Security6 publishers3 min readPublished
Defender's SYSTEM race is back: ShieldBreak PoC says Microsoft's July fix never held
A researcher claims a 100% reliable bypass of the Malware Protection Engine fix for CVE-2026-50656 on Windows 11 25H2 and Server 2025. There is no second patch to apply.
The Watch · Security desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- A security researcher going by Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) released a proof-of-concept for a new Microsoft zero-day called ShieldBreak.
- The vulnerability is rooted in Microsoft Defender for Windows and demonstrates a patch bypass for CVE-2026-50656 (CVSS score 7.8), otherwise known as RoguePlanet.
- RoguePlanet has been described as a race condition that, if successfully exploited, could grant an attacker the ability to spawn a shell with SYSTEM-level privileges, enabling arbitrary code execution or unauthorized actions.
- The vulnerability was first disclosed by the researcher in June 2026, but Microsoft did not release a patch until almost a month later.
- Microsoft described CVE-2026-50656 as a privilege escalation issue in the Microsoft Malware Protection Engine (mpengine.dll).
Compiled by The WatchSomething wrong?How this is made
Why it matters
A researcher using the handle Chaotic Eclipse has published a proof-of-concept, called ShieldBreak, that is assessed to be a full patch bypass for CVE-2026-50656, the Defender privilege escalation flaw also known as RoguePlanet [1][2][7]. If the claim holds, the security product on the endpoint remains a local-to-SYSTEM path on fully updated Windows 11 25H2 and Windows Server 2025, and the vulnerability management dashboard will show it as closed [8].
The original bug is a race condition in the Microsoft Malware Protection Engine, mpengine.dll, which Microsoft rated CVSS 7.8 and described as an elevation of privilege issue; successful exploitation spawns a shell with SYSTEM privileges [2][3][5]. The researcher first disclosed it in June 2026 and Microsoft did not ship a fix until almost a month later [4]. That fix has now been questioned twice. Shortly after it shipped, Chaotic Eclipse reported that the "defense-in-depth updates" caused Defender to leak 8 bytes of data when opening a file in certain scenarios on Windows 11 25H2 and Windows Server 2025, and Microsoft told The Hacker News at the time it was aware of the report and investigating [6]. ShieldBreak goes further: "Microsoft has failed to properly patch the RoguePlanet vulnerability," the researcher said [7].
The operational detail that matters is the reliability claim. According to the researcher, the PoC was tested on the latest Windows 11 25H2 including the Canary channel, and on Windows Server 2025, with a 100% success rate [8]. Windows 10 and its server editions are not currently supported by the PoC but are described by the researcher as vulnerable as well [9]. Microsoft has not publicly confirmed the bypass; The Hacker News said it had contacted the company and would update if it heard back [10]. Treat the success rate as an unverified researcher claim, but treat the underlying class of bug as proven: Microsoft already shipped one patch for it [4][5].
August's Patch Tuesday does not resolve this. The release covers 421 Microsoft CVEs, of which Windows accounts for 236 and Defender for exactly one [11]. That is under a quarter of one percent of the release touching the product now in question [17]. Vendor counts differ depending on what is being counted: CrowdStrike put the total at 415 vulnerabilities, and Security Affairs counted 398 new CVEs [12][13]. Elevation of privilege was again the dominant category, at 174 patches or 42% of the release in CrowdStrike's breakdown [14].
There is a working example of why local SYSTEM bugs deserve the attention. CVE-2026-68820, a use-after-free in afd.sys that also requires winning a race condition, was actively exploited before the fix [15]. Check Point reported that North Korean Lazarus actors used it to deploy a new version of the FudModule kernel-mode rootkit, while Microsoft has not disclosed exploitation details [16]. CISA added it to the Known Exploited Vulnerabilities catalog with a federal remediation deadline of 25 August 2026 [18]. The same researcher's earlier LegacyHive disclosure also landed this month as CVE-2026-62832 in the Windows User Profile Service [19].
What to watch: whether Microsoft issues a fresh CVE and engine update for ShieldBreak rather than another defense-in-depth revision, and whether the 8-byte leak report is ever resolved publicly [6]. Until then, CVE-2026-50656 reads as patched while the exposure dates to June 2026, roughly two months of drift between record and reality [4][20]. Ledger status is not machine status.