A security researcher known as Nightmare Eclipse has released a new Microsoft Defender zero-day exploit named "ShieldBreak" after Microsoft released the August 2026 Patch Tuesday security updates. The new vulnerability is described as a bypass for RoguePlanet, another Defender privilege escalation flaw disclosed in June and patched by Microsoft one month later. However, cybersecurity expert Kevin Beaumont, who also published ShieldBreak exploitation detection queries for Microsoft Defender for Endpoint, said that the two exploits work very differently. "RoguePlanet was a filesystem race condition vuln that uses virtual disks and NT native file manipulation to trick quarantine process into overwriting system files," Beaumont noted. "ShieldBreak user-mode callback hook to change file contents during a Defender cloud-hydration scan via cfapi (Cloud Filter API)." According to Nightmare Eclipse, ShieldBreak can be used to gain SYSTEM privileges on fully patched Windows 10, Windows 11, and Windows Server systems. "Microsoft has failed to properly patch the RoguePlanet vulnerability CVE-2026-50656, this PoC demonstrates a full patch bypass," they said. "The PoC was tested in the latest version of windows 11 25h2 (+Canary channel) and windows server 2025, the PoC also have a 100% success rate. Please note that Windows 10 (and respective server editions) are not currently supported, they are however vulnerable to ShieldBreak as well." Will Dormann, principal vulnerability analyst at ...
New Microsoft Defender 'ShieldBreak' zero-day grants SYSTEM privileges
BleepingComputer
·Sergiu Gatlan
·Published Aug 12, 2026
·Updated
Affected Software
1 affected component
Microsoft Defender=Windows 10 (fully patched), =Windows 11 (fully patched), =Windows Server (fully patched), =Windows 11 25H2 (+Canary channel), =Windows Server 2025
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a new zero-day exploit for Microsoft Defender named 'ShieldBreak' that grants SYSTEM privileges.
2
What security implications are discussed in the article?
The article highlights the risk of privilege escalation due to the ShieldBreak exploit allowing unauthorized access at the SYSTEM level.
3
What products or software are affected by this vulnerability?
The vulnerability affects Microsoft Windows 10, Microsoft Windows 11, and Microsoft Windows Server 2025.
4
Who released the information about the zero-day exploit?
A security researcher known as Nightmare Eclipse released the details of the ShieldBreak exploit.
5
When was the ShieldBreak exploit made public?
The ShieldBreak exploit was published on August 12, 2026, shortly after Microsoft's Patch Tuesday updates.