CVE detail
CVE-2026-50656
Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RoguePlanet ".
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 30.0 · diversity 20.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 19
- within the 30d window
- Peak daily
- 10
- highest bucket
Evidence
Source links by recency
26 source links · newest first
ation of remediations as a trailing indicator. SharePoint: critical auth bypass by Rapid7 Today sees the publication of CVE-2026-55040 , a critical authentication bypass in Microsoft SharePoint. Discovered by Rapid7 Senior Principal Security Researcher Stephen Fewer , and published today in coordination with Microsoft, this vulnerability is the first i
vendorwww.rapid7.comJul 14, 2026, 10:00 PMerica Breach Exposes 7 Million Driver’s Licenses After Employee Account Hack Microsoft fixed Defender flaw RoguePlanet (CVE-2026-50656) Fake VPN and 7-Zip Apps Turn Victims Into Residential Proxy Nodes Ubiquiti Patches Critical UniFi OS Flaws Allowing Command Injection and Privilege Escalation A Hacker Claims 35 GB of Accenture Source Code. The Company
newssecurityaffairs.comJul 12, 2026, 4:58 AMica Breach Exposes 7 Million Driver’s Licenses After Employee Account Hack | Microsoft fixed Defender flaw RoguePlanet (CVE-2026-50656) | Fake VPN and 7-Zip Apps Turn Victims Into Residential Proxy Nodes | Ubiquiti Patches Critical UniFi OS Flaws Allowing Command Injection and Privilege Escalation | A Hacker Claims 35 GB of Accenture Source Code. The C
newssecurityaffairs.comJul 10, 2026, 10:22 AMica Breach Exposes 7 Million Driver’s Licenses After Employee Account Hack | Microsoft fixed Defender flaw RoguePlanet (CVE-2026-50656) | Fake VPN and 7-Zip Apps Turn Victims Into Residential Proxy Nodes | Ubiquiti Patches Critical UniFi OS Flaws Allowing Command Injection and Privilege Escalation | A Hacker Claims 35 GB of Accenture Source Code. The C
newssecurityaffairs.comJul 10, 2026, 8:25 AM- July 2026 Patch Tuesday forecast: Is CVE tracking still practical?Help Net Security
to as RoguePlanet continuing the string of Microsoft Defender flaws that have been identified. RoguePlanet, tracked as CVE-2026-50656 , is a race condition privilege escalation vulnerability. The POC code the researcher posted on GitHub can result in a System privilege shell running on the compromised system. CISA has announced the previously reported
newswww.helpnetsecurity.comJul 10, 2026, 7:30 AM - Microsoft is rewriting Windows patch guidance because of AIHelp Net Security
ortion crew hijacks Microsoft 365 accounts via fake passkey setup Microsoft releases fix for RoguePlanet Defender flaw (CVE-2026-50656) Report: How to Implement a Continuous Offensive Security Testing Program Resources Download: Secure Foundations for AI Workloads on AWS Download: Automating Pentest Delivery Guide CIS Benchmarks March 2026 Update Don't
newswww.helpnetsecurity.comJul 10, 2026, 6:00 AM - Turning software supply chain security into a daily habitHelp Net Security
ortion crew hijacks Microsoft 365 accounts via fake passkey setup Microsoft releases fix for RoguePlanet Defender flaw (CVE-2026-50656) Report: How to Implement a Continuous Offensive Security Testing Program Resources Download: Secure Foundations for AI Workloads on AWS Download: Automating Pentest Delivery Guide CIS Benchmarks March 2026 Update Don't
newswww.helpnetsecurity.comJul 10, 2026, 5:30 AM ica Breach Exposes 7 Million Driver’s Licenses After Employee Account Hack | Microsoft fixed Defender flaw RoguePlanet (CVE-2026-50656) | Fake VPN and 7-Zip Apps Turn Victims Into Residential Proxy Nodes | Ubiquiti Patches Critical UniFi OS Flaws Allowing Command Injection and Privilege Escalation | A Hacker Claims 35 GB of Accenture Source Code. The C
newssecurityaffairs.comJul 9, 2026, 9:29 PM- Microsoft Reins in RoguePlanet Zero-Day ThreatDark Reading
