Skip to main content

CVE detail

CVE-2026-50656

Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RoguePlanet ".

CVSS 7.8 · HighBuzz score 50.0

Buzz score

Why this CVE is surfacing

Buzz score total 50.0

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 30.0 · diversity 20.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Mention score
30.0
26 evidence mentions in the snapshot
Diversity score
20.0
11 sources across 3 categories
KEV score
0.0
No KEV entry observed
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
19
within the 30d window
Peak daily
10
highest bucket

Evidence

Source links by recency

Newest mentions first
26 source links · newest first
  • ation of remediations as a trailing indicator. SharePoint: critical auth bypass by Rapid7 Today sees the publication of CVE-2026-55040 , a critical authentication bypass in Microsoft SharePoint. Discovered by Rapid7 Senior Principal Security Researcher Stephen Fewer , and published today in coordination with Microsoft, this vulnerability is the first i

    vendorwww.rapid7.comJul 14, 2026, 10:00 PM
  • erica Breach Exposes 7 Million Driver’s Licenses After Employee Account Hack Microsoft fixed Defender flaw RoguePlanet (CVE-2026-50656) Fake VPN and 7-Zip Apps Turn Victims Into Residential Proxy Nodes Ubiquiti Patches Critical UniFi OS Flaws Allowing Command Injection and Privilege Escalation A Hacker Claims 35 GB of Accenture Source Code. The Company

    newssecurityaffairs.comJul 12, 2026, 4:58 AM
  • ica Breach Exposes 7 Million Driver’s Licenses After Employee Account Hack | Microsoft fixed Defender flaw RoguePlanet (CVE-2026-50656) | Fake VPN and 7-Zip Apps Turn Victims Into Residential Proxy Nodes | Ubiquiti Patches Critical UniFi OS Flaws Allowing Command Injection and Privilege Escalation | A Hacker Claims 35 GB of Accenture Source Code. The C

    newssecurityaffairs.comJul 10, 2026, 10:22 AM
  • ica Breach Exposes 7 Million Driver’s Licenses After Employee Account Hack | Microsoft fixed Defender flaw RoguePlanet (CVE-2026-50656) | Fake VPN and 7-Zip Apps Turn Victims Into Residential Proxy Nodes | Ubiquiti Patches Critical UniFi OS Flaws Allowing Command Injection and Privilege Escalation | A Hacker Claims 35 GB of Accenture Source Code. The C

    newssecurityaffairs.comJul 10, 2026, 8:25 AM
  • to as RoguePlanet continuing the string of Microsoft Defender flaws that have been identified. RoguePlanet, tracked as CVE-2026-50656 , is a race condition privilege escalation vulnerability. The POC code the researcher posted on GitHub can result in a System privilege shell running on the compromised system. CISA has announced the previously reported

    newswww.helpnetsecurity.comJul 10, 2026, 7:30 AM
  • ortion crew hijacks Microsoft 365 accounts via fake passkey setup Microsoft releases fix for RoguePlanet Defender flaw (CVE-2026-50656) Report: How to Implement a Continuous Offensive Security Testing Program Resources Download: Secure Foundations for AI Workloads on AWS Download: Automating Pentest Delivery Guide CIS Benchmarks March 2026 Update Don't

    newswww.helpnetsecurity.comJul 10, 2026, 6:00 AM
  • ortion crew hijacks Microsoft 365 accounts via fake passkey setup Microsoft releases fix for RoguePlanet Defender flaw (CVE-2026-50656) Report: How to Implement a Continuous Offensive Security Testing Program Resources Download: Secure Foundations for AI Workloads on AWS Download: Automating Pentest Delivery Guide CIS Benchmarks March 2026 Update Don't

    newswww.helpnetsecurity.comJul 10, 2026, 5:30 AM
  • ica Breach Exposes 7 Million Driver’s Licenses After Employee Account Hack | Microsoft fixed Defender flaw RoguePlanet (CVE-2026-50656) | Fake VPN and 7-Zip Apps Turn Victims Into Residential Proxy Nodes | Ubiquiti Patches Critical UniFi OS Flaws Allowing Command Injection and Privilege Escalation | A Hacker Claims 35 GB of Accenture Source Code. The C

