"Microsoft has failed to properly patch the RoguePlanet vulnerability," said the researcher known as Chaotic Eclipse, who on August 2026 released a proof-of-concept (PoC) called ShieldBreak that the researcher says defeats Microsoft’s fixes.
Chaotic Eclipse's ShieldBreak PoC
The researcher going by Chaotic Eclipse (also identified by the aliases INFINITE NIGHTMARE, MSNightmare, and Nightmare‑Eclipse) published a PoC for a Microsoft zero-day they call ShieldBreak. According to the researcher, ShieldBreak is a full patch bypass for CVE-2026-50656 (RoguePlanet), a Windows Defender-related vulnerability with a CVSS score of 7.8. The researcher stated the PoC was tested on the latest Windows 11 25H2 (plus Canary channel) and Windows Server 2025 with a "100% success rate."
RoguePlanet (CVE-2026-50656) and Microsoft’s mpengine.dll fix
RoguePlanet was described as a race condition in Microsoft Defender for Windows that, if successfully exploited, "could grant an attacker the ability to spawn a shell with SYSTEM-level privileges, enabling them to run arbitrary code or perform unauthorized actions." Microsoft characterized the underlying issue as a privilege escalation bug in the Microsoft Malware Protection Engine ("mpengine.dll"). The vulnerability was first disclosed by the researcher in June 2026; Microsoft released a patch almost a month after that initial disclosure.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleDefense-in-depth updates, an 8-byte leak, and the claim of a bypass
After Microsoft issued what it called "defense-in-depth updates" intended to address CVE-2026-50656, Chaotic Eclipse reported that those updates could cause Defender to leak 8 bytes of data when attempting to open a file in certain scenarios on Windows 11 25H2 and Windows Server 2025. The researcher’s assessment is that ShieldBreak remains a full patch bypass for RoguePlanet and that "Microsoft has failed to properly patch the RoguePlanet vulnerability." The researcher also said, "Please note that Windows 10 (and respective server editions) are not currently supported, they are however vulnerable to ShieldBreak as well."
Microsoft’s August patches and related CVEs
Microsoft shipped an August update set that covered 421 security flaws in total, including 236 flaws in Windows. Among the fixes called out in reporting was CVE-2026-62832 (CVSS 7.8), a Windows User Profile Service privilege-escalation issue disclosed by Chaotic Eclipse under the name LegacyHive. Microsoft described that bug as "Improper link resolution before file access ('link following') in Windows User Profile Service" that could allow "an authenticated attacker who has credentials for another local account [to] run a specially crafted application to load another user's registry hive" and potentially "allow the attacker to access or modify another user's data and gain administrator privileges. User interaction is not required."
Also remediated in the same cycle was an actively exploited zero-day in the Windows Ancillary Function Driver for WinSock, tracked as CVE-2026-68820 (CVSS 7.0), which grants SYSTEM privileges, and a publicly disclosed Windows Container Isolation FS Filter Driver (unionfs.sys) tampering vulnerability, CVE-2026-72971 (CVSS 5.5). The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-68820 to its Known Exploited Vulnerabilities (KEV) catalog, creating a Federal requirement to apply fixes for that CVE by August 25, 2026.
What this means for security teams, federal agencies, and enterprises
- Security teams and technologists: Systems running Windows 11 25H2 and Windows Server 2025 should be inspected for the presence of the patched mpengine.dll and related Defender updates. The researcher’s claim that ShieldBreak yields a full patch bypass and an 8‑byte leak will likely prompt lab validation by defensive teams before trust is restored in the applied mitigations.
- Federal agencies and procurement leaders: With CISA adding CVE-2026-68820 to the KEV catalog and setting an August 25, 2026 remediation deadline, agencies face a near-term compliance obligation for at least that exploited WinSock vulnerability regardless of the ShieldBreak debate.
- Enterprises and end users: The researcher’s statement that Windows 10 is "not currently supported" by the PoC but "are however vulnerable to ShieldBreak as well" indicates organizations still running older Windows releases should monitor vendor guidance closely and prioritize patch validation and deployment.
Microsoft told The Hacker News at the time it was aware of the researcher’s report and is investigating the post-patch concerns; The Hacker News has contacted Microsoft for comment on the ShieldBreak PoC and said it will update the story if it hears back. The record now contains competing claims: a vendor patch addressing a documented privilege escalation in mpengine.dll, and a public researcher PoC asserting that the patch can be bypassed and that additional leakage remains.
The immediate, verifiable developments are concrete: a public PoC named ShieldBreak, a researcher claim of a full patch bypass and an 8‑byte leak, Microsoft’s prior patching action for RoguePlanet, and a separate CISA-mandated fix schedule for an actively exploited WinSock zero-day. Which of those will drive urgent changes to Defender updates, patch engineering, or federal compliance will depend on follow-up testing and any further response from Microsoft.




