A new unpatched vulnerability in Microsoft Defender, dubbed "RoguePlanet" (CVE-2026-50656), allows attackers on a Windows computer to gain full SYSTEM-level access — even on machines that have installed all June 2026 security updates.
- What it is: A race condition flaw in the Microsoft Defender security engine that can be exploited to open a command prompt with the highest level of Windows privileges (SYSTEM). A working proof-of-concept exploit has been publicly released on GitHub.
- Who is affected: Any organisation running Windows 10 or Windows 11 with Microsoft Defender — which includes the vast majority of business computers. The vulnerability affects fully up-to-date systems.
- What the risk is: An attacker who can run code on the target machine — for example, through a phishing email or a remote access session — could use this exploit to take complete control of the system.
- What action is needed: Microsoft has acknowledged the vulnerability and is working on a patch. No fix is available yet. Businesses should ensure endpoint detection and response (EDR) tools are active and monitoring for unusual privilege escalation. Avoid clicking unexpected email attachments or running untrusted software.
We will notify clients as soon as a patch is released. Contact us if you have concerns about your endpoint security posture.
Sources: BleepingComputer | Help Net Security | SecurityWeek