logo

U.S. CISA adds a flaw in Microsoft Defender to its Known Exploited Vulnerabilities catalog

ID: e56aa872-ef1e-5c5b-a98e-3bd742f22e25

STIX ID: report--e56aa872-ef1e-5c5b-a98e-3bd742f22e25

Feed Name: Security Affairs

Threat Score
75/100

Date Published: 2026-04-23

Date Updated: 2026-04-23

Author: Pierluigi Paganini

...
...

CISA added Microsoft Defender flaw CVE-2026-33825 (CVSS 7.8) to its Known Exploited Vulnerabilities catalog after reports that attackers are exploiting three recently disclosed Microsoft Defender vulnerabilities (BlueHammer, RedSun, UnDefend) to escalate privileges or disrupt protection; one flaw was patched in April 2026, public proof-of-concept exploit code was published, and federal agencies were ordered to remediate the issue by May 6, 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.