# CVE-2026-50656

Type: vulnerability

Source: Cyber Intelligence Brief — https://getcyberbrief.com/entity/cve-2026-50656
Canonical HTML page: https://getcyberbrief.com/entity/cve-2026-50656

## Timeline

- **2026-06-17**: Security press reports on Microsoft's response — SecurityWeek and BleepingComputer publish articles detailing the advisory and the ongoing feud between the researcher and Microsoft.
- **2026-06-16**: Microsoft assigns CVE and publishes advisory — Microsoft acknowledges CVE-2026-50656 (CVSS 7.8) and announces it is working on a security update, without attributing the discovery to the researcher.
- **2026-06-10**: Researcher discloses RoguePlanet — Nightmare Eclipse publicly releases the vulnerability details and a proof-of-concept exploit, demonstrating local privilege escalation on Windows 10/11.
- **2026-05**: Microsoft hardens Defender — Microsoft releases updates that close some remote code execution paths for the underlying bug, forcing the researcher to rework the exploit into a privilege escalation attack.

## Recent coverage (1 stories)

### RoguePlanet Defender Zero-Day Has 100% Exploit Success on Some Windows Machines
2026-06-17 10:16:49 · Sentiment: Negative · Impact: 8/10 · Sources: 2

A publicly dropped zero-day in Microsoft Defender, tracked as CVE-2026-50656 (CVSS 7.8), can yield SYSTEM privileges with up to 100% reliability on patched Windows 10/11, even when real-time protection is off. Microsoft is scrambling to produce a patch amid an escalating dispute with the researcher behind the PoC.
Full story: https://getcyberbrief.com/story/rogueplanet-defender-zero-day-cve-2026-50656-100-percent-exploit

---
This page is a machine-readable summary. Sentiment measures the directional read of each development for this entity, not the tone of the reporting; impact weights consequence, not syndication reach. See https://getcyberbrief.com/guides/methodology for the full editorial methodology.