Web_Logo
Remote Support
Security Alert: Microsoft Defender Zero-Day RoguePlanet Still Unpatched
Home » Security Alerts  »  Security Alert: Microsoft Defender Zero-Day RoguePlanet Still Unpatched

Security Alert: Microsoft Defender Zero-Day RoguePlanet Still Unpatched

A vulnerability nicknamed RoguePlanet (CVE-2026-50656) in Microsoft Defender allows an attacker to gain full system-level control of any Windows 10 or Windows 11 PC — even machines with all current updates applied. Microsoft has confirmed the issue and says a patch is in development, but no fix has been released yet.

  • What it is: A race condition in Microsoft Defender's real-time scanning engine that can be exploited to give an attacker NT AUTHORITY\SYSTEM level access — the highest privilege level on a Windows machine.
  • Who is affected: All businesses running Windows 10 or Windows 11 with Microsoft Defender enabled, which covers the vast majority of Windows PCs by default.
  • What the risk is: An attacker who can run code on a machine — for example, through a phishing email or a malicious file download — can use this to take complete control of the system. Active exploitation by criminal actors has been confirmed, with forensic evidence pointing to opportunistic use of the public proof-of-concept.
  • What to do now: No patch is available. Keep Microsoft Defender definitions up to date, avoid opening unexpected attachments or clicking unknown links, and apply any out-of-band Microsoft security update for this issue as soon as one is released.

We recommend monitoring Microsoft's security update releases closely over the coming days and applying any emergency patch for CVE-2026-50656 immediately when it becomes available. If you are unsure whether your systems are protected, contact your IT provider.

Sources: BleepingComputer, SecurityWeek, Help Net Security