Published Security3 min read
Protest zero-day LegacyHive gets a fix a month late, four Nightmare Eclipse bugs still open
Microsoft patched CVE-2026-62832 on August Patch Tuesday, roughly four weeks after working exploit code went public. 0Patch shipped first, and the researcher's backlog keeps growing.
Not a builder's beat, but builders have a standing stake in it.See today for builders
What happened
- Microsoft patched the LegacyHive vulnerability as part of its August Patch Tuesday updates and tracks it as CVE-2026-62832.
- LegacyHive was disclosed by a security researcher who uses the handle "Nightmare Eclipse" in protest of Microsoft's bug bounty and vulnerability disclosure practices.
- Nightmare Eclipse claimed the LegacyHive proof-of-concept exploits a vulnerability in the Windows User Profile Service.
- Nightmare Eclipse published the LegacyHive proof-of-concept exploit hours after the July 2026 Patch Tuesday security updates were released.
- Vulnerability analyst Will Dormann explained that non-admin users can use Nightmare Eclipse's exploit to modify the classes registry hive and gain automatic code execution when the admin account logs in to a compromised system.
Compiled by The WatchSomething wrong?How this is made
Why it matters
Microsoft has patched LegacyHive, a Windows User Profile Service flaw it now tracks as CVE-2026-62832, as part of its August Patch Tuesday updates [1][9]. The bug was public in the first place because a researcher using the handle Nightmare Eclipse dropped proof-of-concept code hours after the July 2026 Patch Tuesday release, explicitly in protest of Microsoft's bug bounty and vulnerability disclosure practices [2][3][4] - which means patch teams are now working a clock set by someone else's grievance.
The timeline deserves precision, because that is the operational part. The fix did not arrive out of band; it arrived on the next scheduled Patch Tuesday, roughly four weeks after working exploit code reached the public [1]. In between, Microsoft's public position was that it was "aware of the reported vulnerability and is actively investigating the validity and potential applicability of these claims" [18]. ACROS Security, which runs the 0Patch platform, published free unofficial micropatches on July 20 for Windows 10 2004 and later and Windows Server 2022 and later [10], weeks ahead of the vendor [2]. For that month, most estates had detection and third-party patching, or nothing.
On mechanism, Microsoft says the flaw is improper link resolution before file access, or link following, in the Windows User Profile Service, and that successful exploitation lets a local attacker gain administrator privileges [11]. Per Microsoft's advisory, an authenticated attacker holding credentials for another local account can run a crafted application to load another user's registry hive, then access or modify that user's data and escalate to administrator, with no user interaction [12]. Vulnerability analyst Will Dormann said a non-admin user can use the exploit to modify the classes registry hive and get automatic code execution when the admin account next logs in [5]. Kevin Beaumont confirmed the exploit worked and published Microsoft Defender for Endpoint detection queries a day after the PoC landed [6][7].
The credential requirement, which earlier Nightmare Eclipse releases did not have [8], genuinely raises the bar for opportunistic use. It is not a reason to relax: the Blue Report 2026, which measured defences across 338 million simulations run in customer production environments, argues that prevention drops sharply once attackers are operating with valid credentials [15][16].
The backlog is the real story. Nightmare Eclipse has disclosed nine named Windows zero-days since April 2026 - ShieldBreak, LegacyHive, RoguePlanet, YellowKey, BlueHammer, RedSun, GreenPlasma, MiniPlasma and UnDefend - across Microsoft Defender, BitLocker and other components [13][3]. Microsoft fixed YellowKey, GreenPlasma and MiniPlasma in June, RoguePlanet in July and LegacyHive in August [14][1], which leaves four of the nine without an official patch [4]. Microsoft attributed CVE-2026-62832 to an anonymous researcher and has not acknowledged Nightmare Eclipse as the finder [17]. Withheld credit is what the protest is about, so read that as a forecast rather than a footnote.
Watch three things. The four unpatched names, each of which already has a public description and, on this pattern, may get code. The hours immediately after each Patch Tuesday, which is when this researcher publishes [4]. And whether your change process can accept unofficial micropatches at all, because on this cycle 0Patch was the only patch available for weeks [10].
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Microsoft patched the LegacyHive vulnerability as part of its August Patch Tuesday updates and tracks it as CVE-2026-62832.
ReportedView cited source - [2]
LegacyHive was disclosed by a security researcher who uses the handle "Nightmare Eclipse" in protest of Microsoft's bug bounty and vulnerability disclosure practices.
ReportedView cited source - [3]
Nightmare Eclipse claimed the LegacyHive proof-of-concept exploits a vulnerability in the Windows User Profile Service.
ReportedView cited source - [4]
Nightmare Eclipse published the LegacyHive proof-of-concept exploit hours after the July 2026 Patch Tuesday security updates were released.
ReportedView cited source - [5]
Vulnerability analyst Will Dormann explained that non-admin users can use Nightmare Eclipse's exploit to modify the classes registry hive and gain automatic code execution when the admin account logs in to a compromised system.
ReportedView cited source - [6]
One day after the PoC was released, Kevin Beaumont published LegacyHive exploitation detection queries for Microsoft Defender for Endpoint.
ReportedView cited source
Sources & coverage · 1 publisher
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- bleepingcomputer.comSergiu GatlanAug 13Microsoft patches LegacyHive Windows zero-day vulnerability
Additional citations
- Microsoft advisory language quoted by BleepingComputer
- The Blue Report 2026, cited in promotional material accompanying the article
- Microsoft spokesperson to BleepingComputer



