Safety researchers have launched a brand new Microsoft Defender zero-day exploit named “RoguePlanet” simply hours after Microsoft mounted two flaws beforehand revealed in June 2026 Patch Tuesday.
In accordance with the researchers, often called Nightmare Eclipse, the brand new vulnerability impacts totally patched Home windows 10 and Home windows 11 gadgets and permits an attacker to launch a command immediate with SYSTEM privileges by way of a race situation vulnerability in Microsoft Defender.
Researchers shared the proof-of-concept exploit in a self-hosted Git repository on Tuesday afternoon, after saying the GitHub and GitLab repositories internet hosting the exploit had been beforehand eliminated by Microsoft.
“This exploit is a race situation, so it is hit and miss. We had been in a position to obtain a 100% success fee on some machines, however not on others,” Nightmare Eclipse writes in its repository.
This flaw was reportedly examined in opposition to Home windows 11 official and canary builds and Home windows 10 techniques with the June 2026 safety updates put in.
If profitable, a Home windows command immediate can be launched with SYSTEM privileges.
Cybersecurity firm ThreatLocker informed BleepingComputer that it efficiently reproduced the flaw in testing and confirmed that the exploit works in opposition to a totally patched Home windows 11 system with KB5094126 put in, and shared a demo video of it.
“Our preliminary evaluation confirms that the RoguePlanet exploit is viable and executes as described. Organizations utilizing software whitelisting can forestall the exploit from operating and supply an efficient layer of safety in opposition to this assault,” ThreatLocker CEO Danny Jenkins informed BleepingComputer.
In accordance with Nightmare Eclipse, RoguePlanet was initially developed as a distant code execution vulnerability that exploited file dealing with in Microsoft Defender hosted on a distant SMB share.
“Throughout preliminary improvement, this vulnerability was noticed to end in distant code execution,” researchers defined in a weblog put up.
“The attacker wanted to power the sufferer to open a .vhd(x) on a distant SMB server. As soon as the exploit was profitable, the defender would overwrite his personal file, and the tip end result was clearly an RCE.”
Researchers say that in one other assault state of affairs, merely forcing a sufferer to open an SMB share might result in distant code execution if the symbolic hyperlink status setting is enabled.
Nonetheless, researchers declare that Microsoft quietly hardened Defender to dam junction assaults by patching the mpengine!SysIO* API in mid-Could.
“Rewriting RoguePlanet to make it work once more has drained my spirit and I’ve not been in a position to full every other situations. For now, it’s unclear whether or not RoguePlanet is restricted to LPE or if there’s some technique to flip it into RCE,” the researchers wrote.
The discharge is a part of an ongoing dispute between Nightmare Eclipse and Microsoft over the corporate’s vulnerability disclosure and bug bounty applications.
Over the previous few months, researchers have launched a number of Home windows zero-days containing flaws in BlueHammer, RedSun, GreenPlasma, and YellowKey. Some zero-days focused Microsoft Defender, whereas others focused BitLocker and Home windows parts.
Microsoft right now mounted the GreenPlasma and YellowKey flaws as a part of the June 2026 Patch Tuesday replace.
Microsoft had beforehand warned in response to this disclosure that it might cooperate with regulation enforcement if folks engaged in “malicious exercise that ends in actual hurt to our clients,” main many within the cybersecurity neighborhood to imagine that Microsoft was threatening researchers.
Nightmare Eclipse claims that Microsoft has repeatedly focused and eliminated earlier repositories hosted on GitHub and GitLab, prompting the creation of a self-hosted code platform at projectnightcrawler.dev.
BleepingComputer has contacted Microsoft in regards to the new zero-day and can replace this text as soon as we obtain an announcement.

Safety groups doc 54% of profitable assaults and difficulty a warning on solely 14%. The remainder strikes invisibly by the setting.
Picus’ whitepaper exhibits how one can check your SIEM and EDR guidelines in breach and assault simulations to make sure threats go undetected.
Get the white paper
