Security6 distinct publishers3 min readUpdated
A researcher claims a 100% reliable bypass of the Malware Protection Engine fix for CVE-2026-50656 on Windows 11 25H2 and Server 2025. There is no second patch to apply.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
A researcher using the handle Chaotic Eclipse has published a proof-of-concept, called ShieldBreak, that is assessed to be a full patch bypass for CVE-2026-50656, the Defender privilege escalation flaw also known as RoguePlanet [1][2][7]. If the claim holds, the security product on the endpoint remains a local-to-SYSTEM path on fully updated Windows 11 25H2 and Windows Server 2025, and the vulnerability management dashboard will show it as closed [8].
The original bug is a race condition in the Microsoft Malware Protection Engine, mpengine.dll, which Microsoft rated CVSS 7.8 and described as an elevation of privilege issue; successful exploitation spawns a shell with SYSTEM privileges [2][3][5]. The researcher first disclosed it in June 2026 and Microsoft did not ship a fix until almost a month later [4]. That fix has now been questioned twice. Shortly after it shipped, Chaotic Eclipse reported that the "defense-in-depth updates" caused Defender to leak 8 bytes of data when opening a file in certain scenarios on Windows 11 25H2 and Windows Server 2025, and Microsoft told The Hacker News at the time it was aware of the report and investigating [6]. ShieldBreak goes further: "Microsoft has failed to properly patch the RoguePlanet vulnerability," the researcher said [7].
The operational detail that matters is the reliability claim. According to the researcher, the PoC was tested on the latest Windows 11 25H2 including the Canary channel, and on Windows Server 2025, with a 100% success rate [8]. Windows 10 and its server editions are not currently supported by the PoC but are described by the researcher as vulnerable as well [9]. Microsoft has not publicly confirmed the bypass; The Hacker News said it had contacted the company and would update if it heard back [10]. Treat the success rate as an unverified researcher claim, but treat the underlying class of bug as proven: Microsoft already shipped one patch for it [4][5].
August's Patch Tuesday does not resolve this. The release covers 421 Microsoft CVEs, of which Windows accounts for 236 and Defender for exactly one [11]. That is under a quarter of one percent of the release touching the product now in question [17]. Vendor counts differ depending on what is being counted: CrowdStrike put the total at 415 vulnerabilities, and Security Affairs counted 398 new CVEs [12][13]. Elevation of privilege was again the dominant category, at 174 patches or 42% of the release in CrowdStrike's breakdown [14].
There is a working example of why local SYSTEM bugs deserve the attention. CVE-2026-68820, a use-after-free in afd.sys that also requires winning a race condition, was actively exploited before the fix [15]. Check Point reported that North Korean Lazarus actors used it to deploy a new version of the FudModule kernel-mode rootkit, while Microsoft has not disclosed exploitation details [16]. CISA added it to the Known Exploited Vulnerabilities catalog with a federal remediation deadline of 25 August 2026 [18]. The same researcher's earlier LegacyHive disclosure also landed this month as CVE-2026-62832 in the Windows User Profile Service [19].
What to watch: whether Microsoft issues a fresh CVE and engine update for ShieldBreak rather than another defense-in-depth revision, and whether the 8-byte leak report is ever resolved publicly [6]. Until then, CVE-2026-50656 reads as patched while the exposure dates to June 2026, roughly two months of drift between record and reality [4][20]. Ledger status is not machine status.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
CVE-2026-68820 is an actively exploited use-after-free flaw in afd.sys, the kernel-mode driver underpinning the Windows Sockets API, that can let an authorized attacker elevate to SYSTEM privileges; Microsoft's advisory says successful exploitation requires an attacker to win a race condition.
The researcher said: "The PoC was tested in the latest version of Windows 11 25h2 (+Canary channel) and Windows Server 2025, the PoC also have a 100% success rate."
A security researcher going by Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) released a proof-of-concept for a new Microsoft zero-day called ShieldBreak.
