Vexed researcher Nightmare-Eclipse (aka Chaotic Eclipse, Dead Eclipse, and MSNightmare) released his ninth unpatched Windows vulnerability called LegacyHive. This latest bug drop is a Local Privilege Escalation (LPE) vulnerability affecting Windows User Profile, a component responsible for loading and unloading Windows user profiles. When exploited, LegacyHive can enable attackers to load other users’ hives and gain access to application data and Windows Explorer history, among others.
What’s peculiar about this month’s drop is that the proof-of-concept (PoC) was stripped, deterring the public from exploiting it. On LegacyHive’s GitHub page, Nightmare-Eclipse shared that the original PoC did not need user credentials to work and allowed any hive, including those of administrators, to be loaded. “Any hive could be loaded using this vulnerability, but you would need some brain cells to make the PoC do it,” writes Nightmare-Eclipse.
LegacyHive, which Nightmare-Eclipse publicly shared after Microsoft released this month’s batch of hefty security updates, works on all Windows desktop and server versions, even those that have applied the July 2026 Patch Tuesday update.
Prior to releasing LegacyHive, Nightmare-Eclipse published back-to-back vulnerability drops for June 2026. The first of which was RoguePlanet, a race condition exploit that can spawn a command shell with SYSTEM-level privileges, giving threat actors unfettered access to a vulnerable machine.
GreatXML, on the other hand, is an exploit that allows attackers to bypass BitLocker, a built-in Windows feature that protects data from unauthorized access via full-disc encryption. According to Nightmare-Eclipse, this exploit will work on any system that has previously performed a Microsoft Defender Offline scan, which is typically recommended to users who suspect a malware infection or those who want to ensure that an endpoint is thoroughly clean following a malware outbreak.
We covered the technical mechanisms behind both vulnerabilities in our blog.
As of writing, Microsoft has yet to publicly acknowledge or release a patch for LegacyHive.