Microsoft fixed between 398 and 421 vulnerabilities across Windows, Office, Azure, Exchange, SharePoint, and other products . The CVE counts vary by source:
The single zero-day Microsoft confirmed as exploited in the wild is CVE-2026-68820, an elevation-of-privilege vulnerability in the Windows Ancillary Function Driver for WinSock (afd.sys) . Automox described it as "the driver behind Windows socket connections on effectively every endpoint"
. The bug allows a locally authenticated attacker to gain SYSTEM-level access on affected systems
.
CVE-2026-62832, publicly dubbed "LegacyHive," is an elevation-of-privilege vulnerability in the Windows User Profile Service stemming from improper link resolution before file access (CWE-59) . Microsoft rated it Important with a CVSS score of 7.8, and assessed exploitation as "More Likely"
.
An authenticated attacker who has credentials for a second local account can run a specially crafted application to load another user's registry hive, potentially leading to administrative privileges . The flaw affects Windows 10, Windows 11, and Windows Server 2022/2025 prior to patched builds
.
On August 12, 2026 — the day after Patch Tuesday — researcher Nightmare Eclipse (also known as Chaotic Eclipse) published a proof-of-concept exploit called ShieldBreak . According to the researcher, ShieldBreak is a complete bypass of Microsoft's July 2026 patch for CVE-2026-50656 ("RoguePlanet"), a race-condition privilege-escalation flaw in the Microsoft Defender Malware Protection Engine (mpengine.dll)
.
ShieldBreak reportedly grants NT AUTHORITY\SYSTEM privileges on fully patched Windows 10, Windows 11, and Windows Server systems . The exploit uses a different attack path than its predecessor: while RoguePlanet exploited a filesystem race condition involving virtual disks, ShieldBreak hooks user-mode callbacks to alter file contents during Defender's cloud-hydration scan via the Windows Cloud Filter API (cfapi)
. The researcher stated the proof-of-concept achieves a "100% success rate" on Windows 11 25H2 and Windows Server 2025
.
Some analysts noted that Microsoft may have already silently patched the bypass vector . However, as of the publication of ShieldBreak, no official Microsoft fix was available to close the bypass
. Independent researchers, including Howler Cell, confirmed successful reproduction on a fully patched Windows 11 Pro host
.
The ShieldBreak release is the latest chapter in an escalating dispute between Microsoft and the anonymous researcher Nightmare Eclipse.
Since April 2026, Nightmare Eclipse has publicly disclosed nine zero-day exploits, including earlier flaws named RedSun, UnDefend, BlueHammer, YellowKey, GreenPlasma, and MiniPlasma . Three of these — BlueHammer, RedSun, and UnDefend — were confirmed as exploited in the wild and added to the CISA Known Exploited Vulnerabilities (KEV) catalog
.
On May 27, 2026, the Microsoft Security Response Center (MSRC) published a post threatening criminal prosecution against the researcher . Microsoft also disabled the researcher's accounts on GitHub (owned by Microsoft) and GitLab
. The move triggered a major backlash from the security community
. By June 1, 2026, Microsoft partially walked back its threats, publicly clarifying it has "no intention to pursue action against individuals conducting or publishing their security research"
.
Nightmare Eclipse has continued publishing zero-day exploits throughout the dispute, with ShieldBreak arriving immediately after the August 2026 Patch Tuesday release . The researcher claims that prior vulnerability reports through Microsoft's official channels were ignored, motivating the public disclosures
.