
ShieldBreak PoC Claims Defender Patch Bypass Elevates to SYSTEM
Security researcher Chaotic Eclipse released ShieldBreak, a PoC claiming to bypass the Defender patch for RoguePlanet (CVE-2026-50656) and obtain a SYSTEM shell; the PoC reportedly works on Windows 11 25H2 and Windows Server 2025, with Windows 10 also vulnerable, and Defender’s defense-in-depth updates allegedly leak 8 bytes in some scenarios. Microsoft is investigating while issuing patches for other CVEs in the same wave, including LegacyHive (CVE-2026-62832) and WinSock (CVE-2026-68820), the latter now listed in CISA KEV.
