Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday 25%

By Ravie Lakshmanan12%

7/15/2026, 11:07:00 AM

BS Summary: This article contains 19 faulty reasoning types, including Appeal to Authority, Recency Bias, and Availability Heuristic, with Negativity Bias as the most egregious example at 22.4% saturation with 170 hits. Analysis detected 1,153 faulty-reasoning hits from 758 analyzed words, generating a BS Score of 37.4% and a BS Rank of 25% (16,440 of 21,887 articles). This article is better (less manipulative) than 75.10% of the article peer group.

Security researcher <b>Chaotic Eclipse</b> (aka <b>Nightmare-Eclipse</b>) has <a href="https://blog.projectnightcrawler.dev/posts/2026-07-14-legacyhive-public-disclosure/" target="_blank">released</a> a new proof-of-concept (PoC) exploit called LegacyHive. 
It has been described as a Windows User Profile Service arbitrary hive load elevation of privileges vulnerability. 
The Windows User Profile Service, also referred to as ProfSvc, is a core system component that manages user accounts and environments. 
"The PoC requires another standard user credential and a third username (which can be an administrator account)," Chaotic Eclipse <a href="https://git.projectnightcrawler.dev/NightmareEclipse/LegacyHive" target="_blank">said</a>. 
"If the PoC is successful, it will end up mounting the target user hive in the current user classes root." 
The researcher said the exploit was stripped down to prevent public exploitation, adding the original exploit did not require additional user credentials and was not limited to the "usrclass.dat" hive. 
"Any hive could be loaded using this vulnerability, but you would need some brain cells to make the PoC do it," the researcher noted. 
What makes it notable is that it's functional on all supported desktop and server versions of Windows, including those running the latest July 2026 Patch Tuesday update. 
Chaotic Eclipse and Microsoft have been <a href="https://thehackernews.com/2026/05/microsoft-slams-public-zero-day.html" target="_blank">locked in a heated dispute</a> since at least April 2026, with the researcher releasing details of multiple exploits before the Windows maker had a chance to patch them, citing a breakdown in communication. 
Three of the vulnerabilities in Microsoft Defender came under active exploitation shortly after public disclosure. 
Earlier this month, the tech giant released security updates for another Defender vulnerability known as RoguePlanet that was disclosed by the researcher. 
However, it emerged that the newly introduced "defense-in-depth updates" to address the flaw can cause Microsoft Defender to leak 8 bytes of data when attempting to open a file in certain scenarios. 
Microsoft <a href="https://thehackernews.com/2026/07/microsoft-patches-rogueplanet-defender.html" target="_blank">told</a> The Hacker News that it's investigating the new report. 
We have contacted the company for comment regarding LegacyHive, and we will update the story if we hear back. 
<h3>SharePoint Server Flaws in Spotlight</h3> 
The development comes as Microsoft shipped patches for a <a href="https://thehackernews.com/2026/07/microsoft-patches-record-622-flaws.html" target="_blank">record 622 flaws</a>, including two privilege escalation shortcomings in SharePoint Server (CVE-2026-56164, CVSS score: 5.3) and Active Directory Federation Services (CVE-2026-56155, CVSS score: 7.8) that have been flagged as actively exploited. 
The U.S. 
Cybersecurity and Infrastructure Security Agency (CISA) has <a href="https://www.cisa.gov/news-events/alerts/2026/07/14/cisa-adds-four-known-exploited-vulnerabilities-catalog" target="_blank">added</a> both vulnerabilities to its Known Exploited Vulnerabilities (<a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog" target="_blank">KEV</a>) catalog, which mandates that Federal Civilian Executive Branch (FCEB) agencies apply the fixes by July 17 and July 28, 2026, respectively. 
"After years of relative stability, the Patch Tuesday process has experienced significant turbulence so far in 2026," Adam Barnett, lead software engineer at Rapid7, said in a statement. 
"As well as the AI-fuelled exponential growth of vulnerability reporting and discovery, Microsoft is grappling with the emergence of a series of vulnerabilities disclosed in such a way as to bring maximum discomfort for Redmond." 
In a separate advisory, the agency <a href="https://www.cisa.gov/news-events/alerts/2026/07/14/cisa-urges-sharepoint-hardening-after-new-exploitations" target="_blank">said</a> it's aware of active exploitation of multiple SharePoint Server flaws, including <a href="https://www.cve.org/CVERecord? 
id=CVE-2026-32201" target="_blank">CVE-2026-32201</a>, <a href="https://www.cve.org/CVERecord? 
id=CVE-2026-45659" target="_blank">CVE-2026-45659</a>, and CVE-2026-56164, that enable cyber threat actors to gain unauthorized access to susceptible instances. 
"These vulnerabilities affect all supported on-premises SharePoint Server versions (Subscription Edition, 2019, and 2016) and involve establishing remote code execution (RCE) and post-exploitation activities, such as stealing Internet Information Services (IIS) machine keys and performing deserialization techniques, to gain persistence and deploy malware," CISA said. 
"The flaw stems from missing authentication for a critical function, enabling an attacker to reach functionality that should require authorization," Alex Vovk, CEO and co-founder of Action1, said about CVE-2026-56164. 
"An attacker can send specially crafted network requests to access functionality that should require authentication, resulting in privilege escalation. 
