A security researcher known as Nightmare Eclipse has released a new Microsoft Defender zero-day exploit named “ShieldBreak” after Microsoft released the August 2026 Patch Tuesday security updates.
The new vulnerability is described as a bypass for RoguePlanet, another Defender privilege escalation flaw disclosed in June and patched by Microsoft one month later.
As Nightmare Eclipse explained, ShieldBreak can be used to gain SYSTEM privileges on fully patched Windows 10, Windows 11, and Windows Server systems.
“Microsoft has failed to properly patch the RoguePlanet vulnerability CVE-2026-50656, this PoC demonstrates a full patch bypass,” they said.
“The PoC was tested in the latest version of windows 11 25h2 (+Canary channel) and windows server 2025, the PoC also have a 100% success rate. Please note that Windows 10 (and respective server editions) are not currently supported, they are however vulnerable to ShieldBreak as well.”
Will Dormann, principal vulnerability analyst at Tharros, confirmed on Tuesday that the exploit works, saying that Microsoft Defender needs to be enabled for the ShieldBreak exploit to escalate attackers’ privileges.
The ShieldBreak exploit is part of an ongoing and heated dispute between Microsoft and Nightmare Eclipse over the company’s vulnerability disclosure and bug bounty practices.
Microsoft responded to Nightmare Eclipse’s disclosures with warnings of legal action against people engaging in “malicious activity causing real harm” to its customers, which prompted cybersecurity experts to believe the company was directly threatening the security researcher.
Since April 2026, the anonymous researcher has disclosed multiple other zero-day exploits for security flaws in Microsoft Defender, BitLocker, and various Windows components, including LegacyHive, RoguePlanet, BlueHammer, RedSun, YellowKey, GreenPlasma, MiniPlasma, and UnDefend.
While Microsoft fixed the RoguePlanet vulnerability in July and the YellowKey, GreenPlasma, and MiniPlasma flaws as part of the June 2026 Patch Tuesday, the other vulnerabilities disclosed by Nightmare Eclipse are still waiting for an official patch.
BleepingComputer has contacted a Microsoft spokesperson about the new ShieldBreak zero-day and will update the story if we receive a statement.
Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.
The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
Microsoft patches RoguePlanet Defender zero-day vulnerability
Microsoft working on Defender patch for RoguePlanet zero-day
Windows LegacyHive zero-day flaw gets free, unofficial patches
New Windows LegacyHive zero-day gives hackers admin privileges
Microsoft Defender ‘RoguePlanet’ zero-day grants SYSTEM privileges
LexisNexis shuts down services after suspicious activity on servers
Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days
Valve notifies Steam hardware customers of a data breach
Overdue a password health-check? Audit your Active Directory for free
Webinar: Shadow AI in 2026 (and how attackers are taking advantage)
See how Skyhigh Security’s patent-pending approach secures every browser session without costly and clunky enterprise browser replacements.
See how real inboxes, fake stores and AI scams shaped H1 2026 cyber threats
Pixellot discovered and secured hundreds of unmanaged AI agent identities in weeks, not months. Download the case study for how.
Terms of Use – Privacy Policy – Ethics Statement – Affiliate Disclosure
Read our posting guidelinese to learn what content is prohibited.



