
A security researcher known as Nightmare Eclipse has released a new Microsoft Defender zero-day exploit called ShieldBreak, published hours after Microsoft’s August 2026 Patch Tuesday security updates. The exploit is a bypass for RoguePlanet, a Defender privilege-escalation vulnerability (CVE-2026-50656) that Microsoft patched just last month. While RoguePlanet used a filesystem race condition involving virtual disks and NT native file manipulation, ShieldBreak takes a different approach — it hooks user-mode callbacks to alter file contents during Defender’s cloud-hydration scan via the Windows Cloud Filter API (cfapi). The researcher claims a 100% success rate on fully patched Windows 11 (including the latest Canary channel build) and Windows Server 2025. Principal vulnerability analyst Will Dormann independently confirmed the exploit works.
Microsoft has not yet released a patch for ShieldBreak. The disclosure is part of an escalating public dispute between Nightmare Eclipse and Microsoft over the company’s vulnerability disclosure and bug bounty practices; Microsoft previously warned of potential legal action against those engaging in “malicious activity causing real harm,” a statement widely read in the security community as a threat directed at the researcher. Since April 2026, Nightmare Eclipse has publicly disclosed a series of Windows zero-days — including LegacyHive, BlueHammer, RedSun, and now ShieldBreak — many of which remain unpatched.
How to check if you’re affected
Affected versions include Windows 10, Windows 11, and Windows Server with Microsoft Defender enabled. There is currently no official patch. Keeping Defender enabled remains the baseline recommendation — disabling it would create a far larger attack surface. Watch for a Microsoft security update addressing CVE-2026-50656’s patch bypass.
