Security researcher Nightmare Eclipse has dropped a fresh zero-day exploit leading to privilege escalation on Windows.

Also known as Chaotic Eclipse, the disgruntled researcher released multiple zero-day exploits targeting Microsoft products over the past several months, usually right after the Patch Tuesday security updates.

Right on cue, the new proof-of-concept (PoC) exploit, dubbed ShieldBreak, was published on August 2026 Patch Tuesday. It targets a vulnerability in Microsoft Defender, allowing any user to gain System privileges.

According to Nightmare Eclipse, the exploit is a RoguePlanet patch bypass, works on the latest Windows 11 versions and on Windows Server 2025, and likely impacts Windows 10 machines as well.

Tracked as CVE-2026-50656, RoguePlanet is a race condition flaw in Defender that Nightmare Eclipse dropped as a zero-day on June 9. Microsoft acknowledged the exploit on June 16 and released fixes for it on July 9.