Microsoft confirms it is developing a security update for a Microsoft Defender vulnerability publicly disclosed as “RoguePlanet.” Multiple outlets report that the issue is assigned CVE-2026-50656 and has a CVSS score of 7.8. The company acknowledges the public proof-of-concept and says it is working to provide a security update that addresses the vulnerability, with further information to be released when the fix is available.

The reported attack involves a race condition in the Microsoft Malware Protection Engine (part of Defender) that can allow local attackers to gain SYSTEM-level privileges. The PoC associated with the vulnerability is attributed to a researcher known as Nightmare Eclipse (also reported as Chaotic Eclipse). Outlets state the exploit can work on fully patched Windows 10 and Windows 11 systems, and some reports indicate it may succeed whether Defender’s real-time protection is enabled or disabled, including potentially in passive mode.

Independent reporting also says security researchers and testing firms have reproduced the flaw and demonstrated its viability. One reported mitigation is application allowlisting, which can prevent the exploit from executing.