U.S. CISA adds a flaw in Microsoft Defender to its Known Exploited Vulnerabilities catalog
ID: e56aa872-ef1e-5c5b-a98e-3bd742f22e25
STIX ID: report--e56aa872-ef1e-5c5b-a98e-3bd742f22e25
Feed Name: Security Affairs
Threat Score
CISA added Microsoft Defender flaw CVE-2026-33825 (CVSS 7.8) to its Known Exploited Vulnerabilities catalog after reports that attackers are exploiting three recently disclosed Microsoft Defender vulnerabilities (BlueHammer, RedSun, UnDefend) to escalate privileges or disrupt protection; one flaw was patched in April 2026, public proof-of-concept exploit code was published, and federal agencies were ordered to remediate the issue by May 6, 2026.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
