New Windows zero-day LegacyHive bypasses July Patch Tuesday, no fix yet
A researcher known as Nightmare Eclipse published a working Windows exploit called LegacyHive hours after Microsoft's July 2026 Patch Tuesday. It abuses the Windows User Profile Service to let a low-privileged user hijack an administrator's registry hive and run code as admin. Mi
A working zero-day exploit for Windows, dubbed LegacyHive, went public on July 17 from a researcher using the Nightmare Eclipse handle, only hours after Microsoft's July 2026 Patch Tuesday. The flaw sits in the Windows User Profile Service and lets a low-privileged user mount another user's registry hive, then tamper with how an administrator account launches programs or system components. When that admin next logs in, the altered entries execute with full admin rights, and because it happens inside a legitimate account, endpoint security is less likely to flag it. Researchers Will Dormann and Kevin Beaumont confirmed the exploit works on fully updated Windows 10, 11, and Server, with no assigned CVE and no security bulletin. Microsoft $MSFT says it is aware and investigating. Sources: BleepingComputer, Cyber Security News.