Site icon VMVirtualMachine.com

Microsoft patches LegacyHive Windows zero-day vulnerability

Microsoft patches LegacyHive Windows zero-day vulnerability

By Sergiu Gatlan
Publication Date: 2026-08-13 17:46:00

Microsoft has released security patches to address a Windows zero-day vulnerability known as “LegacyHive,” disclosed after the July 2026 Patch Tuesday.

The security flaw was disclosed by a security researcher who uses the “Nightmare Eclipse” handle in protest of Microsoft’s bug bounty and vulnerability disclosure practices.

Nightmare Eclipse published a LegacyHive proof-of-concept (PoC) exploit hours after the July 2026 Patch Tuesday security updates were released, claiming it exploits a security vulnerability in the Windows User Profile Service.

However, unlike previous exploits they released, the LegacyHive PoC requires additional credentials, making it harder for threat actors to weaponize the vulnerability.

“Microsoft is aware of the reported vulnerability and is actively investigating the validity and potential applicability of these claims,” a Microsoft spokesperson told BleepingComputer when asked for a statement regarding LegacyHive.

Vulnerability…

Exit mobile version