already stated last week that it was aware of the reports and was investigating the validity of the claims and the potential extent of the vulnerability's impact. The official confirmation of the patch deployment shows that the company considers the incident serious enough to require immediate intervention.
See also: Windows Alert: Zero-day Exploit in Microsoft Defender – Update

RoguePlanet is the fourth Microsoft Defender vulnerability disclosed by Chaotic Eclipse, following BlueHammer (CVE-2026-33825), UnDefend (CVE-2026-45498), and RedSun (CVE-2026-41091), which have already been patched via security updates.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
The recurring emergence of vulnerabilities in Defender highlights the challenges faced by even the most advanced security platforms. Despite significant investments in detection and protection technologies, the constant search for new exploitation techniques by researchers and attackers turns cybersecurity into a constant race between defense and offense.
