Nightmare Eclipse Unleashes ShieldBreak Zero-Day Exploit on Fully Patched Windows Systems
A serial zero-day hunter known as Nightmare Eclipse has released another exploit that allows attackers to gain SYSTEM privileges on fully patched Windows systems. This latest vulnerability, called ShieldBreak, bypasses Microsoft's RoguePlanet patch (CVE-2026-50656) and targets Defender.
The researcher claims the exploit works on all versions of Windows 10, Windows 11, and Windows Server systems, including the latest version of Windows 11 and Windows Server 2025. Nightmare Eclipse says the PoC has a 100% success rate in testing.
This is not the first vulnerability released by Nightmare Eclipse, who has published nine other zero-days since April. The researcher claims to be targeting Microsoft specifically due to past disputes over vulnerability disclosure rules.
Microsoft did not respond to requests for comment on whether and when it would patch ShieldBreak, but experts say defenders should use hunting queries provided by another security expert, Kevin Beaumont, to detect any stealthy threats.