    newssecurityaffairs.comJul 9, 2026, 9:29 PM
  • t issued an out-of-band patch for RoguePlanet , an elevation-of-privilege vulnerability in Windows Defender, tracked as CVE-2026-50656. The high-severity flaw, which received a 7.8 CVSS score from Microsoft, could allow an attacker to escalate privileges on a Windows device from a basic user to the highest SYSTEM-level access, which would give them com

    newswww.darkreading.comJul 9, 2026, 8:21 PM
  • ica Breach Exposes 7 Million Driver’s Licenses After Employee Account Hack | Microsoft fixed Defender flaw RoguePlanet (CVE-2026-50656) | Fake VPN and 7-Zip Apps Turn Victims Into Residential Proxy Nodes | Ubiquiti Patches Critical UniFi OS Flaws Allowing Command Injection and Privilege Escalation | A Hacker Claims 35 GB of Accenture Source Code. The C

    newssecurityaffairs.comJul 9, 2026, 6:11 PM
  • pse after months of public sparring over the company's handling of vulnerability reports. The vulnerability, tracked as CVE-2026-50656, was addressed through an update to the Microsoft Malware Protection Engine rather than via its monthly Patch Tuesday bundle. Microsoft said customers should ensure they're running the latest engine version to receive t

    newswww.theregister.comJul 9, 2026, 1:30 PM
  • Microsoft has finally released a security update for its Microsoft Malware Protection Engine, which fixes CVE-2026-50656, the Windows Defender local privilege escalation vulnerability triggered by the RoguePlanet exploit. The vulnerability and the fix CVE-2026-50656 is due to improper link resolution before file access, affects Windows 10

    newswww.helpnetsecurity.comJul 9, 2026, 12:14 PM
  • Microsoft fixes RoguePlanet zero-day in DefenderMalwarebytes Labs

    The RoguePlanet zero-day is now fixed in Microsoft Defender. Here's how to make sure your system is protected.

    newswww.malwarebytes.comJul 9, 2026, 11:38 AM
  • The privilege escalation vulnerability tracked as CVE-2026-50656 has been patched with a Microsoft Malware Protection Engine update. The post Microsoft Patches Defender ‘RoguePlanet’ Vulnerability appeared first on SecurityWeek .

    newswww.securityweek.comJul 9, 2026, 10:28 AM
  • Microsoft fixed RoguePlanet (CVE-2026-50656), a Defender flaw allowing local attackers to gain higher privileges through the Malware Protection Engine. Microsoft released security updates for RoguePlanet, a vulnerability tracked as CVE-2026-50656 (CVSS score of 7

    newssecurityaffairs.comJul 9, 2026, 10:17 AM
  • lnerability known as RoguePlanet, nearly a month after details of the flaw became public. The vulnerability, tracked as CVE-2026-50656 (CVSS score: 7.8), is a privilege escalation issue in the Microsoft Malware Protection Engine ("mpengine.dll"), which provides scanning, detection, and cleaning capabilities for its antivirus and

    newsthehackernews.comJul 9, 2026, 8:48 AM
  • fender zero-day vulnerability known as "RoguePlanet," disclosed after the June 2026 Patch Tuesday. The flaw (tracked as CVE-2026-50656 ) was disclosed by a security researcher using the "Nightmare Eclipse" handle as part of an ongoing dispute with Microsoft over the company's bug bounty and vulnerability disclosure practices. They also shared a proof-o

    newswww.bleepingcomputer.comJul 9, 2026, 5:42 AM
  • ica Breach Exposes 7 Million Driver’s Licenses After Employee Account Hack | Microsoft fixed Defender flaw RoguePlanet (CVE-2026-50656) | Fake VPN and 7-Zip Apps Turn Victims Into Residential Proxy Nodes | Ubiquiti Patches Critical UniFi OS Flaws Allowing Command Injection and Privilege Escalation | A Hacker Claims 35 GB of Accenture Source Code. The C