The vulnerability primarily impacts system integrity by allowing unauthorized actions without requiring prior authentication or user interaction. 
Internet-facing SharePoint servers are particularly exposed because the attack can be performed remotely without valid credentials." 
It's worth noting that the July 2026 update also addresses another critical SharePoint Server security feature bypass vulnerability (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55040" target="_blank">CVE-2026-55040</a>, CVSS score: 9.1) that a remote unauthenticated attacker could exploit to bypass authentication on a vulnerable SharePoint server and perform operations as a SharePoint site user or administrator. 
"The vulnerability is due to several issues in the JWT token validation pipeline," Rapid7 <a href="https://www.rapid7.com/blog/post/ve-cve-2026-55040-microsoft-sharepoint-jwt-token-authentication-bypass-fixed/" target="_blank">said</a>. 
"An attacker who successfully exploits CVE-2026-55040 can perform operations against the target SharePoint site as the user they identify as. 
Furthermore, this authentication bypass can be chained to additional vulnerabilities within the authenticated attack surface of the target site." 
Article reasoning-pattern comparisonThis article: 0.0%Ravie Lakshmanan: 1.5%The Hacker News: 1.9%Confirmation Bias0.0%This article: 6.5%Ravie Lakshmanan: 1.4%The Hacker News: 1.2%Anchoring Bias6.5%This article: 16.5%Ravie Lakshmanan: 2.4%The Hacker News: 3.3%Availability Heuristic16.5%This article: 5.0%Ravie Lakshmanan: 1.7%The Hacker News: 1.5%Representativeness Heuristic5.0%This article: 0.0%Ravie Lakshmanan: 0.9%The Hacker News: 0.6%Hindsight Bias0.0%This article: 0.0%Ravie Lakshmanan: 2.4%The Hacker News: 2.5%Overconfidence Bias0.0%This article: 2.1%Ravie Lakshmanan: 2.4%The Hacker News: 2.7%Framing Effect2.1%This article: 0.0%Ravie Lakshmanan: 0.8%The Hacker News: 1.0%Loss Aversion0.0%This article: 0.0%Ravie Lakshmanan: 0.4%The Hacker News: 0.6%Status Quo Bias0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.1%Sunk Cost Effect0.0%This article: 4.6%Ravie Lakshmanan: 1.1%The Hacker News: 1.3%Optimism Bias4.6%This article: 2.1%Ravie Lakshmanan: 1.5%The Hacker News: 1.6%Pessimism Bias2.1%This article: 22.4%Ravie Lakshmanan: 7.7%The Hacker News: 6.7%Negativity Bias22.4%This article: 4.0%Ravie Lakshmanan: 0.3%The Hacker News: 0.8%Self-Serving Bias4.0%This article: 5.4%Ravie Lakshmanan: 0.6%The Hacker News: 0.4%Fundamental Attribution Error5.4%This article: 5.4%Ravie Lakshmanan: 0.1%The Hacker News: 0.1%Actor-Observer Bias5.4%This article: 0.0%Ravie Lakshmanan: 0.1%The Hacker News: 0.1%In-Group Bias0.0%This article: 0.0%Ravie Lakshmanan: 1.2%The Hacker News: 0.3%Out-Group Homogeneity Bias0.0%This article: 0.0%Ravie Lakshmanan: 0.3%The Hacker News: 0.6%Halo Effect0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Horn Effect0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Dunning-Kruger Effect0.0%This article: 17.2%Ravie Lakshmanan: 2.4%The Hacker News: 1.5%Recency Bias17.2%This article: 0.0%Ravie Lakshmanan: 0.3%The Hacker News: 0.3%Primacy Effect0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.1%Blind-Spot Bias0.0%This article: 0.0%Ravie Lakshmanan: 0.2%The Hacker News: 0.1%Ad Hominem0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.1%Straw Man0.0%This article: 17.5%Ravie Lakshmanan: 4.9%The Hacker News: 4.0%Appeal to Authority17.5%This article: 0.0%Ravie Lakshmanan: 0.5%The Hacker News: 1.6%False Dilemma0.0%This article: 2.5%Ravie Lakshmanan: 0.5%The Hacker News: 0.5%Slippery Slope2.5%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.1%Circular Reasoning0.0%This article: 6.7%Ravie Lakshmanan: 4.0%The Hacker News: 4.3%Hasty Generalization6.7%This article: 0.0%Ravie Lakshmanan: 0.2%The Hacker News: 0.1%Red Herring0.0%This article: 0.0%Ravie Lakshmanan: 0.2%The Hacker News: 0.2%Bandwagon0.0%This article: 3.2%Ravie Lakshmanan: 1.1%The Hacker News: 1.1%Appeal to Emotion3.2%This article: 0.0%Ravie Lakshmanan: 0.2%The Hacker News: 0.5%Begging the Question0.0%This article: 8.8%Ravie Lakshmanan: 2.1%The Hacker News: 1.9%Post Hoc (False Cause)8.8%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Tu Quoque0.0%This article: 0.0%Ravie Lakshmanan: 0.9%The Hacker News: 0.6%Burden of Proof0.0%This article: 0.0%Ravie Lakshmanan: 0.1%The Hacker News: 0.1%Appeal to Nature0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.3%Composition/Division0.0%This article: 0.0%Ravie Lakshmanan: 0.4%The Hacker News: 1.0%Anecdotal0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.1%No True Scotsman0.0%This article: 10.6%Ravie Lakshmanan: 3.8%The Hacker News: 2.3%Ambiguity (Equivocation)10.6%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Gambler’s Fallacy0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Middle Ground0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Personal Incredulity0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.1%Special Pleading0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.1%Genetic Fallacy0.0%This article: 2.2%Ravie Lakshmanan: 3.4%The Hacker News: 1.4%Unattributed Quote2.2%This article: 0.0%Ravie Lakshmanan: 2.6%The Hacker News: 0.9%Quote-first Misdirection0.0%This article: 9.4%Ravie Lakshmanan: 2.5%The Hacker News: 2.3%Biased Writer Voice9.4%This article: 0.0%Ravie Lakshmanan: 2.4%The Hacker News: 4.4%Indoctrination0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Politically Left Leaning Bias0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Politically Right Leaning Bias0.0%This article: 0.0%Ravie Lakshmanan: 0.4%The Hacker News: 3.0%Attempt to Sell a Product or S…0.0%

