ShieldBreak Zero-Day Bypasses Microsoft Defender Patch
A new zero-day vulnerability in Microsoft Defender has been discovered by security researcher Chaotic Eclipse. The flaw, dubbed ShieldBreak, bypasses the patch for CVE-2026-50656 (RoguePlanet) and allows attackers to execute code with SYSTEM-level privileges.
The PoC was tested on Windows 11 25H2 and Windows Server 2025, with a 100% success rate. Chaotic Eclipse criticized Microsoft for failing to properly patch the RoguePlanet vulnerability, stating that the PoC demonstrates a full patch bypass.
Microsoft had released security updates for RoguePlanet in early July, but it appears that these patches did not address all aspects of the vulnerability.