t issued an out-of-band patch for RoguePlanet , an elevation-of-privilege vulnerability in Windows Defender, tracked as CVE-2026-50656. The high-severity flaw, which received a 7.8 CVSS score from Microsoft, could allow an attacker to escalate privileges on a Windows device from a basic user to the highest SYSTEM-level access, which would give them com
newswww.darkreading.comJul 9, 2026, 8:21 PM - GodDamn Ransomware Uses PoisonX to Blind Security SoftwareSecurity Affairs
ica Breach Exposes 7 Million Driver’s Licenses After Employee Account Hack | Microsoft fixed Defender flaw RoguePlanet (CVE-2026-50656) | Fake VPN and 7-Zip Apps Turn Victims Into Residential Proxy Nodes | Ubiquiti Patches Critical UniFi OS Flaws Allowing Command Injection and Privilege Escalation | A Hacker Claims 35 GB of Accenture Source Code. The C
newssecurityaffairs.comJul 9, 2026, 6:11 PM - Microsoft closes book on Nightmare Eclipse's RoguePlanet zero-dayThe Register Security
pse after months of public sparring over the company's handling of vulnerability reports. The vulnerability, tracked as CVE-2026-50656, was addressed through an update to the Microsoft Malware Protection Engine rather than via its monthly Patch Tuesday bundle. Microsoft said customers should ensure they're running the latest engine version to receive t
newswww.theregister.comJul 9, 2026, 1:30 PM Microsoft has finally released a security update for its Microsoft Malware Protection Engine, which fixes CVE-2026-50656, the Windows Defender local privilege escalation vulnerability triggered by the RoguePlanet exploit. The vulnerability and the fix CVE-2026-50656 is due to improper link resolution before file access, affects Windows 10
newswww.helpnetsecurity.comJul 9, 2026, 12:14 PM- Microsoft fixes RoguePlanet zero-day in DefenderMalwarebytes Labs
The RoguePlanet zero-day is now fixed in Microsoft Defender. Here's how to make sure your system is protected.
newswww.malwarebytes.comJul 9, 2026, 11:38 AM The privilege escalation vulnerability tracked as CVE-2026-50656 has been patched with a Microsoft Malware Protection Engine update. The post Microsoft Patches Defender ‘RoguePlanet’ Vulnerability appeared first on SecurityWeek .
newswww.securityweek.comJul 9, 2026, 10:28 AM- Microsoft fixed Defender flaw RoguePlanet (CVE-2026-50656)Security Affairs
Microsoft fixed RoguePlanet (CVE-2026-50656), a Defender flaw allowing local attackers to gain higher privileges through the Malware Protection Engine. Microsoft released security updates for RoguePlanet, a vulnerability tracked as CVE-2026-50656 (CVSS score of 7
newssecurityaffairs.comJul 9, 2026, 10:17 AM lnerability known as RoguePlanet, nearly a month after details of the flaw became public. The vulnerability, tracked as CVE-2026-50656 (CVSS score: 7.8), is a privilege escalation issue in the Microsoft Malware Protection Engine ("mpengine.dll"), which provides scanning, detection, and cleaning capabilities for its antivirus and
newsthehackernews.comJul 9, 2026, 8:48 AM- Microsoft patches RoguePlanet Defender zero-day vulnerabilityBleepingComputer
fender zero-day vulnerability known as "RoguePlanet," disclosed after the June 2026 Patch Tuesday. The flaw (tracked as CVE-2026-50656 ) was disclosed by a security researcher using the "Nightmare Eclipse" handle as part of an ongoing dispute with Microsoft over the company's bug bounty and vulnerability disclosure practices. They also shared a proof-o
newswww.bleepingcomputer.comJul 9, 2026, 5:42 AM ica Breach Exposes 7 Million Driver’s Licenses After Employee Account Hack | Microsoft fixed Defender flaw RoguePlanet (CVE-2026-50656) | Fake VPN and 7-Zip Apps Turn Victims Into Residential Proxy Nodes | Ubiquiti Patches Critical UniFi OS Flaws Allowing Command Injection and Privilege Escalation | A Hacker Claims 35 GB of Accenture Source Code. The C
