Exploited in the wild Microsoft Defender ransomware gangs ransomware Microsoft privilege-escalation
CISA: Windows BlueHammer flaw now exploited by ransomware gangs
CVE Tools coverage
The U.S. CISA has confirmed that ransomware groups have started exploiting the Microsoft Defender privilege-escalation vulnerability tracked as CVE-2026-33825. This issue, known as BlueHammer, allows an authenticated attacker to elevate local privileges by exploiting overly broad access control, which can lead to SYSTEM-level control and full compromise. CISA added CVE-2026-33825 to its KEV catalog and urged rapid patching because it is now tied to real ransomware activity.