CVE-2026-50656
published 2026-06-16CVE-2026-50656: Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RoguePlanet ".
PriorityP339high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
EPSS
3.39%
87.5th percentile
Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RoguePlanet ".
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_malware_protection_engine | >= 1.1.0.0 < 1.1.26060.3008 | 1.1.26060.3008 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RoguePlanet ".
ghsa_unreviewed·2026-06-16
CVE-2026-50656 [HIGH] CWE-59 Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RoguePlanet ".
Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RoguePlanet ". We are working to provide a high quality security update that addresses this vulnerability. We will provide information in this CVE when the update is available.
VulDB
Microsoft Malware Protection Engine link following
vuldb·2026-06-16·CVSS 7.8
CVE-2026-50656 [HIGH] Microsoft Malware Protection Engine link following
A vulnerability classified as critical has been found in Microsoft Malware Protection Engine. This vulnerability affects unknown code. The manipulation leads to link following.
This vulnerability is listed as CVE-2026-50656. The attack must be carried out locally. There is no available exploit.
No detection rules found.
No public exploits indexed.
Hackernews
Microsoft Patches RoguePlanet Defender Flaw That Can Grant SYSTEM Privileges
blogs_hackernews·2026-07-09·CVSS 7.8
CVE-2026-50656 [HIGH] Microsoft Patches RoguePlanet Defender Flaw That Can Grant SYSTEM Privileges
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Microsoft Patches RoguePlanet Defender Flaw That Can Grant SYSTEM Privileges
Microsoft has released security updates for a Defender vulnerability known as RoguePlanet, nearly a month after details of the flaw became public.
The vulnerability, tracked as CVE-2026-50656 (CVSS score: 7.8), is a privilege escalation issue in the Microsoft Malware Protection Engine ("mpengine.dll"), which provides scanning, detection, and cleaning capabilities for its antivirus and antispyware software.
The issue has been remediated in Microsoft Malware Protection Engine version 1.1.26060.3008, along with defense-in-depth updates to harden unspe
Checkpoint
22nd June – Threat Intelligence Report
blogs_checkpoint·2026-06-22
CVE-2026-42824 22nd June – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 22nd June – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 22nd June, please download our Threat Intelligence Bulletin.
TOP ATTACKS AND BREACHES
Texas Parks and Wildlife Department has been affected by a third-party data breach involving its license system vendor. The incident exposed driver’s license information, passport numbers, emails, phone numbers, and residential addresses for 3,087,721 hunting and fishing license customers. Social Security numbers and payment dat
Bleepingcomputer
Microsoft working on Defender patch for RoguePlanet zero-day
blogs_bleepingcomputer·2026-06-17·CVSS 7.8
CVE-2026-50656 [HIGH] Microsoft working on Defender patch for RoguePlanet zero-day
## Microsoft working on Defender patch for RoguePlanet zero-day
## Sergiu Gatlan
"The exploit is a race condition, so it's a hit or miss. I have managed to get a 100% success rate on some machines while it struggled to work on others," Nightmare Eclipse said. "The PoC for RoguePlanet works regardless if real time protection is on or not," they added in a Tuesday update .
"Microsoft is aware of the reported vulnerability and is actively investigating the validity and potential applicability of these claims. Microsoft is committed to investigating security issues and updating impacted products to protect customers as soon as possible," a Microsoft spokesperson told BleepingComputer when asked for a statement at the time.
## Now tracked as CVE-2026-50656, waiting for a patch
On Tuesday,
Hackernews
Microsoft Confirms RoguePlanet Defender Zero-Day, Says Patch is in Development
blogs_hackernews·2026-06-17·CVSS 7.8
CVE-2026-50656 [HIGH] Microsoft Confirms RoguePlanet Defender Zero-Day, Says Patch is in Development
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Microsoft Confirms RoguePlanet Defender Zero-Day, Says Patch is in Development
Microsoft has formally disclosed that it's working to release a patch to address a Defender zero-day codenamed RoguePlanet .
The vulnerability has now been assigned the CVE identifier CVE-2026-50656 (CVSS score: 7.8), with the tech giant describing it as a privilege escalation flaw.
"Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender, publicly referred to as 'RoguePlanet,'" the company said. "We are working to provide a high-quality security update that addresses this vulnerability."
2026-06-16
Published