newssecurityaffairs.comJul 8, 2026, 11:09 AMica Breach Exposes 7 Million Driver’s Licenses After Employee Account Hack | Microsoft fixed Defender flaw RoguePlanet (CVE-2026-50656) | Fake VPN and 7-Zip Apps Turn Victims Into Residential Proxy Nodes | Ubiquiti Patches Critical UniFi OS Flaws Allowing Command Injection and Privilege Escalation | A Hacker Claims 35 GB of Accenture Source Code. The C
newssecurityaffairs.comJul 8, 2026, 7:24 AM- Week in review: 74k Fortinet firewall credentials stolen, Splunk Enterprise RCE under active attackHelp Net Security
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: A hardware neural network backdoor that hides in plain sight Deep learning systems on edge devices often rely on third-party-designed FPGAs and ASICs for performance and efficiency, creating supply chain risks. Researchers from the University of Tennessee and the University of Florida developed HAMLOCK, a backdoor attack that splits malicious functionality between hardware and software, making detection more difficult. Onspring … More →
newswww.helpnetsecurity.comJun 21, 2026, 8:00 AM Microsoft says it’s working on a fix for an unpatched Defender vulnerability that can give attackers the highest level of access on Windows.
newswww.malwarebytes.comJun 18, 2026, 12:58 PMMicrosoft confirmed the RoguePlanet Defender zero-day (CVE-2026-50656), a privilege escalation flaw, and is developing a security patch. Microsoft has acknowledged the RoguePlanet zero-day affecting Microsoft Defender, tracked as CVE-2026-50656 (CVSS score of 7.8). The vulnerability allows privilege escalation through the Microsoft Malware Protection Engine. The company stated it is aware of the issue and is […]
newssecurityaffairs.comJun 18, 2026, 9:21 AMMicrosoft has acknowledged the local elevation of privilege issue in Microsoft Defender that can be triggered via the “RoguePlanet” exploit, and is “working to provide a high quality security update that addresses this vulnerability.” The vulnerability, which has been assigned the CVE-2026-50656 identifier, stems from improper link resolution before file access, and can be exploited in low complexity attacks by authenticated attackers, with no user interaction required. Zero-day exploits by Nightmare Eclipse RoguePlanet is one … More →
newswww.helpnetsecurity.comJun 17, 2026, 11:26 AMThe public PoC code exploits a race condition in Microsoft Defender to spawn a command prompt with System privileges.
newswww.securityweek.comJun 17, 2026, 9:41 AMNo excerpt available.
Exploitgithub.comJun 16, 2026, 7:16 PMMicrosoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RoguePlanet ". We are working to provide a high quality security update that addresses this vulnerability. We will provide information in this CVE when the update is available.
vendormsrc.microsoft.comJun 16, 2026, 2:00 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-41091CVSS 7.8 · High
Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally.
- CVE-2026-67433CVSS 5.8 · Medium
Linuxfabrik monitoring-plugins provides Python monitoring plugins for Icinga, Nagios, and related monitoring systems. In version 6.0.0, the logfile check legacy database migration…
- CVE-2026-13268CVSS 7.8 · High
G DATA Total Security Backup Service Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installa…
- CVE-2026-13723CVSS 6.5 · Medium
A vulnerability in the `zipx.Unzip` extraction routine of Develar's app-builder allows an attacker to overwrite arbitrary files on macOS APFS by exploiting a Unicode Normalization…
- CVE-2026-43765CVSS 5.5 · Medium
This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to modify prote…
- CVE-2026-17459CVSS 2.1 · Low
A vulnerability was determined in perwendel spark up to 2.9.4. This vulnerability affects the function staticFiles.externalLocation of the file src/main/java/spark/resource/Extern…