Overview
- The researcher known as Chaotic Eclipse published a proof-of-concept called ShieldBreak on August 12, 2026 that they say fully bypasses Microsoft’s July patch for CVE-2026-50656 (RoguePlanet).
- Independent analyst Will Dormann confirmed the exploit works when Microsoft Defender is enabled and noted the PoC generally requires running a local app to trigger SYSTEM-level privilege escalation.
- Microsoft shipped fixes for RoguePlanet in July but has not released a ShieldBreak-specific patch and did not immediately comment to reporters when contacted on the new disclosure.
- The release intensifies a running dispute between the anonymous researcher and Microsoft that has included public zero-day dumps, MSRC warnings about out-of-policy disclosures, and accusations that Microsoft revoked the researcher’s reporting access.
- The timing raises operational urgency for defenders because CISA has added a separate actively exploited Windows zero-day to its KEV list with an August 25 remediation deadline for federal agencies and researchers have published detection and mitigation guidance such as disabling Defender as a temporary, imperfect workaround.