INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Microsoft patches LegacyHive Zero-Day Vulnerability

| 2026-08-13 17:46 CRITICAL HIGH
Executive Summary AI-generated
The newly discovered vulnerability, known as LegacyHive, has been patched by Microsoft and other companies in response to a recent security update. This zero-day flaw was first reported on August 13, 2026, and affects Windows systems running older versions of the operating system. The exploit allows local attackers to gain administrator privileges, making it possible for them to modify the registry hive and execute code automatically when an admin account logs in. Microsoft has now released patches for these vulnerabilities as part of its August Patch Tuesday updates, which have been tracking this CVE since June 2026.
Technical Mitigations AI-generated
* Use Microsoft Defender for Endpoint (MDE) with the latest patches, including official LegacyHive and RoguePlanet vulnerabilities. * Implement a layered security approach that includes: + User interaction is not required to exploit vulnerabilities like LegacyHive or ShieldBreak. + Authentication and authorization mechanisms can help prevent unauthorized access even if credentials are obtained through exploitation. + Regular software updates and patching can reduce the risk of future vulnerabilities. + Monitoring and incident response plans should be in place to quickly respond to security incidents.
Technical Observables
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-72971CVE-2026-72971 CVE-2026-62832CVE-2026-62832 CVE-2026-50656CVE-2026-50656 CVE-2026-68820CVE-2026-68820
Target & Sectors
NORTH_AMERICA NORTH_AMERICA legallegal defensedefense
Incident Timeline
‎April 2026
Nightmare Eclipse disclosed zero-day flaws in Microsoft Windows components, including ShieldBreak and LegacyHive.
infrastructure Windows
organisation ShieldBreak
organisation YellowKey
organisation BlueHammer
organisation GreenPlasma
organisation Microsoft Defender
organisation BitLocker
organisation MiniPlasma
‎June 2026
Threat actors used the YellowKey zero-day exploit to target fully updated Windows 10 and Windows 11 systems running the June 2026 Patch Tuesday updates.
infrastructure Windows
organisation YellowKey
organisation BlueHammer
organisation GreenPlasma
organisation BitLocker
organisation MiniPlasma
organisation RoguePlanet
general_metric 10 Windows
general_metric 11 Windows
‎2026/07/13
Threat actors exploited a previously unknown Windows User Profile Service privilege escalation vulnerability, CVE-2026-62832.
infrastructure Windows
vulnerability CVE-2026-62832
tactic Privilege Escalation
organisation Windows User Profile Service
general_metric 7.8 score
‎July 2026
Nightmare Eclipse published a proof-of-concept exploit for the Windows User Profile Service zero-day vulnerability known as LegacyHive.
infrastructure Windows
organisation Nightmare
organisation PoC
organisation the Windows User Profile Service
organisation LegacyHive
‎July 20
Threat actors used ACROS Security's 0Patch patches to target Windows systems running Windows 10 2004 or later and Windows Server 2022 or later.
infrastructure Windows
organisation ACROS Security
tactic T1584.004 - Server
general_metric 10 Windows
‎Aug 12, 2026
Threat actors exploited a previously unknown vulnerability in Microsoft Windows to gain unauthorized access and elevate their privileges.
‎2026/08/13
An attacker who already has code execution as a standard user can use the User Profile Service to load another user's registry hive, potentially that of a local administrator.
infrastructure Windows
organisation Microsoft
organisation ShieldBreak
organisation GreenPlasma
organisation BitLocker
organisation the Windows Collaborative Translation Framework
organisation CTFMON
organisation the Windows User Profile Service
organisation ProfSvc
data_breach 8 bytes
organisation CVE-2026
organisation Microsoft Defender
organisation CVSS
organisation the Windows Ancillary Function
organisation Windows Container Isolation FS Filter
organisation ShieldBreak Zero-Day
organisation Nightmare
organisation INFINITE NIGHTMARE
organisation MSNightmare
organisation PoC
organisation Chaotic Eclipse
organisation RoguePlanet
organisation YellowKey
organisation BlueHammer
organisation MiniPlasma
organisation Tharros
organisation BleepingComputer
organisation LegacyHive
organisation Vulnerability
organisation Microsoft Defender for Endpoint
organisation MDE
organisation The Blue Report 2026
organisation The Microsoft
infrastructure 7.8
organisation ShieldBreak PoC
organisation Coordinated Vulnerability Disclosure
organisation MSRC
organisation Microsoft’s Security Response Center
organisation the User Profile Service
organisation SecurityAffairs
organisation The Hacker News
‎August 2026
Nightmare Eclipse released a Microsoft Defender zero-day exploit called ShieldBreak after the company's August 2026 Patch Tuesday security updates became available.
organisation Microsoft
organisation Nightmare
‎August 25, 2026
Threat actors used a zero-day exploit in Microsoft Windows to gain unauthorized access.
vulnerability CVE-2026-68820
attribution Known Exploited
tactic T1588.006 - Vulnerabilities
attribution KEV
Tactical Metrics
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
‎7.8
Software Version
Metrics
data_breach
8
Bytes
Intelligence Sources