Microsoft has begun rolling out patches for a Defender vulnerability known as RoguePlanet, roughly one month after a researcher published a zero-day exploit for it.

Officially tracked as CVE-2026-50656, the vulnerability leverages a race condition, enabling an attacker to escalate privileges to System.

A PoC exploit for RoguePlanet was made public on June 9 by a researcher known as Nightmare Eclipse (Chaotic Eclipse), who over the past months released several Windows exploits following a quarrel with Microsoft over the company’s handling of vulnerability reports.

The researcher noted at the time that the exploit had not achieved a 100% success rate during testing, but it could be redesigned to become more stable.

Microsoft published an advisory for the vulnerability on June 16 and updated it on July 8 to inform customers about the availability of patches.