758 words analyzed.

Speakers

6speakers44%attributed speech427writer words
Voice mapSelect a segment to jump to its words
Writer's voice • 11 words • 0.0% coverageWriter's voice • 17 words • 0.0% coverageWriter's voice • 17 words • 100.0% coverageWriter's voice • 21 words • 0.0% coverageChaotic Eclipse • 22 words • 0.0% coverageChaotic Eclipse • 20 words • 0.0% coverageWriter's voice • 30 words • 100.0% coverageWriter's voice • 24 words • 0.0% coverageWriter's voice • 27 words • 0.0% coverageWriter's voice • 41 words • 100.0% coverageWriter's voice • 15 words • 0.0% coverageWriter's voice • 22 words • 0.0% coverageWriter's voice • 32 words • 0.0% coverageMicrosoft • 13 words • 0.0% coverageWriter's voice • 19 words • 0.0% coverageWriter's voice • 5 words • 0.0% coverageWriter's voice • 42 words • 0.0% coverageWriter's voice • 2 words • 0.0% coverageCybersecurity and Infrastructure Security Agency (CISA) • 41 words • 0.0% coverageAdam Barnett • 28 words • 0.0% coverageAdam Barnett • 35 words • 0.0% coverageCybersecurity and Infrastructure Security Agency (CISA) • 22 words • 0.0% coverageWriter's voice • 4 words • 0.0% coverageWriter's voice • 16 words • 0.0% coverageCybersecurity and Infrastructure Security Agency (CISA) • 45 words • 0.0% coverageAlex Vovk • 30 words • 0.0% coverageAlex Vovk • 19 words • 0.0% coverageWriter's voice • 17 words • 0.0% coverageWriter's voice • 16 words • 0.0% coverageWriter's voice • 49 words • 0.0% coverageRapid7 • 17 words • 0.0% coverageRapid7 • 20 words • 0.0% coverageRapid7 • 19 words • 0.0% coverage
Selected voice

Adam Barnett

100%flagged-word coverage
63 attributed words19% of attributed speech92% writer coverage
0%10.0%20.0%Biased Writer Voice-16.6 ptsWriter: 16.6%Adam Barnett: 0.0%0.0%Unattributed Quote-4.0 ptsWriter: 4.0%Adam Barnett: 0.0%0.0%

Attribution is sentence-level. Pattern percentages are calculated only from words assigned to that voice.

Loading…
Loading…
Loading…
Loading…

Analysis

Hover over highlighted words in the article to view the associated bias or fallacy analysis.