Loading article…
Microsoft confirms CVE‑2026‑50656 (RoguePlanet) in Defender, a race‑condition that gives SYSTEM rights, and says a fix is in development.
Microsoft has assigned CVE‑2026‑50656 to a newly disclosed elevation‑of‑privilege flaw in the Microsoft Defender Malware Protection Engine, dubbed “RoguePlanet,” and says a high‑quality update is being prepared [2]. The vulnerability, a race‑condition that can grant attackers full SYSTEM privileges on fully patched Windows 10 and 11 machines, raises immediate security concerns for enterprises that rely on Defender as a primary endpoint protection layer.
| At a glance | |
|---|---|
| Vulnerability | CVE‑2026‑50656 (RoguePlanet) |
| Affected product | Microsoft Defender Malware Protection Engine |
| Impact | Elevation‑of‑privilege, SYSTEM‑level access |
| Status | Patch in development, announced 18 Jun 2026 |
The flaw was disclosed by security researcher “Chaotic Eclipse,” who released a proof‑of‑concept exploit hours after Microsoft’s June Patch Tuesday update. The exploit exploits a race condition, meaning success varies by system; the researcher reported a 100 % success rate on some machines while others were less reliable [2]. ThreatLocker, a security firm, confirmed the vulnerability works and even produced a demonstration video. This is the seventh zero‑day disclosed by the same researcher in recent months, following exploits named BlueHammer, RedSun, GreenPlasma, MiniPlasma, YellowKey and UnDefend, several of which also targeted Defender or other Windows components.
Microsoft’s advisory states the company is “hard at work” on a fix and will provide details when the update is ready. The company’s wording emphasizes a “high quality” patch, reflecting the need to address a flaw that affects fully patched systems—a rare scenario that can erode confidence in Windows’ baseline security. The timing is notable because the vulnerability emerged just after Microsoft’s regular monthly security roll‑out, potentially prompting customers to reassess reliance on Defender’s default protection and consider supplemental security solutions. Competitors in the endpoint security market, such as Bitdefender and Norton, may see increased interest as organizations seek layered defenses while awaiting Microsoft’s patch.
The emergence of RoguePlanet underscores the challenge of securing even the most widely deployed operating systems, and it will test Microsoft’s ability to quickly remediate high‑impact flaws without disrupting the broader Windows ecosystem.
Coverage is mostly measured — 17 of 17 reports stay neutral.
Every Monday — the token unlocks, Fed dates & catalysts set to move crypto and markets this week. So you’re never blindsided.
Free · 3-min read · one-click unsubscribe
AI-assisted synthesis by the TrendWatcher Editorial Desk · sourced from 2 outlets · Jun 18, 2026 · How we report
It provides AI-powered assistance in Word, Excel, PowerPoint, Outlook and other apps to draft content, analyze data, create images, and streamline tasks.
Microsoft was founded on April 4, 1975, by Bill Gates and Paul Allen.
Microsoft's IPO occurred on March 13, 1986, valuing the company at about $520 million.
The release of Windows 3.0 on May 22, 1990, marked a significant shift toward a graphical user interface.
It offers a unified AI chat, search, and creation interface that can locate files, summarize information, and generate content within familiar productivity tools.