Exploited in the wild Microsoft Defender zero-day Microsoft privilege-escalation
BlueHammer Vulnerability Exploited in Ransomware Attacks
CVE Tools coverage
CISA says a vulnerability in Microsoft Defender, tracked as BlueHammer and identified as CVE-2026-33825, is being used as part of ransomware intrusions. The issue affects Microsoft’s Defender component and can enable authenticated attackers to escalate privileges, which is why it matters for incident risk. CISA added the flaw to its Known Exploited Vulnerabilities (KEV) catalog and later updated the entry to indicate ransomware exploitation in the wild, underscoring the need to apply Microsoft’s April patches.