The Circuitry
THE CIRCUITRYYour one-stop source for all tech news
HOMETODAYNEWSFEEDEVENTS
BOOKMARKS
RSS
© 2026 The Circuitry
About UsSourcesContactCorrectionsPrivacy
  • Today
  • Feed
  • Events
  • Saved
Scroll for more
Verification
VERIFIEDConfidence: HIGH
Source identified
Claims cross-referenced
No discrepancies found
Fact-check summary

BleepingComputer and other outlets confirm Microsoft patched the RoguePlanet Defender zero-day (CVE-2026-50656) via out-of-band Malware Protection Engine update on July 9.

Sourcing
1source

via The Register

The Register · track record
16Stories
100%Verified
030d
All sources →
Markets
MSFT···

Live quote · not investment advice

From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →
Home/Tech/Microsoft patches Nightmare Eclipse's RoguePlanet Defender zero-day
VERIFIEDBy Xavier Rivera· ·1.5 min read

Microsoft patches Nightmare Eclipse's RoguePlanet Defender zero-day

Microsoft has fixed the RoguePlanet zero-day in Defender via an update to the Malware Protection Engine. The patch closes the latest vulnerability publicly disclosed by researcher Nightmare Eclipse, who has sparred with the company over its handling of bug reports all year.

Source:The Register
Post
Microsoft patches Nightmare Eclipse's RoguePlanet Defender zero-day
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →
TL;DRAI · 60 sec read

Microsoft fixed the RoguePlanet zero-day in Microsoft Defender after Nightmare Eclipse published exploit code for CVE-2026-50656. The patch arrived outside Patch Tuesday and requires the latest Malware Protection Engine. It closes the researcher's seventh public zero-day disclosure amid disputes over Microsoft's vulnerability handling.

Microsoft has fixed the RoguePlanet zero-day vulnerability in Microsoft Defender, weeks after security researcher Nightmare Eclipse published exploit code for the flaw.

Microsoft addressed the bug outside its regular Patch Tuesday cycle. The company updated the Microsoft Malware Protection Engine to resolve CVE-2026-50656. Customers must run the latest engine version to receive the protection.
Microsoft addressed the bug outside its regular Patch Tuesday cycle.
The vulnerability first appeared in June when Nightmare Eclipse released technical details and a proof-of-concept exploit. The researcher claimed RoguePlanet could spawn a command prompt with SYSTEM privileges on fully patched Windows 10 and Windows 11 systems by exploiting a race condition in Defender.

The exploit's success depended on precise timing. Nightmare Eclipse described it as a race condition that delivered a 100 percent success rate on some machines but struggled on others. The bug reportedly worked whether or not Defender's real-time protection was enabled.
From The CircuitryThe Feed — live briefs across tech, all day.See what’s happening →
When The Register first reported on RoguePlanet in June, Microsoft said only that it was investigating the claims. The company has now completed that probe and issued the fix but has not explained the technical changes or confirmed any real-world exploitation beyond the published proof-of-concept.
RoguePlanet marks the seventh zero-day publicly disclosed by Nightmare Eclipse since April.
RoguePlanet marks the seventh zero-day publicly disclosed by Nightmare Eclipse since April. The researcher, who claims to be a former Microsoft employee, has conducted an increasingly acrimonious campaign against the company's vulnerability disclosure and bug bounty programs. Nightmare Eclipse has accused Microsoft of ignoring reports, deleting submission accounts, and treating independent researchers with contempt.

Microsoft initially warned that publishing exploit code could carry legal consequences. Security researchers pushed back, prompting the company to clarify it had no intention of pursuing action against legitimate security research. The researcher also alleged that Microsoft removed RoguePlanet proof-of-concept repositories from GitHub and GitLab before the code moved to a self-hosted location.
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →
With the patch for CVE-2026-50656 now live, Microsoft has closed every public zero-day disclosed by Nightmare Eclipse earlier this year.

EXPERT TAKE

The quiet engine update rather than a Patch Tuesday release suggests Microsoft treated the race condition as a targeted Defender fix, though the lack of technical detail leaves defenders without clear guidance on detection or mitigation steps.

Why this mattersAI · ~100 words

Tap a lens to see what this story means for you.

Morning Brief

Liked this? The Brief brings you the whole day in tech, verified, every morning.

Two minutes, free forever. What's in The Brief →

Reader-supported
DonateBuy me a coffee →Follow@thecircuitry_ →Follow@thecircuitry.to →
HELP US IMPROVE
From The Circuitry

See what’s happening right now

The Feed runs all day — short, verified briefs the moment they break.

Open the Feed →
From The Circuitry

Follow @thecircuitry_

Every story we publish, as it happens. No noise between.

Follow on X ↗On Bluesky ↗

Reader-supported

The Circuitry is a passion project I've always wanted to build, and I love the work behind it.

Running it costs real money. APIs, hosting, time. To keep improving the site and growing this into something useful for everyone, those costs have to be covered.

Any contribution is appreciated. If not, no pressure. Thanks for reading.

Buy me a coffee
MicrosoftSecurityZero-DayVulnerability
More fromThe Register
  • Xi calls for AI emergency systems and global openness

    Tech · 2mo
  • OpenAI admits GPT-5.6 occasionally deletes files – but it's an 'honest mistake'

    Tech · 2mo
  • Philips to replace bricked Hue Bridge Pro devices

    Tech · 2mo
More inTech
  • GlobalFoundries signs $2B TSMC deal for US silicon interposers

    Tech · 8h
  • SpaceX agrees to buy 800 MHz spectrum for Starlink Mobile

    Tech · 11h
  • Anthropic Launches Cyber Mission to Secure Infrastructure and Open-Source Code

    Tech · 13h
SupportThe Work

The Circuitry is reader-supported. If you find the daily brief useful, you can buy me a coffee to keep it going.

Buy a coffee →
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →

MORE IN THIS BEAT

All Tech →
  • Tech· 

    Critical CVE-2026-88131 hits Microsoft Dataverse with remote code execution

    Microsoft Dataverse is affected by critical vulnerability CVE-2026-88131, which allows remote code execution. The flaw scores 9.8 on CVSS; Microsoft says it has already fully mitigated it and customers have nothing to patch.

  • Tech· 

    Microsoft discloses CVE-2026-83947 in Azure Event Grid

    Microsoft has disclosed CVE-2026-83947, a CVSS 7.7 HIGH spoofing vulnerability in Azure Event Grid caused by missing authorization. Microsoft says it has already fully mitigated the cloud-service flaw and customers have nothing to do.

  • Tech· 

    Critical CVE-2026-77900 Hits Microsoft Azure App Service for Linux

    A critical vulnerability CVE-2026-77900 affects Microsoft Azure App Service for Linux with a CVSS score of 9.8. The flaw allows an unauthenticated attacker to execute code over the network. Microsoft says it has already fully mitigated the flaw; no customer action is needed.

  • Tech· 

    Critical CVE-2026-16823 hits IBM Security Verify Access

    IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 contain critical authentication bypass flaw CVE-2026-16823. The NVD rates it 9.1 and warns of remote exploitation without credentials.

  • Tech· 

    Red Hat OpenShift 4 hit by CVE-2026-93017 with 7.7 CVSS score

    Red Hat OpenShift Container Platform 4 is affected by CVE-2026-93017, a high-severity flaw that lets attackers read every secret in every namespace. The 7.7 CVSS score reflects broad access granted through an unrestricted ClusterRole on the insights-operator-gather service account.