In summary
- Nightmare Eclipse has released a proof of concept called ShieldBreak, a zero-day flaw in Defender that allows privilege escalation to SYSTEM with no patch yet available.
- The exploit bypasses Microsoft’s July fix for RoguePlanet, CVE-2026-50656, and researchers Will Dormann and Kevin Beaumont have both confirmed it works on the latest Windows 11.
- Microsoft’s August 2026 patch batch of 421 fixes also addresses a WinSock privilege escalation bug already exploited by North Korean IT workers targeting aerospace and defence firms.
Nightmare Eclipse, the pseudonymous security researcher turned Microsoft nemesis, has released another proof of concept (PoC) with source code for a vulnerability.
Called ShieldBreak the vulnerability lies in the Defender anti-malware tools and is a zero-day flaw for which no patch currently exists and allows for privilege escalation to the SYSTEM user in Windows.
The researcher said the PoC was tested in the latest version of Windows 11 25h2, and the Canary channel, as well as Windows Server 2025,
Nightmare Eclipse claims the PoC has a 100 percent success rate.
“Please note that Windows 10 (and respective server editions) are not currently supported, they are however vulnerable to ShieldBreak as well,” Nightmare Eclipse wrote.
Nightmare Eclipse’s exploit gets around the fix CVE-2026-50656, a Defender elevation-of-privilege flaw known as RoguePlanet that Microsoft patched in July and rated 7.8 on the CVSS scale.,
Will Dormann, principal vulnerability analyst at Tharros, confirmed the exploit works when Defender is enabled in Windows.
There is no evidence so far that ShieldBreak has been used in real-world attacks.
Security researcher Kevin Beaumont said he had tried the exploit and found it worked on the latest Windows 11, and published Microsoft Defender Advanced Hunting queries that defenders could use.
Beaumont said ShieldBreak operated differently from the original RoguePlanet race condition rather than simply replaying it.
ShieldBreak is the latest in a series of Windows exploits Nightmare Eclipse had released through 2026, a campaign fuelled by open grievance over Microsoft’s handling of the researcher’s disclosures.
Microsoft threatened legal measures against the researcher and others disclosing serious bugs but had to back down following a backlash from the security industry community.
For August 2026, Microsoft released a large, 421-set of security patches.
One vulnerability highlighted by Microsoft involves a privilege escalation in low-level Windows Sockets networking component (WinSock).
That vulnerability has been exploited by North Korean fraudulent IT workers, to target the aerospace and defence sectors, with the United States Cybersecurity and Infrastructure Security Agency (CISA) adding the bug to its must-fix catalogue, aimed at government agencies.

