CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

Researcher Releases Windows Zero-Day PoC LegacyHive Hours After July 2026 Patch Tuesday

July 15, 2026

Security researcher Chaotic Eclipse (aka Nightmare-Eclipse) has released a proof-of-concept (PoC) exploit called LegacyHive, targeting a Windows User Profile Service (ProfSvc) arbitrary hive load elevation of privileges vulnerability. The exploit is functional on all supported desktop and server versions of Windows, including those with the latest July 2026 Patch Tuesday updates. The researcher claims the PoC was stripped down to prevent public exploitation, and that the original exploit could load any hive without additional credentials.

The disclosure follows a heated dispute between Chaotic Eclipse and Microsoft since April 2026, with the researcher releasing multiple exploits before patches were available. Three Microsoft Defender vulnerabilities disclosed by the researcher were actively exploited shortly after public disclosure. Earlier in July, Microsoft patched another Defender flaw (RoguePlanet) but the fix introduced a data leak issue.

Microsoft’s July 2026 Patch Tuesday addressed a record 622 flaws, including two actively exploited privilege escalation vulnerabilities in SharePoint Server (CVE-2026-56164, CVSS 5.3) and Active Directory Federation Services (CVE-2026-56155, CVSS 7.8). CISA added both to its Known Exploited Vulnerabilities (KEV) catalog, mandating fixes by July 17 and July 28, 2026, respectively. CISA also warned of active exploitation of multiple SharePoint Server flaws (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164) enabling unauthorized access, remote code execution, and post-exploitation activities including IIS machine key theft and malware deployment.

Additionally, the update addresses a critical SharePoint Server security feature bypass vulnerability (CVE-2026-55040, CVSS 9.1) that allows remote unauthenticated attackers to bypass authentication via JWT token validation issues. Rapid7 noted this bypass can be chained with other vulnerabilities.

CVEs: CVE-2026-56164, CVE-2026-56155, CVE-2026-32201, CVE-2026-45659, CVE-2026-55040

Companies: Microsoft, Rapid7, Action1, CISA

Products: Microsoft Defender, SharePoint Server, Active Directory Federation Services