    newssecurityaffairs.comJul 8, 2026, 11:09 AM
  • ica Breach Exposes 7 Million Driver’s Licenses After Employee Account Hack | Microsoft fixed Defender flaw RoguePlanet (CVE-2026-50656) | Fake VPN and 7-Zip Apps Turn Victims Into Residential Proxy Nodes | Ubiquiti Patches Critical UniFi OS Flaws Allowing Command Injection and Privilege Escalation | A Hacker Claims 35 GB of Accenture Source Code. The C

    newssecurityaffairs.comJul 8, 2026, 7:24 AM
  • Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: A hardware neural network backdoor that hides in plain sight Deep learning systems on edge devices often rely on third-party-designed FPGAs and ASICs for performance and efficiency, creating supply chain risks. Researchers from the University of Tennessee and the University of Florida developed HAMLOCK, a backdoor attack that splits malicious functionality between hardware and software, making detection more difficult. Onspring … More →

    newswww.helpnetsecurity.comJun 21, 2026, 8:00 AM
  • Microsoft says it’s working on a fix for an unpatched Defender vulnerability that can give attackers the highest level of access on Windows.

    newswww.malwarebytes.comJun 18, 2026, 12:58 PM
  • Microsoft confirmed the RoguePlanet Defender zero-day (CVE-2026-50656), a privilege escalation flaw, and is developing a security patch. Microsoft has acknowledged the RoguePlanet zero-day affecting Microsoft Defender, tracked as CVE-2026-50656 (CVSS score of 7.8). The vulnerability allows privilege escalation through the Microsoft Malware Protection Engine. The company stated it is aware of the issue and is […]

    newssecurityaffairs.comJun 18, 2026, 9:21 AM
  • Microsoft has acknowledged the local elevation of privilege issue in Microsoft Defender that can be triggered via the “RoguePlanet” exploit, and is “working to provide a high quality security update that addresses this vulnerability.” The vulnerability, which has been assigned the CVE-2026-50656 identifier, stems from improper link resolution before file access, and can be exploited in low complexity attacks by authenticated attackers, with no user interaction required. Zero-day exploits by Nightmare Eclipse RoguePlanet is one … More →

    newswww.helpnetsecurity.comJun 17, 2026, 11:26 AM
  • The public PoC code exploits a race condition in Microsoft Defender to spawn a command prompt with System privileges.

    newswww.securityweek.comJun 17, 2026, 9:41 AM
  • No excerpt available.

    Exploitgithub.comJun 16, 2026, 7:16 PM
  • Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RoguePlanet ". We are working to provide a high quality security update that addresses this vulnerability. We will provide information in this CVE when the update is available.

    vendormsrc.microsoft.comJun 16, 2026, 2:00 PM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence
  • CVE-2026-41091

    Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally.

    CVSS 7.8 · High
    KEV listed23 mentions
  • CVE-2026-67433

    Linuxfabrik monitoring-plugins provides Python monitoring plugins for Icinga, Nagios, and related monitoring systems. In version 6.0.0, the logfile check legacy database migration…

    CVSS 5.8 · Medium
    2 mentions
  • CVE-2026-13268

    G DATA Total Security Backup Service Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installa…

    CVSS 7.8 · High
    1 mention
  • CVE-2026-13723

    A vulnerability in the `zipx.Unzip` extraction routine of Develar's app-builder allows an attacker to overwrite arbitrary files on macOS APFS by exploiting a Unicode Normalization…

    CVSS 6.5 · Medium
    4 mentions
  • CVE-2026-43765

    This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to modify prote…

    CVSS 5.5 · Medium
    3 mentions
  • CVE-2026-17459

    A vulnerability was determined in perwendel spark up to 2.9.4. This vulnerability affects the function staticFiles.externalLocation of the file src/main/java/spark/resource/Extern…

    CVSS 2.1 · Low
    6 mentions