NightmareEclipse Coordinated Disclosure Breach Campaign: 9+ Windows Zero-Days (CVE-2026-33825, CVE-2026-41091, CVE-2026-45498, CVE-2026-45585, CVE-2026-45586) Dumped Outside Responsible Disclosure and Weaponized in Real-World Intrusions — Threadlinqs Intelligence
As of 2026-08-04, NightmareEclipse Coordinated Disclosure Breach Campaign: 9+ Windows Zero-Days (CVE-2026-33825, CVE-2026-41091, CVE-2026-45498, CVE-2026-45585, CVE-2026-45586) Dumped Outside Responsible Disclosure and Weaponized in Real-World Intrusions is a critical-severity vulnerability threat attributed to NightmareEclipse, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 19 indicators of compromise.
Threat ID: TL-2026-1865 · Severity: CRITICAL · CVSS: 7.8 · Status: ACTIVE · Category: VULNERABILITY
Attribution: NightmareEclipse · DESTRUCTION
A disgruntled security researcher operating under the alias NightmareEclipse (also Chaotic Eclipse, MSNightmare) publicly released nine unpatched Windows zero-day exploits outside coordinated
Between April and July 2026, a threat actor using the pseudonym NightmareEclipse (also tracking as Chaotic Eclipse and MSNightmare) systematically released nine separate zero-day proof-of-concept exploits for Microsoft Windows components — all outside of coordinated vulnerability disclosure (CVD) protocols. The actor claims Microsoft's Security Response Center (MSRC) mishandled prior vulnerability submissions, leaving them 'insulted, humiliated, and left homeless,' and stated the goal of causing 'maximum harm' to Microsoft. The resulting exploits have been weaponized in real-world intrusions documented by Huntress, with CISA adding three of the disclosed CVEs to the Known Exploited Vulnerabilities catalog.
The nine exploits span multiple attack surfaces across the Windows ecosystem:
BlueHammer (CVE-2026-33825, CWE-1220) — A TOCTOU race condition in Windows Defender Antimalware Platform (< 4.18.26030.3011) exploiting opportunistic locks (oplock) and Volume Shadow Copy to achieve SYSTEM-level privilege escalation via SAM database credential extraction. CVSS 7.8 (HIGH), actively exploited, added to CISA KEV April 22, 2026.
RedSun (CVE-2026-41091, CWE-59) — A symlink-following vulnerability in the Microsoft Malware Protection Engine (< 1.1.26040.8) enabling local privilege escalation to SYSTEM via COM object hijacking of the Storage Tiers Management Engine service. CVSS 7.8 (HIGH), actively exploited, added to CISA KEV May 20, 2026.
UnDefend (CVE-2026-45498, CWE-400) — A resource exhaustion vulnerability in Microsoft Defender Antimalware Platform (< 4.18.26040.7) that creates locked file handles on Defender signature definition files (mpavbase.lkg, mpavbase.vdm), temporarily disabling real-time protection until process exit. CVSS 7.5 (HIGH, NVD rating), actively exploited, added to CISA KEV May 20, 2026.
YellowKey (CVE-2026-45585, CWE-77) — A command injection vulnerability in Windows BitLocker enabling security feature bypass on systems using TPM-only pre-boot authentication (no PIN). A physical attacker can extract the decryption key from the TPM. CVSS 6.8 (MEDIUM), requires physical access. Affects Windows 11 24H2/25H2/26H1 and Windows Server 2025.
GreatXML (no CVE assigned) — A design-level abuse of Windows Recovery Environment (WinRE) that allows an attacker with administrative access to plant a malicious unattend.xml file on the recovery partition. Upon reboot into WinRE, the answer file processes before security boundaries enforce, spawning a SYSTEM shell with full access to BitLocker-encrypted volumes without a recovery key. Requires prior admin access to plant the file — acts as a persistent backdoor surviving credential rotation. Independently tested by Cyderes (Howler Cell) who confirmed the attack chain.
GreenPlasma (CVE-2026-45586) — A local privilege escalation in the Windows Text Services Framework (CTFMON/CTF) subsystem combining Object Manager symbolic link placement and registry link abuse to create arbitrary memory sections in SYSTEM-writable object directories. Affects Windows 11 and Windows Server 2022/2025/2026. Builds on prior research by James Forshaw (Google Project Zero, 2019).
MiniPlasma (no CVE assigned) — A local privilege escalation in the Windows Cloud Files Mini Filter Driver (cldflt.sys) that revives a vulnerability originally reported by James Forshaw as CVE-2020-17103 but which remained exploitable. The function HsmOsBlockPlaceholderAccess fails to specify OBJ_FORCE_ACCESS_CHECK when creating registry objects, allowing an attacker using Anonymous token impersonation and a race condition to write to SYSTEM-level registry locations and spawn a full SYSTEM shell. Affects all Windows versions according to the researcher.
RoguePlanet (no CVE assigned) — A local privilege escalation exploiting a race condition in Windows Defender's scan-and-quarantine pipeline. Chains NTFS directory junctions, opportunistic locks (oplocks), Volume Shadow Copy, and Windows Error Reporting's QueueReporting sched
Weaknesses (CWE)
CWE-1220, CWE-59, CWE-400, CWE-77, CWE-264, CWE-367
Target sectors: government administration, finance, health, technology, critical-infrastructure
Target regions: North America, Europe, Asia-Pacific
Detections & IOCs
As of 2026-08-08, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 19 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-33825, CVE-2026-41091, CVE-2026-45498, CVE-2026-45585, CVE-2026-45586, T1078, T1133, T1059, T1053, T1055, T1546, T1574, T1562, T1003, T1555