Microsoft’s fix for the Windows Defender zero-day RoguePlanet (CVE-2026-50656) is facing new scrutiny after researcher Chaotic Eclipse alleged that changes in mpengine.dll introduced fresh problems in the Microsoft Malware Protection Engine. The original flaw was described as a race-condition privilege-escalation bug that could yield a SYSTEM shell and had public proof-of-concept code, adding to mounting pressure on defenders as Microsoft disclosed more than 200 CVEs in a single month across Windows, Office, SharePoint Server, Visual Studio, and .NET.
According to the researcher, the patched engine may expose an eight-byte information disclosure and a more practical denial-of-service condition that can fill local storage by abusing oversized Zone.Identifier alternate data streams during Defender scanning over SMB. In the reported scenario, MsMpEng.exe continues caching content from a controlled SMB server while a later read request is stalled, eventually exhausting disk space; the behavior was reportedly reproduced on Windows 11 25H2 and Windows Server 2025. Microsoft previously addressed RoguePlanet in engine version 1.1.26060.3008, but had not publicly confirmed the alleged post-patch issues at the time of reporting.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
Researcher Chaotic Eclipse claimed that Microsoft's RoguePlanet patch introduced an eight-byte information disclosure and a denial-of-service condition that can exhaust local disk space. The behavior was reportedly reproduced on Windows 11 version 25H2 and Windows Server 2025 using a controlled SMB server.
Microsoft previously fixed CVE-2026-50656 in Microsoft Malware Protection Engine version 1.1.26060.3008. The fix is referenced in later reporting about alleged post-patch issues.
CISA said that previously reported Microsoft Defender vulnerabilities, including BlueHammer, are already being exploited by ransomware operators. This indicated active in-the-wild abuse of related Defender flaws.
Microsoft announced RoguePlanet, tracked as CVE-2026-50656, as a Windows Defender zero-day. The flaw was described as a race-condition privilege-escalation issue with public proof-of-concept code capable of yielding a SYSTEM shell.
After patching six ColdFusion vulnerabilities with a maximum CVSS score of 10, Adobe moved to issuing two security releases per month. The change was cited as part of a broader acceleration in vendor patch activity.
In June 2026, Microsoft disclosed more than 200 CVEs, including 116 affecting Windows 11 and 104 affecting Windows 10, and issued fixes across Office, SharePoint Server, Visual Studio, and .NET.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
cryptika.com
Open sourcecybersecuritynews.com
Open sourcehelpnetsecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.