DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 06:12:51ZSOURCES: 14CRITICAL: 31
⚠ ACTIVE ALERTS
@GossiTheDog CRITICAL — Sampled credentials from the FortiBleed dataset and confirmed they are authentic. Many of… /// @MsftSecIntel CRITICAL — Tracking FortiBleed downstream activity. Buyers of the FortiGate credential sets are… /// @TalosSecurity CRITICAL — FortiBleed is just one piece of a broader IAB operation. The same Russian-speaking actor… /// @MalwareHunterTeam CRITICAL — The Gentlemen RaaS internal data leak (May 2026, ~16GB) confirmed operators actively… /// @CrowdStrike CRITICAL — Gentlemen RaaS affiliates are deploying GentleKiller variants that specifically target…
31Critical Threats
18Active CVEs
19IOCs Tracked
11New Advisories
TLP:WHITEVULNERABILITY BRIEF // CVE-2026-50656PUBLISHED: 2026-06-16
HIGHCVE-2026-50656

RoguePlanet: Microsoft Defender Malware Protection Engine TOCTOU EoP Zero-Day

VENDOR: Microsoft//PRODUCT: Microsoft Defender (Microsoft Malware Protection Engine)
7.8
HIGH
CVSS 3.1
NO PATCH AVAILABLE
This vulnerability has no vendor patch at this time. Apply mitigation steps below or restrict network access to affected systems.
PATCH STATUS
NO PATCH
EXPLOIT STATUS
PUBLIC EXPLOIT

A Time-of-Check to Time-of-Use (TOCTOU) race condition (CWE-362) in the Microsoft Malware Protection Engine's file-scanning workflow allows a low-privileged local attacker to substitute a malicious payload during the gap between file check and file open, triggering execution under the SYSTEM account. Researcher Nightmare Eclipse (Chaotic Eclipse) published a working PoC on GitHub on June 10, 2026 before a patch existed; Microsoft confirmed the flaw (MSRC advisory) and stated a high-quality fix is in development with no release date committed. The PoC functions regardless of whether Defender real-time protection is enabled.

Attack Vector
LOCAL
Attack Complexity
HIGH
Privs Required
LOW
User Interaction
NONE
Scope / Impact
UNCHANGED
C:H · I:H · A:H
AFFECTED VERSIONSAll Windows 10 and Windows 11 systems running Microsoft Defender with the Malware Protection Engine (MPE) prior to a forthcoming patch; no fix available as of June 24, 2026
  • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50656
  • https://www.securityweek.com/microsoft-working-on-patch-for-rogueplanet-zero-day/
  • https://thehackernews.com/2026/06/microsoft-confirms-rogueplanet-defender_02022423645.html
  • https://github.com/MSNightmare/RoguePlanet
  • https://thecyberexpress.com/cve-2026-50656-rogueplanet-windows-defender/
SHARE BRIEF:✕ Post on Xin Share on LinkedIn