CVE Tools
Back to feed
Exploited in the wild Microsoft Defender zero-day Microsoft privilege-escalation

BlueHammer Vulnerability Exploited in Ransomware Attacks

SecurityWeek·By Eduard Kovacs··1 min read
CVE Tools coverage

CISA says a vulnerability in Microsoft Defender, tracked as BlueHammer and identified as CVE-2026-33825, is being used as part of ransomware intrusions. The issue affects Microsoft’s Defender component and can enable authenticated attackers to escalate privileges, which is why it matters for incident risk. CISA added the flaw to its Known Exploited Vulnerabilities (KEV) catalog and later updated the entry to indicate ransomware exploitation in the wild, underscoring the need to apply Microsoft’s April patches.