Vulnerabilities

Nightmare Eclipse Drops ‘LegacyHive’ Windows Zero-Day 

The researcher stripped the proof-of-concept (PoC) exploit to prevent immediate exploitation of the vulnerability.

Windows security

Nightmare Eclipse, the disgruntled security researcher who has been dropping zero-day exploits targeting Microsoft products, released another unpatched Windows vulnerability this week, right on the July 2026 Patch Tuesday.

The fresh exploit, named LegacyHive, is a local privilege escalation bug in the Windows User Profile Service that allows an attacker to load other users’ hives, including those of administrators.

Also known as Chaotic Eclipse, Nightmare Eclipse released proof-of-concept (PoC) exploit code that works on systems running Microsoft’s July 2026 patches.

“The PoC requires another standard user credentials and a third username (which can be an administrator account), if the PoC is successful, it will end up mounting the target user hive in current user classes root,” the researcher explains.

Unlike previously dropped zero-day exploits from Nightmare Eclipse, LegacyHive was released with a stripped PoC to prevent the security defect’s in-the-wild exploitation.

According to the researcher, the exploit originally did not require user credentials and allowed any hive to be loaded, not just the usrclass.dat hive. That is still possible, the researcher says, but would require some work.

Advertisement. Scroll to continue reading.

To date, Nightmare Eclipse released over half a dozen zero-days in Microsoft products, including BlueHammer, RedSun, and UnDefend, which have been exploited in attacks, along with GreenPlasma, RoguePlanet, YellowKey, and GreatXML.

Responding to a SecurityWeek inquiry, a Microsoft spokesperson said the company was investigating the LegacyHive exploit:

“Microsoft is aware of the reported vulnerability and is actively investigating the validity and potential applicability of these claims. Microsoft is committed to investigating security issues and updating impacted products to protect customers as soon as possible. Importantly, we support coordinated vulnerability disclosure, an industry standard that protects customers and supports the research community by ensuring their findings are thoroughly investigated and addressed before being made public.”

*Updated with statement from Microsoft.

Related: Unpatched Cursor Vulnerability Exposes Users to Code Execution

Related: CISA Urges Immediate Patching of Exploited SharePoint Vulnerabilities

Related: Windows Bind Link Attacks Can Hide Malware From EDR Tools

Related: Progress Confirms Zero-Day Vulnerability Behind ShareFile Disruption

Related Content

Vulnerabilities

A CVE identifier has not yet been assigned, but PaperCut is urging NG/MF users to install patches and implement mitigations.

Vulnerabilities

The security defect is described as an SQL injection that could allow attackers to achieve remote code execution.

Vulnerabilities

Dropped on Patch Tuesday, the exploit allows any user to spawn a shell with System privileges.

Vulnerabilities

The vulnerability was patched by Microsoft in July and CISA warned that it could end up being exploited in the wild.

Vulnerabilities

The bug allowed attackers to gain full control of the victims’ systems and deploy the ForestTiger backdoor.

Vulnerabilities

CVE-2026-20349 can be exploited remotely without authentication against Secure Firewall ASA and FTD devices.

Vulnerabilities

A use-after-free in the afd.sys Windows kernel-mode driver has been exploited to gain SYSTEM privileges.

Vulnerabilities

Remote, unauthenticated attackers could exploit the bugs to cause a denial-of-service (DoS) condition.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version