CrowdStrike's breakdown of the August 2026 release lists elevation of privilege as the leading risk type with 174 patches (42%), followed by remote code execution with 109 (26%) and information disclosure with 85 (20%).
RoguePlanet has been described as a race condition that, if successfully exploited, could grant an attacker the ability to spawn a shell with SYSTEM-level privileges, enabling arbitrary code execution or unauthorized actions.
The vulnerability was first disclosed by the researcher in June 2026, but Microsoft did not release a patch until almost a month later.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Two independent reports plus one adversarial technical review; no vendor confirmation
The existence and public availability of the PoC are corroborated by two publishers, and BleepingComputer adds named third-party analysis (Beaumont on mechanism, Dormann on the Defender-enabled precondition) plus detection queries. But the core severity claims — full patch bypass and 100% reliability — rest on the researcher's own statements, Microsoft has not commented, no CVE or vendor severity exists for ShieldBreak, and Beaumont's account of differing mechanics complicates the 'the July fix never held' reading. Surrounding Patch Tuesday facts are well corroborated, though trackers disagree on totals.
Exploit code public and detections shipped, but no vendor fix and no reported in-the-wild use
Working exploit code is publicly available and at least one defender-side artifact (Defender for Endpoint detection queries) has been published, which is real operational uptake. Against that, no source reports ShieldBreak being used in attacks, no patch exists to deploy, and the only in-the-wild exploitation and compliance deadline in the cluster belong to a different flaw (CVE-2026-68820). The Defender component received exactly one CVE in the August release, indicating no remediation pipeline has visibly engaged.
Real unpatched exposure, but the '100% reliable, fix never held' framing outruns verification
The underlying situation is genuine: public SYSTEM-level exploit code against an enabled Defender with no available patch. The headline framing is nonetheless ahead of the evidence — the 100% success rate is the researcher's own untested-by-others figure, Microsoft has not confirmed anything, Beaumont says ShieldBreak and RoguePlanet operate through different mechanisms (Cloud Filter API hydration hook vs. quarantine filesystem race), so 'the July fix never held' is an interpretation rather than a demonstrated regression, and Windows 10 exposure is asserted without a working PoC. Four of six publishers in the cluster did not consider the claim newsworthy at all.
Disclosure feud plus vendor-authored patch commentary shape most of the framing
BleepingComputer states plainly that ShieldBreak is part of an ongoing, heated dispute between Microsoft and the researcher over disclosure and bug bounty practices, following Microsoft warnings of legal action that experts read as directed at the researcher — a strong incentive for maximal public framing on both sides, and for Microsoft's silence. On the analysis side, much of the surrounding commentary is supplied by parties selling adjacent products: CrowdStrike's own patch-analysis post, Action1 executives quoted throughout Infosecurity, Check Point credited for the exploited zero-day, and Tharros for the caveat. Microsoft's non-response leaves the record one-sided.
Solid on what was published, weak on severity and reach
High confidence that the PoC exists, is public, targets Defender, and shipped without a corresponding Microsoft fix, and that the surrounding August 2026 zero-day facts (afd.sys exploitation, Lazarus/FudModule attribution, KEV deadline, LegacyHive patch) are accurate. Low confidence in the quantified severity claims — reliability rate, breadth of affected Windows versions, and whether this genuinely constitutes a failure of the July patch — given no vendor response, no CVE, one adversarial technical reading, and tracker-level disagreement on baseline patch counts.
build
A researcher is timing zero-days to Patch Tuesday, and the monthly cadence has no reply1 distinct publisher
build
ShieldBreak: a Defender-to-SYSTEM PoC that your last patch cycle did not stop1 distinct publisher
build
A UDP packet is now enough: IKEEXT RCE moves from patch queue to fire drill1 distinct publisher
security
Two years, 117 identified children: the only Com case this week with an outcome attached1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 12, 2026
1 article
1 article · August 12, 2026
1 article · August 11, 2026
1 article · August 12, 2026
1 article · August 11, 2026