CVE Tools
Back to feed
Exploited in the wild Microsoft Defender ransomware gangs ransomware Microsoft privilege-escalation

CISA: Windows BlueHammer flaw now exploited by ransomware gangs

BleepingComputer·By Sergiu Gatlan··2 min read
CVE Tools coverage

The U.S. CISA has confirmed that ransomware groups have started exploiting the Microsoft Defender privilege-escalation vulnerability tracked as CVE-2026-33825. This issue, known as BlueHammer, allows an authenticated attacker to elevate local privileges by exploiting overly broad access control, which can lead to SYSTEM-level control and full compromise. CISA added CVE-2026-33825 to its KEV catalog and urged rapid patching because it is now tied to real ransomware activity.