
New Microsoft Defender ‘ShieldBreak’ zero-day grants SYSTEM privileges
A security researcher known as Nightmare Eclipse has released a new Microsoft Defender zero-day exploit named “ShieldBreak” after Microsoft released the August 2026 Patch Tuesday security updates.
The new vulnerability is described as a bypass for RoguePlanet, another Defender privilege escalation flaw disclosed in June and patched by Microsoft one month later.
However, cybersecurity expert Kevin Beaumont, who also published ShieldBreak exploitation detection queries for Microsoft Defender for Endpoint, said that the two exploits work very differently.
“RoguePlanet was a filesystem race condition vuln that uses virtual disks and NT native file manipulation to trick quarantine process into overwriting system files,” Beaumont noted. “ShieldBreak user-mode callback hook to change file contents during a Defender cloud-hydration scan via cfapi (Cloud Filter API).”
According to Nightmare Eclipse, ShieldBreak can be used to gain SYSTEM privileges on fully patched Windows 10, Windows 11, and Windows Server systems.
“Microsoft has failed to properly patch the RoguePlanet vulnerability CVE-2026-50656, this PoC demonstrates a full patch bypass,” they said.
“The PoC was tested in the latest version of windows 11 25h2 (+Canary channel) and windows server 2025, the PoC also have a 100% success rate. Please note that Windows 10 (and respective server editions) are not currently supported, they are however vulnerable to ShieldBreak as well.”
Will Dormann, principal vulnerability analyst at Tharros, confirmed on Tuesday that the exploit works, saying that Microsoft Defender needs to be enabled for the ShieldBreak exploit to escalate attackers’ privileges.

The ShieldBreak exploit is part of an ongoing and heated dispute between Microsoft and Nightmare Eclipse over the company’s vulnerability disclosure and bug bounty practices.
Microsoft responded to Nightmare Eclipse’s disclosures with warnings of legal action against people engaging in “malicious activity causing real harm” to its customers, which prompted cybersecurity experts to believe the company was directly threatening the security researcher.
Since April 2026, the researcher has disclosed LegacyHive, RoguePlanet, BlueHammer, RedSun, YellowKey, GreenPlasma, MiniPlasma, and UnDefend zero-day exploits targeting Microsoft Defender, BitLocker, and various other Windows components
While Microsoft fixed the RoguePlanet vulnerability in July and the YellowKey, GreenPlasma, and MiniPlasma flaws as part of the June 2026 Patch Tuesday, the other vulnerabilities disclosed by Nightmare Eclipse are still waiting for an official patch.
“Microsoft is aware of the reported vulnerability and is actively investigating the validity and potential applicability of these claims. Microsoft is committed to investigating security issues and updating impacted products to protect customers as soon as possible,” a Microsoft spokesperson told GeekFeed when asked for a statement regarding the new ShieldBreak zero-day exploit.
“Importantly, we support coordinated vulnerability disclosure, an industry standard that protects customers and supports the research community by ensuring their findings are thoroughly investigated and addressed before being made public.”


