Microsoft Patches Critical Windows Defender Zero-Day Amid Feud with Researcher
Microsoft has issued an urgent out-of-band patch for a critical Windows Defender zero-day vulnerability, CVE-2026-50656, which allowed attackers SYSTEM-level control over Windows 10 and 11 systems.
✨ This content was summarized and interpreted by AI; it may contain errors — please verify accuracy with the original sources. Learn more
Listen to this story

Microsoft has released an out-of-band patch for a critical zero-day vulnerability, dubbed "RoguePlanet" (CVE-2026-50656), in its Windows Defender antivirus engine, which allowed attackers to achieve SYSTEM-level privileges on fully updated Windows 10 and 11 systems. This urgent update, delivered via the Microsoft Malware Protection Engine version 1.1.26060.3008, addresses a race condition flaw that could grant an attacker complete control over a compromised device.
The vulnerability was publicly disclosed by the anonymous security researcher known as NightmareEclipse (also Chaotic Eclipse), a figure embroiled in an escalating and acrimonious feud with Microsoft. Believed to be a former Microsoft security employee, NightmareEclipse has been systematically releasing Windows zero-day exploits since April 2026, citing frustration over Microsoft's handling of vulnerability reports, alleged communication failures, and the deletion of their MSRC account. RoguePlanet marks at least the eighth such public disclosure, following others like BlueHammer, RedSun, and UnDefend, some of which have already seen in-the-wild exploitation.
This ongoing saga highlights a deeply fractured relationship between a major vendor and a disgruntled researcher, with significant implications for cybersecurity. While Microsoft typically updates Defender automatically, the rapid, uncoordinated disclosure of critical flaws, often timed just after Patch Tuesday, forces an accelerated response cycle and leaves users exposed for longer. The persistent defiance from NightmareEclipse, who has vowed to continue exposing vulnerabilities and has already identified new issues post-patch, suggests this contentious disclosure model is far from over. The industry must contend with the collateral damage when vulnerability reporting devolves into personal vendettas, turning bug hunters into adversaries.