Threat Intelligence

New 'ShieldBreak' Exploit Bypasses Windows Defender Patch, Grants Full System Access

The Hacker News · 12 Aug 2026
Key Takeaway Keep an eye on Microsoft security advisories and apply any follow-up patches for CVE-2026-50656 as soon as they're released, since the original fix can reportedly be bypassed.

A security researcher known as Chaotic Eclipse has released proof-of-concept (PoC) code for a vulnerability dubbed ShieldBreak, which bypasses a patch Microsoft issued for an earlier flaw known as RoguePlanet (CVE-2026-50656, CVSS 7.8) in Microsoft Defender for Windows.

According to the report, the ShieldBreak PoC effectively undoes the protection that Microsoft's fix was meant to provide, potentially allowing an attacker who exploits it to gain SYSTEM-level access — the highest level of privilege on a Windows device. This means that even businesses that applied the RoguePlanet patch may still be exposed if Microsoft has not yet released a fix for ShieldBreak.

While no active exploitation has been confirmed at this stage, the public release of PoC code often accelerates real-world attacks, as it lowers the technical barrier for cybercriminals to develop working exploits. Small businesses running Windows systems with Microsoft Defender should watch closely for official guidance and updates from Microsoft, as patch bypasses like this can undermine confidence in previously 'fixed' vulnerabilities.

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.