EN·DE
IT Security

Researcher Releases ShieldBreak Zero-Day That Bypasses Microsoft Defender Patch

A researcher published a zero-day exploit that bypasses a recent Microsoft Defender patch, granting SYSTEM privileges on fully patched Windows systems, and reigniting a dispute over disclosure practices.

This article was drafted with AI assistance from multiple sources and was reviewed and approved by a human editor before publication.

A security researcher has published a new zero-day exploit that bypasses a recent patch for a Microsoft Defender vulnerability, escalating a long-running dispute over disclosure and bug bounty practices.

The exploit, named ShieldBreak, was released on August 12, 2026, by the researcher known as Nightmare Eclipse. It targets a privilege escalation flaw in Microsoft Defender, tracked as CVE-2026-50656 and dubbed RoguePlanet, which was disclosed in June and patched by Microsoft in July. According to the researcher, ShieldBreak can achieve SYSTEM privileges on fully patched Windows 10, Windows 11, and Windows Server systems.

In a statement accompanying the release, Nightmare Eclipse said: "Microsoft has failed to properly patch the RoguePlanet vulnerability CVE-2026-50656, this PoC demonstrates a full patch bypass." The researcher also detailed the exploit's testing conditions: "The PoC was tested in the latest version of windows 11 25h2 (+Canary channel) and windows server 2025, the PoC also have a 100% success rate. Please note that Windows 10 (and respective server editions) are not currently supported, they are however vulnerable to ShieldBreak as well."

Will Dormann, principal vulnerability analyst at Tharros, verified on August 11 that the exploit functions as claimed, but noted that Microsoft Defender must be enabled on the target system for the privilege escalation to succeed.

ShieldBreak is the latest in a series of zero-day disclosures by Nightmare Eclipse since April 2026. The researcher has publicly released exploits including LegacyHive, RoguePlanet, BlueHammer, RedSun, YellowKey, GreenPlasma, MiniPlasma, and UnDefend, targeting Microsoft Defender, BitLocker, and other Windows components. While Microsoft fixed RoguePlanet in July 2026, other vulnerabilities disclosed by the researcher, including YellowKey, GreenPlasma, and MiniPlasma, were addressed in the June 2026 Patch Tuesday updates. However, several other disclosed flaws remain without an official patch.

The ongoing dispute between Nightmare Eclipse and Microsoft centers on vulnerability disclosure and bug bounty practices. Microsoft has responded to the researcher's disclosures with warnings of legal action against individuals engaging in "malicious activity causing real harm" to customers.

BleepingComputer has contacted Microsoft for comment on the ShieldBreak zero-day but has not yet received a response as of publication.

Sources

  1. BleepingComputer – New Microsoft Defender 'ShieldBreak' zero-day grants SYSTEM privileges